Security outcomes

Production data from a governed loop.

Automation speeds up work. It doesn't remove the decision burden. A system where the Governor, not a ticket queue, decides when a case closes does.

These aren't isolated improvements

The same three numbers from the homepage. This page goes deeper on where they come from.

%
MTTD ↓Reduction in mean time to detect
%
MTTR ↓Reduction in mean time to respond
%
Primary outcomeAutonomous ↑Investigations resolved without a human

The deeper numbers

What sits underneath the headline three.

~150 hrsAnalyst Hours Removedper day from investigation and triage
~7XSecurity ROIreturn on autonomous SOC operations
5–10%Escalation Rateof investigations reach a human
<2%False Positive Rateverified against analyst-confirmed incidents
Why this matters

The four outcomes of switching to Sirp

Human SOC
  • Detection~5 min
  • Ticket~15 min
  • Assignment~20 min
  • Investigation~95 min
  • Approval~40 min
  • Action~10 min
Autonomous SOC
  • Detection~5 sec

    Covers ticket, assignment, investigation, approval

  • Evaluation~55 sec
  • Action~15 sec
Total time0.0 hrs
Total time0 sec
Human SOC total 3.1 hrs. Autonomous SOC total 75 sec. Same incident, resolved 148x faster.
Gate-to-execution, not queue-to-pickup

Response speed becomes structural

The Autonomy Gate fires per action, before execution, not after a human picks up a ticket. Decision and execution happen in the same step. Containment windows for ransomware and lateral movement are measured in minutes. When your gate-to-execution time is seconds, you're inside that window.

~1,500 investigations/day resolved autonomously

Volume stops scaling with headcount

The Executor runs whatever the Gate allows, without waiting on analyst availability. Alert volume can grow without a matching hiring plan, because nothing in the loop is rate-limited by a person's calendar.

150 analyst hours/day → <1 hour/day

Analyst work changes completely

The Decision Governor issues one of three verdicts per case: close it, escalate it, or send it back to the Planner with a delta. Only the escalate verdict reaches a person, and Sara is what surfaces it with the reasoning attached, not a bare alert.

$800K–$1M → ~$100K annually

The cost curve flattens

Planner reasoning runs on compute, not on shift coverage. Cost tracks alert volume the way infrastructure cost tracks usage, not the way payroll tracks headcount.

Real Deployments

Real deployments

CASE // FIN-04
+
Global fintech SOC
120K alerts/day4 regionsHighly regulated
Before Sirp

11 analysts, approval gates, 4–6 hour case age

After Sirp

2 analysts on oversight, under 30 second case age, under 5% human review

Results

7x cost reduction, zero audit findings, more thorough compliance documentation

The unexpected

"Audit trail improved. Automated logging turned out more complete than manual documentation ever was."

CASE // SAAS-01
+
SaaS infrastructure company
Cloud-nativeHigh analyst turnoverAlert fatigue
Before Sirp

Tiered L1 to L2 to L3 escalation model

After Sirp

System-first resolution, single oversight team

Results

92% autonomous actions, zero routine escalations, team stayed intact

The moment

"Running in parallel for 30 days, the autonomous system caught three incidents the human team missed to queue backlog. That ended the internal debate."

Why these metrics move together

This isn't five separate improvements. It's one architectural change, measured five ways.

Planner

Reasons about what an alert needs and proposes every action. It approves none of them, so speed here doesn't trade off against control.

Autonomy Gate

Checks each proposed action against policy before it runs, per action type, not per platform. This is where response-speed and false-positive numbers both originate: the same check that keeps latency low is the check that keeps error rate low.

Executor

Runs only what the Gate allowed. This is where the headcount-decoupling comes from. Nothing here waits on an analyst's queue position.

Decision Governor

Fires once, after the run, and issues one of three verdicts. The 90% autonomous-actions figure and the 5–10% escalation rate are the same number, seen from opposite sides: cases the Governor closed vs. cases it sent to a human.

CloseEscalateReturn to Planner

The key difference: decision placement.

Workflow automation makes humans faster at the same job. This loop removes humans from the execution path and gives them the judgment calls instead. That's why MTTD, MTTR, cost, and analyst hours all move together — they're all downstream of where the decision gets made, not five separate product features.

What the system doesn't handle

This is the Governor's second verdict: escalate.

It fires when:

  • Confidence falls below policy threshold
  • The attack pattern is novel or outside training data
  • Context requires business knowledge the system doesn't have
  • Multiple conflicting signals produce ambiguous risk

Escalation rate: 5–10% of investigations

False positive rate: <2%

Humans handle ambiguity and strategy. The system handles volume and routine execution.

#6707
CriticalHighOpen

2025-06-26 09:32 AM

Rewterz — IPS Traffic Accepted from Malicious source.

Malware
Stream of autonomously triaged alerts

How we measured this:

3 enterprise SOCsFintech, SaaS, and healthcare. Case studies below cover the fintech and SaaS deployments.
90-day window90-day window post-stabilization (excludes tuning and pilots).
Millions of alertsMillions of alerts across EDR, cloud, identity, SaaS, endpoint.
Full chain measuredDetection → triage → decision → containment

Excluded: Test incidents, training data, simulations, deployment phase, cases requiring human judgment

Read the full methodology in the Trust Center

What this means for your SOC

If your SOC depends on human availability, tickets, and shift coverage, your performance is capped by how fast analysts work and how many you can hire.

When decisions are policy-bound and system-executed, response speed becomes predictable, cost becomes flat, quality becomes consistent, and scale becomes an infrastructure question.

The operating model changes. The outcomes follow.