Torq has unveiled SOC Brain, a self-learning layer of its AI SOC Platform designed to help security teams investigate and remediate rising alert volumes.
For MSPs and MSSPs, the technology could expand analyst capacity while creating opportunities to deliver deeper, more differentiated security services.
Torq SOC Brain combines precedent with learned judgment
According to Torq, SOC Brain takes a different approach from autonomous investigation systems that retrieve previous cases and feed them to an LLM. The new platform layer reasons from precedent, adapts to how each SOC evaluates risk, and refines its judgment with every completed investigation.
SOC Brain comprises three capabilities: Recall, Reflex, and Retrospect.
- Torq Recall: Uses deterministic matching on security observables to retrieve and rank relevant historical cases, interpret analyst notes, identify conflicting precedents, and adjust confidence based on the available evidence.
- Torq Reflex: Continuously trains dedicated AI models using a SOC team’s confirmed verdicts and corrections, learning how the organization evaluates risk, evidence, and security decisions.
- Torq Retrospect: Imports resolved incidents from existing security tools before deployment, making the organization’s historical knowledge available to Recall and Reflex from day one.
Torq will offer SOC Brain demonstrations to qualified Black Hat USA 2026 attendees at its booth in the Mandalay Bay Convention Center in Las Vegas from August 3 to 6.
Torq CTO says his goal is to reduce burden placed on security teams
Channel Insider spoke with Leonid Belkind, co-founder and chief technology officer at Torq, who said SOC Brain was designed to reduce the cognitive burden placed on security teams.
“The end goal is to shift as much as possible of a cognitive load required to investigate incoming security alerts,” said Belkind.
“For many, many years, while there have been tools available, automation, orchestration, etc., a big chunk of cognitive load of what should be done, what infrastructure I should build, and so on, has been on humans.”
Torq is positioning SOC Brain as a way to take on more of that burden through a “self-learning system” that can reach new conclusions while drawing on an organization’s historical data and context.
How agentic AI can mimic human analysis
Belkind compared the system’s approach to combining a human analyst’s “gut feeling” with the “recall of precedents” when evaluating security alerts. Agreement between those two signals can give the system greater confidence to automate remediation.
“An alert comes in, you get what the system recommends the verdict is. You get a recall of memory with the unique relevance scoring, and you get the reflex,” said Belkind. “How in agreement or disagreement they are is key.”
When those signals conflict, the system must reconcile its learned judgment with the available evidence before determining how to proceed.
“If the gut feeling is, ‘I really want it,’ but the data shows it’s a bad decision, this is where reconciliation kicks in,” Belkind explained. “At the end of the day, we are in the business of remediating threats, not only investigating threats.”
Targeting analyst capacity and MSSP service differentiation
As security vendors continue adding AI to their offerings, Channel Insider asked Belkind how SOC Brain could affect the way MSPs and MSSPs deliver managed security services, including their ability to scale operations and address analyst shortages.
Belkind said the technology could automate high-volume, lower-value tasks, allowing analysts to focus on deeper investigations and other work that delivers greater value to customers.
In his view, providers would gain the most by reinvesting that additional capacity rather than simply using AI to deliver the same services at a lower cost.
“Those who take the opportunity and say, ‘My analysts, my most important precious resource, are now being freed from one load. What brings more value to my customers that they can [now] take upon themselves?’ That, I think, could be industry-impacting.”
He added that this shift could give MSPs and MSSPs another way to differentiate services that customers may otherwise struggle to compare.
“It turns the discussion from purely ‘Who’s cheaper?’ to ‘Who’s better? Who’s more professional? Who’s delivering deeper insights and investigations?’ At least that’s what I’m hoping for.”
Private customer models support data isolation
Because SOC Brain learns from sensitive security data, Torq said each customer receives a private model built exclusively for its organization. The model learns from that customer’s analysts, incidents, policies, and historical investigations.
According to Torq, it does not pool customer data, share model parameters, or train one customer’s AI using another customer’s information. The company says this isolation is built into the platform’s architecture rather than enabled through a configuration setting.
Belkind also said the data and model weights resulting from the training can be confined to a particular region. This allows Torq to address local and regional data residency requirements using the storage, computing, and GPU infrastructure available in that geography.
AI-driven threats increase pressure on security teams
As organizations contend with growing data privacy requirements and AI-enabled threats, Channel Insider asked Belkind how he expects the wider cybersecurity landscape to evolve.
Belkind pointed to the need to relieve security professionals of a mounting volume and variety of security signals, which he said show no signs of plateauing.
He also warned that AI is lowering the barrier to entry for attackers, enabling less sophisticated threat actors to develop capabilities that were previously much harder to obtain.
“People do not multiply at the rate these different security alerts arrive, and people do not get trained in computer science and network security at the same speed. If we do not shift [the] cognitive load, we will fail as an industry.”
Cyber insurance can help MSPs manage the financial impact of data breaches, ransomware, and other digital threats. Compare the top cyber insurance providers for MSPs in 2026, including their coverage options, strengths, limitations, and key policy considerations.





