Security1 distinct publisher3 min readPublished
SentinelOne's 451 Research survey of 611 practitioners finds AI returns arriving at the bottom of the maturity ladder. It leaves the top of the ladder almost entirely unmeasured.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Four percent of 611 is about 24 respondents [1]. That is the whole population in this survey running AI above senior-triage and basic incident response work [2], and it is the population that any claim about what happens at higher maturity would have to rest on. The report does not make that claim numerically. With a cohort that size, it could not.
What the sample does support is narrower and more usable. The returns being reported come from chatbots handling first-pass alert triage and automation that sorts true positives from noise [4]. That is the labour being displaced, and the near-universal improvement figure is measured against it.
That figure also deserves a closer read than it usually gets. It is published as the share of organizations reporting improvement in incident response and remediation, with no magnitude and no named metric attached [12]. No median change in time to respond, no alerts closed per analyst, no baseline. A room where everyone says "better" and a room where everyone says "31% faster" are different findings, and this is the first kind. As a signal that Level 1 automation is not vapour, it holds. As an input to a business case with a payback period in it, it does not.
The platform numbers have a similar softness underneath them. Self-described platform orientation went from roughly 69% to 82% in a year [5][3], which is a large move for an architecture change and a modest one for a change in vocabulary. The survey itself complicates the distinction: EDR, SIEM and CNAPP are simultaneously the technologies most often deployed standalone and the top anchors that organizations expand outward from [6]. An estate running EDR next to a SIEM can answer that question the same way an estate that deliberately consolidated does.
The sequencing argument is where the vendor's read and its own data pull apart. SentinelOne's position is that organizations waiting for higher AI maturity before building the supporting infrastructure are running the sequence backward, and that the foundation built today determines how far the returns scale [8]. The mechanism it offers is real enough: agentic AI needs connected, continuously updated telemetry, and fragmented pipelines that require manual effort will not carry autonomous action at scale [9]. But note what the survey contributes to that case. The most-cited benefit of a SecOps data lake is supporting AI-driven workloads and agents [7], which records what buyers expect the lake to do, not what it has done for them.
So the two purchases sit on different evidence. Triage automation has roughly 605 organizations behind it saying it improved something [2], and it demands very little of the underlying stack. The data layer is being priced against returns this survey did not observe, for the straightforward reason that almost nobody in it has reached the maturity level where those returns would appear [2]. That is not an argument against consolidating telemetry. It is an argument for buying it on your own architecture and incident-history case, at a pace you set, rather than on the strength of a number generated by organizations doing alert triage.
The one asymmetry worth holding onto: the cheap tier is the tier with the evidence, and the expensive tier is the one with the roadmap.
Ranked by verification strength, evidence, and original report placement.
For the second year, SentinelOne commissioned 451 Research to survey 611 North American cybersecurity decision-makers and practitioners on the state of security operations strategy.
96% of organizations surveyed are still operating AI at the earliest maturity levels: Level 1 (basic monitoring; triage specialist/alert analyst) and Level 2 (more senior triage analyst / basic incident responder and investigator).
99% of those same organizations already report improvements in incident response and remediation.
82% of organizations describe themselves as platform-oriented, a 13-point jump in a single year, and 94% expect to be there within three years.
The 99% figure is presented as the share of organizations reporting improvements in incident response and remediation; the post states no size of improvement and no specific metric behind it.
The same technologies most frequently deployed as standalone tools (EDR, SIEM, CNAPP) are also the top anchors for integrated platforms; organizations typically start with one of these and expand outward.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Thin: one sponsor-published survey summary, no methodology or effect sizes
All numbers come from a single vendor blog summarizing research the vendor commissioned. Sample size (611) and headline percentages are stated, but the underlying report, questionnaire, field dates, screening and customer mix are not published, the improvement claim carries no magnitude or metric, and the outcome data is not broken out by maturity level. The architectural and attack-surface assertions are supplied without benchmarks or incidents.
Wide but shallow: AI at triage nearly universal, autonomy barely present
Self-reported survey data indicates AI is broadly present in surveyed SOCs and platform consolidation is advancing (82% platform-oriented, 94% intending within three years), but depth is minimal: 96% remain at Level 1–2 and only about 24 of 611 respondents operate above senior-triage capability. Adoption is therefore scored on breadth of shallow triage use rather than on the autonomous operations the post promotes, and it rests on respondent self-description rather than measured deployment telemetry.
Overstated: Autonomous SOC framing outruns a triage-level dataset
The post's conclusion — that the potential of GenAI and agentic AI in the SOC 'is already being realized' on the path to an Autonomous SOC — is drawn from a population that is 96% at triage-level maturity, with the autonomous tier represented by roughly 24 respondents that are never separately measured. The supporting outcome number (99% reporting improvement) has no magnitude attached, and the burnout and attack-surface findings are unquantified. The measured substance is that shallow AI triage is widely deployed and users like it; the framing extends that into an architectural mandate and an autonomy roadmap.
Strong: sponsor-commissioned research validating the sponsor's product thesis
SentinelOne commissioned and published the research, and every headline finding maps onto its commercial position: early AI returns justify buying now, platform consolidation favors a single-vendor stack, a SecOps data lake is a prerequisite, and securing AI infrastructure should run on 'the same platform.' The post closes by stating the findings align with SentinelOne's defined path to autonomous security operations. No customer-mix disclosure or independent review is offered to offset the sponsor's interest.
Moderate: framing and incentives are unambiguous, substance is unverifiable
Confidence is high on what can be read directly off the source — the reported percentages, the sample size, the sponsor relationship, and the gap between a triage-level population and an autonomy narrative. Confidence is limited on the underlying reality because the cluster contains one sponsored source, no primary report, no effect sizes, and no independent corroboration, so the true state of SOC AI outcomes cannot be established from this material.
product
The number in the Palo Alto-NTT DATA deal is not $1 billion. It is 80 machine accounts per human2 distinct publishers
product
A third confide in chatbots, half don't know it trains the model. That gap is a product spec1 distinct publisher
security
Levi Strauss lost corporate files through three laptops and no malware1 distinct publisher
product
Alice raised $140m to red-team the frontier, and a security vendor bought in quietly1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026