Global cybersecurity company, N-able, have released their second annual State of the SOC Report, which draws on aggregated data and investigations conducted by their SOC spanning more than 900,000 alerts between March and December 2025.
The report reveals an attack landscape defined by the resurgence of network-based threats, the limits of endpoint-only strategies, and the rapid operationalisation of AI across security operations.
N-able previously estimated that 70% of all investigation and remediation would be automated through AI in 2024, new estimates suggest this could have been up to 90% of all investigations in 2025.
The report suggests that this level of AI use isn’t to replace security experts.
Of over 900,000 total alerts processed in 2025, over 650,000 were automated alerts that required correlation across layers. At this scale, manual investigation models struggle to manage workloads.
The data signals an inflection point for security teams.
Escalating alert volumes, faster attack execution, and increasingly sophisticated adversaries can put limits on legacy SOC approaches, requiring AI-driven operations that can keep pace.
The report found 90% of investigation activity is executed autonomously by AI. Adversaries are leveraging AI to accelerate attacks and bypass defences, increasing challenges for organisations that lag in automation maturity. As a result, the SOC analyst role has fundamentally shifted from investigator to decision-maker and threat hunter.
In 2025, perimeter attacks returned as blind spots expanded, a shift away from the endpoint and cloud attacks the industry is used to. 18% of alerts originated from network and perimeter infrastructure. The data reveals that threat activity is increasingly bypassing traditional device-level visibility, with around half of attacks never touching the endpoint.
SOAR is redefining the response layer with a 500% year-over-year surge in SOAR-orchestrated alert workflows. There has been a fundamental shift in how security teams respond to threats. Alert volume has made manual response execution unscalable and it difficult to keep pace. SOAR supports automated, co-ordinated and timely responses, to stay ahead of modern attacks.
End-to-end resilience is the multiplier of any defence strategy: Layered security has a measurable impact, with each layer reducing the probability of threat success. N-able found that organisations relying exclusively on endpoint monitoring would have missed over 130,000 network and perimeter threats over the reporting period. Layered detection translates into faster action as well. The SOC executed over 145,000 automated SOAR containment actions, utilising machine speed to limit disruption and reduce dwell time.
Recommended reading
- Scottish Cyber Awards 2026 | Meet the Finalists
- Report: Public Sector Scottish Cyber Activity 2026
- Cybersecurity Talent Is the UK Job Market’s Hot New Bombshell
Will Ledesma, Director of MDR Cybersecurity Operations at N-able commented: “What we are seeing in 2026 is a return to security fundamentals, with layered defence becoming non-negotiable.
“Attackers are deliberately targeting all business layers, accelerating access to critical assets and compressing response windows. Organisations without depth across the security stack are operating blind, while those built on defence in depth are far more resilient under sustained attack.”
As threat actors diversify tactics and accelerate operations, the advantage increasingly belongs to organisations that can see and act across their entire attack surface. The data underscores a decisive shift toward defence-in-depth, where layered visibility, automated response, and coordinated controls across the security stack are now essential to achieving business resilience.





