How AI Is Changing Threat Detection for San Francisco Businesses

How AI Is Changing Threat Detection for San Francisco Businesses
Dale Roberts 450px png

DALE ROBERTS

Dale discovered his penchant for technology while working on radars during his time in the US Navy. He built on that experience with stints at tech firms, both nationally and internationally, eventually founding Centarus to help small companies leverage technology to grow their businesses. 

Most security tools are built to catch attacks that already have a signature, like a known virus or a blocklisted IP address. AI threat detection is built for what doesn’t have one yet, like a login that looks almost normal or a file transfer that’s just slightly too large. Here’s how that works inside a modern security operations center and what it means for businesses across the Bay Area. 

What AI threat detection looks like inside a modern SOC 

A security operations center, or SOC, is the team and toolset responsible for watching a network around the clock. Analysts inside a SOC review login activity and network traffic, checking for anything that suggests a problem. The system that feeds them this information is called a SIEM, short for security information and event management. It pulls activity data from email, cloud apps, endpoints, and firewalls into one place, so analysts aren’t checking a dozen separate dashboards during an active incident. 

For years, SOC teams relied mostly on fixed rules that flag a specific action the moment it happens. That approach works for known threats, but it struggles with anything new. AI threat detection adds a second layer on top of those rules, one that learns what normal activity looks like for a specific network and flags anything that deviates from it, even without a rule written for that exact scenario. Centarus’s SOC and SIEM service page covers how the two systems work together in practice. 

Where machine learning fits into AI-powered cybersecurity monitoring 

Machine learning models used in threat detection are trained on large volumes of network behavior, like what a typical login looks like or how large a normal file transfer tends to be. Once a model has that baseline, it can flag activity that falls outside it within seconds. Manual review can take hours to reach the same conclusion. 

CISA’s own approach to AI-assisted threat hunting follows a similar principle, automating the correlation of large volumes of network log data so analysts can focus on the anomalies that need review, rather than sorting through raw data by hand. It narrows down what needs attention first, which matters when a SOC is watching thousands of events an hour. 

What AI-powered detection catches that manual monitoring misses 

A few examples illustrate the difference. An employee who typically logs in from San Francisco during business hours suddenly authenticates from overseas at 3 a.m. A system built only on fixed rules might miss this if the credentials themselves are valid. A model trained on that employee’s usual pattern flags the mismatch right away. 

Lateral movement is another case worth knowing about. Once an attacker gets a foothold on one device, they often try to move to other systems next, looking for the ones that hold sensitive data before making a bigger move. Because attackers frequently use legitimate credentials to do this, the activity can look like normal user behavior to a rules-only system. CISA’s guidance on detecting insider threats makes a related point about detection depending on both human observation and technical monitoring. 

Insider threats fall into a similar category, whether that’s a departing employee downloading files they shouldn’t, or an account behaving in a way that doesn’t match a person’s normal role. None of these look like an obvious red flag on their own. What makes them detectable is the pattern across several small signals, which is what these models are built to catch. 

Why small businesses in the Bay Area are targets too 

It’s tempting to assume attackers go after large enterprises with more to steal, but the data doesn’t support that. In Verizon’s 2025 Data Breach Investigations Report, ransomware was linked to 88% of breaches at small and medium-sized businesses, compared with 39% at larger organizations. AI cybersecurity for small business matters just as much here, since smaller firms often carry client data, financial records, case files, and health information without the same monitoring budget as a larger company. 

For law firms, financial services firms, insurance agencies, and nonprofits across San Francisco, that difference in monitoring matters more than most owners realize, since client trust and regulatory obligations are tied directly to how well that data gets protected. A missed anomaly at a firm like this can carry consequences beyond IT, including a breach notification requirement or a difficult explanation to a client about how their data was handled. Centarus’s cybersecurity services page covers the layers involved, from endpoint protection through the SOC itself. 

How Centarus pairs AI monitoring with human oversight 

Centarus runs SOC services for Bay Area businesses built around a managed SIEM for San Francisco clients. The approach combines AI-powered monitoring that flags anomalies as they happen with a team of analysts who review what the models surface before deciding on next steps. The AI layer handles the volume, sorting through network activity and login attempts around the clock, while analysts handle judgment calls that need context a model doesn’t have, like whether a login from a new city is a business trip or a stolen password. 

The managed SIEM platform behind this, built with Perch, pulls activity from Microsoft 365, Microsoft Entra ID (formerly Azure Active Directory), and other cloud environments into a single feed, so nothing gets missed because it happened in a system no one was watching that day. Centarus is SOC2 Type 2 certified, meaning the process behind that monitoring has been independently audited. 

The bottom line 

If your current monitoring setup depends mostly on manual review or a handful of fixed alert rules, it’s worth checking whether it would catch a threat that moves slowly, the kind that never trips an obvious alarm. Want to know if your current security monitoring is keeping up? Get in touch with our team for a free security assessment.