SOC Fatigue, Revisited: How AI is Contributing to Burnout
Our earlier post on SOC burnout argued that analyst fatigue comes mainly from repetitive data work rather than the complexity of the threats themselves and made the case for automating the tedious layer of the job rather than the analyst. The industry research behind that argument was already a few years old even then.
A Ponemon Institute study run with Devo, surveying 554 IT and security practitioners at organisations with a SOC, found 65% had considered changing careers or leaving their job over burnout related pain points. A 2022 Tines survey of 468 US based analysts found 71% experiencing some level of burnout and 64% saying they were likely to switch jobs within the year. Both studies predate the current wave of AI tooling in the SOC, and I have not been able to find an equivalent large scale, independent study measuring burnout specifically among analysts working in AI assisted SOCs today. Over a year on from our last post, with AI tools now sitting inside a growing number of SOC workflows, it is worth asking what has changed, and what has not, while being honest that the comparison below is reasoned rather than measured.
What Changed When AI Arrived
The promise was straightforward. Hand the repetitive layers of the job, meaning data collection, enrichment, correlation and first pass triage, over to automation and AI tooling, and give analysts back time for the investigative work that drew them into the field. Where that promise has landed, teams report less time lost to manual data wrangling and faster first response on high confidence alerts. That is a genuine gain, and it matches what the earlier post predicted.
What is harder to find is solid, independently verified data on how much SOC wide burnout has fallen as a result. Vendor surveys report improvement, which is what you would expect from a survey run by a vendor selling the tool. Independent, large sample research on burnout specifically among analysts using AI assisted workflows is thinner than the marketing around it. Treat any single statistic on this topic, including ones from HOOP Cyber’s own earlier posts, as directional rather than settled, and measure your own team rather than relying on an industry average.
The New Sources of Fatigue
Removing one source of fatigue does not always mean removing fatigue itself. Teams using AI more heavily in triage report a different kind of tiredness taking its place.
Oversight fatigue is the most reported version. An analyst reviewing 50 AI generated triage decisions a day still must apply judgement to each one, and verifying a machine’s reasoning carries its own mental cost, even when the machine is usually right.
Confidence calibration is a related problem. Analysts need to build an accurate sense of when to trust a tool’s output and when to override it, and that sense takes months to develop. Until it does, teams report either over trusting the tool, which creates risk, or double checking everything, which recreates the manual workload the tool was meant to remove.
There is also a quieter concern around skills. If AI tools handle a growing share of first pass triage, junior analysts get fewer reps at the pattern recognition work that used to build expertise over their first 2 years. That is not fatigue in the traditional sense, but it is a workforce risk worth naming alongside it.
What to Measure Now
If your earlier burnout metrics were built around alert volume and false positive rate, add a second layer: time spent reviewing and correcting AI output, how often analysts override an AI recommendation and why, and how confident junior analysts report feeling in their own judgement compared with 6 months earlier. None of these need to be complicated to track, and they will tell you more about where fatigue has moved to than a repeat of the original burnout survey.
The tools have changed since the first post. The underlying question has not. Give analysts back time for the work that made them want to do this job in the first place, and keep checking whether that is happening, not assuming it is because the dashboard says alert volume is down.
Ready to Modernise?
HOOP Cyber helps security teams audit their data estate, design the routing and normalisation that sits behind it, and rebuild security operations around a data architecture they control. If you cannot currently produce the three pieces of information at the top of this article, that is where we would start. Get in touch via .