As the adoption of AI in the SOC accelerates, companies are moving beyond questioning how it can improve cybersecurity operations. Today, the biggest question most companies have is, “How do we know that our AI spend won’t get out of control?” The first generation of enterprise AI deployments in cybersecurity was sold on outcomes like faster triage, fewer false positives, and analyst hours reclaimed. However, the non-linear math of agentic, multi-thread queries and investigations caused tokens to add up quickly. While protecting against threats and reducing cyber risk, AI has introduced a new kind of risk. One that comes up in the budget meeting.
The challenge is that what makes AI powerful in cybersecurity is its ability to extract meaningful insights from volumes of information. The more you enrich, the better the agent’s work. But, the more you enrich, the more expensive it becomes. The CISO’s job is to drive as much value as possible from a set budget, but as more enrichment data is introduced, the costs can spiral. When AI stops being a capability and starts being a liability, budgets get cut and deployments scaled back. The technology that was supposed to transform the SOC risks getting deprioritized if nobody can make the business case hold up past the first invoice.
How AI Spend Is Upending Security Budgets
Traditional software solutions have relatively predictable costs. Licenses are fixed. Compute scales in ways infrastructure teams understand and can model. AI changes that predictability in ways that procurement and finance leaders are only starting to grapple with. There are stories of companies blowing through a year’s AI budget in a month with no early warning system in place to catch it. This is a potential outcome of AI implementation at this point.
What makes AI powerful in cybersecurity is its ability to run multi-step enrichment investigations, spawn sub-tasks, query multiple data sources, and reason across hundreds of alerts simultaneously. But in doing this, token consumption compounds fast.
We Build to Optimize AI Spend
AI efficiency is integral to our product by design. Rather than asking customers to ration their token usage, we focus on features that help each query do more with less, like scoping an investigation to only the data that matters, or giving analysts a clear view of what the AI intends to do before any tokens are spent.
Other capabilities follow the same logic. Persistent memory ensures that the product builds on what it has learned instead of starting from scratch each time. Keeping context compact as investigations grow saves time and storage, and focusing enrichment on what’s relevant to your environment avoids spending on queries that miss the context.
These features help keep our customers’ usage and spend under control. They also reflect a discipline we’ve built into the product itself: a sustainable approach to AI that extends to how we develop it and how we use and scale it. To realize AI potential, we need to make it efficient and affordable. That’s our approach to AI-powered security products.
Features that Optimize AI Efficiency and Reduce Token Spend
Connector Auto Scoping
Narrows the queries to the connectors that hold meaningful context for a specific investigation. This lowers AI spend while reducing noise and accelerating response time.
Context Awareness
Arms agents with context-specific insights so they can know what alerts and threat intel inputs matter to an organization’s specific risk profile, and which don’t.
Context Compaction
Summarizes the conversation history into a compressed representation, preserving the most relevant information without retaining every raw token exchanged.
Data Dictionary
As the index of all connected data sources, it offers a view of every dataset, field, and path across connectors, helping SOC teams understand what data is available and how to use it.
Persistent Memory
Our product learns from context and from experience. It can self-correct and self-heal, so previous events inform current developments, saving enrichment and investigation time.
Planning Mode
Enables SOC teams to know in real time what assumptions the AI is making, allowing analysts to guide and edit agent-led workflows before using tokens to embark on the wrong initiative.
Eliminating the Surprises in Scaling the AI-SOC
At Andesite, we recognized early on that system architecture deeply impacts AI spend. Cost optimization is a core consideration when evaluating feature development and delivery efforts. We’ve built in strategies to optimize AI efficiency and keep AI spend in check.
Because we understand the challenge that today’s CISOs face in controlling and justifying AI spend, we know that our product must deliver features that help keep spending in check. But thinking of this as purely a cost control problem frames it too narrowly. Operational efficiency for AI has to be built for the people who are actually accountable for the spend, not just the people who built the system.
When security leaders can’t explain AI spend to their leadership, the conversation shifts from outcomes to overhead. At the end of the day, a CISO needs to be able to walk into any room with their CFO, their board, or their auditors and say with confidence: ‘I know what this system is doing, I know what it can cost, I know the risks, and I am in control.’ This is why a more thoughtful approach to token usage needs to be an early part of any conversation about the AI-enabled SOC. At Andesite, that’s where we start.