AI All-in-One series · Security operations

AI-Powered SOC All-in-One by Kai London

Adding AI to a badly instrumented SOC produces faster noise. This book builds the autonomous security operations centre in the right order — telemetry, detection engineering, then automation — and is honest about which decisions must stay with a human.

Available on Amazon.

What is inside

The operating model

Roles, tiers and workflows for a SOC where agents do the first pass and analysts do the thinking.

Telemetry and data foundations

Log quality, coverage and cost control — because every automation inherits the gaps beneath it.

Detection engineering

Writing, testing and versioning detections, with ATT&CK coverage measured rather than assumed.

Triage and enrichment with AI

Where models genuinely reduce time to decision, and where they quietly manufacture confidence.

SOAR and response automation

Playbooks, safe actions, approval gates and rollback when the automation is wrong.

Threat hunting and metrics

Hypothesis-driven hunting, and the small set of measures that tell a leadership team the SOC is improving.

Who it is for: SOC managers and detection engineers modernising their operation, incident responders, MSSP leadership, and CISOs funding SOC transformation.

MITRE ATT&CKNIST CSF 2.0NIST SP 800-61NIST AI RMFISO/IEC 27001

Automate the toil. Keep the judgement. Measure both.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.