The Watch Problem: Who Catches What the Autonomous SOC Misses
In this blog
An old problem
"The civilized man has built a coach, but has lost the use of his feet. He has a fine Geneva watch, but he fails of the skill to tell the hour by the sun. His note-books impair his memory; his libraries overload his wit. It may be a question whether machinery does not encumber; whether we have not lost by refinement some energy."
(Ralph Waldo Emerson, Self-Reliance, 1841)
Emerson was writing about self-reliance, but he was also writing about every major technology disruption that came after him. Security operations are walking into this same trap right now. Automation and improvement were always supposed to be two halves of the same system. Security operations are about to build only one of them.
In the 1880s, London had ten thousand licensed horse cabs. Behind each one, an entire ecosystem: stable workers, harness makers, feed merchants. By 1915, that ecosystem had collapsed. Motor cabs replaced horse cabs within fifteen years, and the old ecosystem did not transition cleanly into the new one (McShane, Clay and Tarr, Joel. The Horse in the City. Johns Hopkins University Press, 2007.).
This pattern repeats. The power loom displaced hand weavers within a working generation. Mechanized agriculture pushed people off the land where they were no longer needed. Electricity killed ice harvesting, gas lamps and kerosene supply, and their entire ecosystems, within three decades. The trend holds: each transition is genuinely brutal at the individual level and unambiguously positive at the civilizational level. Good for humanity, hard for specific humans.
I believe it's the honest lens for AI in security operations, too. But something is different this time.
Skills displaced
Take the horse cab transition. The institutional knowledge built around that ecosystem wasn't needed in the next generation. Urban vets moved to rural areas. Saddles were still made, just at a fraction of the scale. None of those skills translated to the automobile. A veterinarian didn't become a mechanic. A saddle maker didn't become one either. Even the years spent building real skill as a horse rider became moot. The carriage driver could switch to motor vehicles, sure, but the skills required were entirely different, and at the time, automobiles were genuinely new to the world. Nobody had years of hand-earned intuition about internal combustion that automation was erasing. There was nothing to lose because nothing had been built yet.
That is not what's happening in security operations.
Tier one analysts perform triage. Hundreds of alerts a shift, severity assessments, escalation decisions. It's grinding work, and it's a real reason we hear about burnout constantly (48% of cybersecurity professionals feel exhausted from trying to stay current on the latest threats and emerging technologies, and 47% feel overwhelmed by the workload. That's from the ISC2 2025 Cybersecurity Workforce Study, published December 2025) . AI SOC platforms legitimately fix this problem. That's a good thing.
But triage is where security analysts are made.
The mental model that produces a senior responder, a threat hunter, it isn't taught in a certification course. It's built over years of repetition with real stakes at the end. An analyst who has seen fifty thousand alerts in every shape and size has developed something you cannot shortcut. Intuitive pattern recognition. A feel for what looks "off" before you can articulate why. The ability to find the path without needing directions. It only comes from walking it.
Automate away tier one, and you close tickets faster. You also close the pipeline.
The senior analyst six years from now is the tier one analyst of today. If that analyst never builds the foundation, never hones the investigative instinct, triage forces you to rely on the bench when you need it. It won't be visible right away, either. It'll erode quietly, year over year, with less and less real threat exposure, until you notice all at once: a novel technique appears, the AI flags it as unknown, hands it to a human, and the human has spent three years watching dashboards instead of hunting. The judgment isn't there. It was never built.
Other industries have already learned this
Other high-stakes domains have already built formal responses to exactly this failure mode.
- Aviation built Upset Prevention and Recovery Training after Air France 447 in 2009 and AirAsia in 2014, the same failure mode five years apart, nearly four hundred dead. Pilots who hadn't hand-flown in years couldn't recover their aircraft once autopilot disengaged. The FAA mandated recurring hand-flying qualifications. The industry had to rebuild the skill it had automated away. (Both of those final reports can be found: BEA Final Report, Air France Flight 447, July 2012 and KNKT Final Report, AirAsia QZ8501, December 2015).
- The Institute of Nuclear Power Operations (INPO) formed after Three Mile Island in 1979. Operators misread instruments, missed a stuck-open valve and made a partial meltdown worse. The operators self-organized before any regulator forced their hand: mandatory simulator time, peer review across plants, standardized training. American commercial nuclear hasn't had a second Three Mile Island in 45 years, and that doctrine is why. (For further reading: Report of the President's Commission on the Accident at Three Mile Island (Kemeny Commission), 1979. Nuclear Regulatory Commission)
- Surgery built Advanced Trauma Life Support and the Morbidity and Mortality (M&M) conference. Every death gets reconstructed in front of the full medical team, not to assign blame, but to extract the curriculum. Every failure becomes a teaching moment, on purpose, as a structural feature of the profession.
Security operations teams have none of this. No regulator with real teeth. No INPO equivalent. No M&M conference, outside of the occasional internal after-action review. The doctrine simply does not exist yet.
