Security1 distinct publisher3 min readPublished
Prophet Security's report benchmarks attacker breakout at 29 minutes, which makes the hour of queue time before anyone opens an alert worth more than the 25 minutes AI takes off the investigation. The sample is the vendor's own.
The Watch · Security desk
build
Time to revoke: the two timestamps a closed ticket cannot give you1 distinct publisher
security
66% of mobile banking trojans now take the whole device, and 45% ask for a ransom1 distinct publisher
product
A third confide in chatbots, half don't know it trains the model. That gap is a product spec1 distinct publisher
security
U.S. warning on Siemens S7 PLCs: AI-written scripts, borrowed scan data, read access first1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
Multiply the survey's own averages. One hundred alerts a day at 75 minutes each is 7,500 analyst-minutes, or 125 hours of investigation work generated every day [3][5][1]. Many respondents run fewer than ten analysts [4]. Ten people on eight-hour shifts supply 80 hours, and nobody spends a full shift on triage, so the shortfall is at least 45 hours a day before meetings, projects and on-call [2]. The 28 percent of alerts that never get investigated [8] is that shortfall expressed as a percentage.
For the quarter of teams above 500 alerts a day [3], the same arithmetic demands 625 analyst-hours, a gap no hiring plan closes [5].
The clock the report builds its case on is a different one. An hour of queue time before a human touches the alert [6] plus 75 minutes to work it [5] is 135 minutes from firing to answer, about 4.7 times the 29-minute breakout figure the report uses as its benchmark [7][3]. Now apply the reported gain: 72 percent of AI users say investigation time fell by at least 25 percent, roughly 25 minutes an alert [14]. That takes 75 minutes to 50, and the cycle to 110 [4]. That is still 3.8 times breakout [4]. The saving is landing on the analysis while most of the delay sits in the queue.
Which is why the muted-rule number carries more weight than the volume number. Up to 40 percent of organizations have switched off alert rules because they had no one to read the output [10]. The report draws the distinction correctly: retiring a rule that never escalates is detection engineering, while silencing one because nobody has time narrows coverage precisely where the team already cannot see, so real load and real exposure both exceed what respondents reported [11]. The 100-alert average measures what teams chose to keep.
One note on provenance. This is a single vendor report, produced by Prophet Security from ViB's survey of 250-plus practitioners [1], and its most quotable finding is the one about in-house work: 72 percent of AI users tried to build their own tooling, and 46 percent of those projects were abandoned, never reached production, or were replaced by a commercial product [15]. The companion number is the one that keeps it honest. Teams that built reported investigation-time gains of 25 percent or more at 73 percent, against 72 percent for AI users overall [16]. The two paths were level on speed, and differed only in whether the thing was still running a year later.
The autonomy ceiling is set by the respondents, not by the vendor: 57 percent require a human to review every AI decision before an alert closes, 44 percent use AI to recommend actions for people to execute, 30 percent allow low-risk automated remediation, and none grants unsupervised autonomy [17]. Where the recovered time goes is threat hunting, and 38 percent of teams say hunting turned up malicious activity their automated tooling missed [18]. That is a real return, but not a containment return. If the 60-minute first-touch delay stays where it is, the gap against a 29-minute breakout survives every efficiency gain in the report.
Ranked by verification strength, evidence, and original report placement.
Prophet Security's State of AI in Security Operations 2026 report was produced from ViB's survey of 250+ cybersecurity professionals.
40% of security teams use AI daily, 56% are testing it, and 4% have no plans to adopt it.
The average security team gets about 100 alerts a day, larger companies often close to 1,000, and over a quarter of teams face more than 500 alerts daily.
Team sizes vary widely: some very large organizations have over 100 analysts, while many teams run fewer than ten people.
It takes an average of 75 minutes to thoroughly investigate a single alert.
Alerts often sit untouched for nearly an hour before anyone looks at them.
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor-produced survey, no independent corroboration
Every figure in the cluster derives from one report published by Prophet Security and fielded by ViB among 250-plus self-selected respondents, relayed in a single article that appears twice. Sampling frame, respondent seniority, question wording and the provenance of the 29-minute breakout benchmark are undisclosed, and all outcome measures (time saved, alerts uninvestigated, rules disabled) are self-reported. The internal arithmetic is checkable and consistent, which keeps this above the floor, but nothing here is externally verified.
Broad experimentation, narrow production autonomy
Adoption is disclosed rather than absent: 40% daily use and 56% testing indicate wide penetration of AI into security operations. It is discounted because the deployed surface stays shallow and self-described, with 57% of teams gating every decision behind human review, none granting unsupervised autonomy, and 46% of in-house builds abandoned or displaced, so most of the reported adoption is assistive tooling rather than delegated operation.
Overstated: 'AI is actually working' against a cycle still 3.8x the benchmark
The article's framing ('AI is officially mainstream', 'AI is actually working') runs ahead of its own numbers. Even granting the reported 25-minute saving, the alert-to-answer cycle stays near 110 minutes against a 29-minute breakout benchmark, 28% of alerts remain uninvestigated, up to 40% of organizations have switched detections off, and no respondent trusts AI unsupervised. The largest single component of the delay, nearly an hour of queue time, is untouched by the investigation-speed gain the piece celebrates, and the report is published by a vendor of the recommended remedy.
Vendor-published research ending in a vendor pitch
The report is authored and published by Prophet Security, which sells an agentic AI SOC platform, and the article closes with a 'How Prophet Security Works' section citing a Rising in Cyber 2026 accolade. The findings that most favor the sponsor are the ones most prominently framed: alert overload, DIY build failure at 46% with no speed advantage, and evaluation of AI vendors rather than sitting on the sidelines. No independent methodology audit or dissenting dataset appears in the cluster.
Provenance clear, verification absent
Confidence is moderate: the sourcing chain is fully transparent and the numbers are internally consistent and arithmetically checkable, so the assessment of framing and incentive structure is firm. What limits it is the absence of any second publisher, independent survey, or disclosed methodology against which the underlying percentages could be tested, plus reliance on a duplicated article as the only textual basis.