For most of the past decade, Managed Detection and Response (MDR) was the answer to staffing and alert fatigue challenges. However, as attackers increasingly leverage AI to automate reconnaissance, generate convincing phishing at scale, and create malware variants that evade signature-based detection, the traditional MDR model is proving insufficient. Analysis of 25 million alerts across global enterprises in 2025 reveals that approximately 60% of alerts go unreviewed, with nearly 1% of real threats originating in low-severity and informational alerts. For an enterprise generating 450,000 alerts annually, this translates to roughly 54 real incidents per year—about one per week—sitting in the deprioritized queue where no one is looking.
Key gaps in the MDR model include inconsistent investigation quality depending on the analyst on shift, a lack of closed-loop detection engineering where insights from investigations rarely feed back into detection systems, and a black-box approach that prevents customers from auditing investigation logic or evidence trails. Additionally, AI-driven cost savings from MDR providers are not passed on to customers, and detection rules, triage logic, and case history remain locked within the vendor’s platform, creating switching costs and hindering AI readiness.
The article advocates for a transition to an AI-powered Security Operations Center (AI SOC), where AI executes investigative execution and humans supervise. This model ensures 100% of alerts are triaged and investigated automatically, with forensic depth applied to every alert regardless of severity or time of day. Intezer’s platform data shows that less than 2% of alerts required human escalation, with over 98% resolved autonomously with sub-minute median triage time and 98% verdict accuracy. Closed-loop detection engineering continuously improves detection posture, and per-endpoint pricing eliminates the economic penalty for investigating every alert. Ownership of detection rules, investigation history, and organizational context remains with the customer, enabling security maturity and broader adoption of AI tools.
CVEs: CVE-2026-11645
Malware: Agent Tesla, LummaC2
Companies: Intezer
Products: Intezer AI SOC
Original source: thehackernews.com