The compliance counterargument
"But Zach, we have CISA's 72-hour rule, and SEC disclosure requirements."
We do, and they matter. But look at what they actually capture: timeline of discovery, nature of the data, regulatory exposure and remediation taken. That list is designed for lawyers and regulators. It does nothing for the practitioners inside the SOC. There's no review of the missing telemetry that would have helped the investigation. No documentation of the judgment calls that got missed. No public accounting of which security platforms failed to catch which piece of the attack lifecycle. Breach notifications are built to minimize liability. M&M conferences are built to make surgeons better. That's the entire difference.
We know why the technical details stay internal. The moment an incident happens, legal steps in before incident response is even finished, and the report gets shaped around liability, not learning. The detection gap, the lateral movement technique that went unnoticed, the automation that quietly failed, none of it leaves the organization. Most of the time, it never leaves legal and IT.
INPO's operators made a calculation: the potential cost of a second Three Mile Island incident pushed sharing failure data with competitors worthwhile. Security hasn't made that calculation yet, partly because we haven't been forced to, and partly because our compliance mechanisms only check whether a process exists, not whether it produces anything real. A framework that verifies existence instead of depth will only ever produce the appearance of rigor.
The result: thousands of breaches a year, each one containing a lesson for every SOC and every practitioner in the industry, and none of it propagates. Every SOC relearns the same lessons in isolation. The same failures repeat, indefinitely, because nothing is built to stop them from repeating.
There's a better counterargument than compliance, though, and it deserves a real answer: won't AI trained on enough incident data eventually produce the next generation of incident responders itself? The machine learns faster. It works 24 hours a day. Why do we need the human at all?
The answer is simpler than that, and it's architectural. AI learns from patterns it has already seen. Novel adversary tradecraft, by definition, is not in that training data. The analyst who spent years building real intuition through incidents with real stakes can reason about something they've never encountered before. Operating in the gap between what the model knows and whatever the adversary just invented is the actual job. Deskill the humans who are supposed to live in that gap, and you've built analysts who've never learned to operate without the machine, which is precisely the failure mode you need them to handle the day the machine is wrong.
The missing half: Jidoka
WWT's ARGUS framework was built to solve a speed problem: the attacker moves in seconds, the analyst moves in minutes, and the architecture closes that gap through autonomous detection, enrichment, and containment across six enforcement domains.
ARGUS already borrows half of this doctrine, even if it never named it. The Andon Cord principle (again, Toyota): stop the line, hand control to a human. Jidoka: autonomous detection and containment, with a mandatory human checkpoint built into the architecture. That part is solved.
What ARGUS doesn't yet name is the other half of the system it borrowed from. At Toyota, Jidoka was never a standalone practice. Every line stop triggered Kaizen, the discipline of investigating root cause and feeding that finding back into the process, so both the system and the humans running it got sharper every single time the line stopped. Toyota didn't just want defects caught. They wanted every stoppage to compound expertise among the people closest to the work, not as a training initiative run once a quarter.
That's the piece missing from autonomous SOC design right now, ARGUS included. The architecture handles the stop and hands off with full context. But nothing in it asks whether that handoff builds the analyst's judgment or just closes the ticket faster. Right now, the default is: AI generates the summary, human reviews it, and then moves on. That's Jidoka without Kaizen. You get the stop. You don't get the improvement loop, and you especially don't get it in the resource that was supposed to come out of this sharper, not dumber.
Call it the Kaizen Layer. Autonomous containment without a deliberate doctrine for building human judgment doesn't solve the problem ARGUS was built to prevent. It relocates it, from the machine to the analyst who will eventually have to catch what the machine can't.
Where this goes
This problem exists at two levels, and the fix has to match.
At the industry level, the question is whether security operations can build the collective infrastructure that aviation, nuclear and surgery built, the shared postmortem architecture, the workforce competency standards and a body that treats analyst capability as a shared problem rather than a competitive differentiator. That is a longer conversation, and a harder one.
At the individual level, the question is what a SOC leader can do inside their own organization right now, without waiting for the industry to move. That answer exists. It is not complicated. Both conversations are worth having in full. This is not the piece for them.
Closing
The pilots of Air France 447 didn't fail because the autopilot disengaged. They failed because no one had made them hand-fly in years. Automation had quietly rendered the skill unnecessary.
Security operations is building that same system right now. The metrics will look better. The dashboards will look cleaner. AI will absorb the workload and very likely ease the burnout that's been driving people out of this field for years. But somewhere inside the efficiency being gained, the pipeline that produces the next generation of judgment is quietly closing.
Emerson's Geneva watch keeps perfect time, right up until the moment you actually need it, and the watch is gone.
The question isn't whether autonomous SOC operations are coming. They already are. The question is whether we build the Kaizen Layer before our version of the crash, or whether security learns this lesson the exact same way every other industry already has.