The Future of the AI SOC: What Black Hat Revealed, with Monzy Merza on The Ravit Show
Conversation on The Ravit Show, published September 3, 2026. Monzy Merza's second appearance on the show.
The show opens on a question most AI security conversations skip: what happens when the AI SOC becomes more expensive, less private, and harder to control? Monzy Merza, Crogl's Founder and CEO, returns to The Ravit Show to work through that, starting from what Black Hat USA 2026 actually revealed about where the AI SOC is heading.
The four questions this episode takes on
The show frames the conversation around four questions that get less attention than they deserve.
- Where does AI genuinely add value in the SOC? Not where it demos well, but where it changes the work.
- Does cybersecurity have a talent shortage, or a productivity problem? The two diagnoses lead to very different spending.
- What happens when security teams pay for every alert and every token? Consumption pricing changes which alerts a team can afford to investigate.
- Should sensitive security telemetry be sent to third-party AI models and cloud providers? The question a regulated buyer asks first and a vendor answers last.
The conversation then goes further into the trade-offs between AI capability, cost, telemetry, and data sovereignty.
Where Crogl stands on each
These are Crogl's published positions, which is useful context for the episode rather than a substitute for it. The conversation goes well past them.
On where AI adds value. Investigation is the bottleneck, not detection. Enterprise SOCs receive around 4,330 alerts a day and investigate roughly 37% of them, so the remaining volume closes without a documented finding. AI earns its place by conducting the investigation end to end and handing an analyst a documented result to decide on, rather than by generating one more recommendation for a human to chase down.
On talent versus productivity. It is a productivity problem that looks like a staffing problem. An investigation runs at the speed of whichever expert happens to be on shift, because each console has its own query language and its own in-house specialist. Removing that expert dependency raises throughput without raising headcount.
On paying per alert and per token. Crogl's pricing carries no per-alert, per-investigation, or per-user fees. A team reviewing 10,000 alerts pays what a team reviewing 10 pays, which is what makes "investigate everything" a decision about coverage rather than a decision about budget.
On telemetry leaving your environment. It does not. Crogl deploys on-premises, in your private cloud, or fully air-gapped, and no data reaches Crogl's infrastructure. Federated search is what makes that work: Crogl queries each source in place, in its own language, so an investigation reaches your SIEM, EDR, identity provider, and data lake without copying any of it into a vendor platform first. Models run where you choose, including fully self-hosted inference, and LLMs never see the secrets behind your connectors.