Case Study
Global SOC Cuts False Positives, Meets SLAs
A multinational SOC turned to Arcanna Decision Models to reduce false positives, improve consistency, and meet SLAs, proving reliable AI in production.
Challenges
A global team with 4 regional SOCs faced rising alert volumes, SLA breaches, and limited automation. Traditional playbooks couldn't keep pace, and generic AI was dismissed as unreliable. They needed an AI Platform for SOCs that was accurate, consistent, and audit-ready.
Problems They Faced
- High alert volume, high false positives: analysts overwhelmed with benign alerts.
- SLA breaches: backlog slowed response to real incidents.
- Playbook limits: SOAR rules couldn't adapt to edge cases.
- Architecture transition: new cloud-native SOC stack introduced scale challenges.
Solution: Arcanna Decision Models
- Started in Suggest mode – analysts approved/denied AI recommendations, training the model.
- Initial rollout – reliability and learning performance validated within weeks.
- 1-year results - expanded scope confirmed sustained accuracy, reduced false positives, and measurable SLA improvements.
- Seamless SIEM/SOAR integration – worked directly with Google SecOps SOAR, no new stack required.
Competition & Differentiator
Unlike generic GenAI tools dismissed for hallucinations and inconsistency, Arcanna proved:
- Predictable accuracy - models aligned with analyst judgment.
- Explainability - decisions backed by evidence and similarity matches.
- Governance controls - thresholds, HITL, rollback ensured safety.
Metrics & Results
4,546
P1/P2 cases offloaded = 1,136 analyst hours saved potential
18 min → 3 min
MTTT reduced (Analysts vs Arcanna)
93.55%
SLA met percentage (all misses due to SIEM-SOAR delays)
83%
Triage time reduction (4,185 minutes total saved)
Why It Matters for MSSPs
For MSSPs, every analyst must cover multiple tenants. The ability to triple tenant coverage without extra hires depends on reducing false positives and hitting SLA targets. Arcanna's models slot into existing SOAR workflows, so SOC leaders can:
- Serve more clients per analyst without burnout
- Show auditors and customers proof of control
- Maintain margins while scaling operations globally
This case study is anonymized, but for qualified MSSPs and enterprise SOCs, we can arrange a direct introduction to the vendor team that ran this deployment. Book a Demo