For decades, cyber defense operated on a timeline measured in weeks. When a new vulnerability was discovered, an adversary typically took 15 to 20 days to analyze the code, develop an exploit and weaponize it. This buffer gave defenders a window to patch systems or adjust firewalls.
That window has closed.
As nation-state actors incorporate artificial intelligence and generative AI into their offensive strategies, the window between discovery and exploitation has diminished from weeks to hours, often occurring before a vulnerability is officially announced. In this new environment, the security of the Defense Department, its agencies, the defense industrial base (DIB) and critical infrastructure depends on how well the department’s AI-driven reconnaissance and countermeasures can outpace the adversary.
A significant example of a recent AI-driven attack with broad national security implications is the 2024-2025 Salt Typhoon campaign, in which China-linked hackers used AI-accelerated techniques to breach U.S. telecommunications providers, affecting critical infrastructure and government communications, and potentially compromising data from nearly every American.
]]>
In response to AI-driven attacks, the military can deploy an agentic-AI-powered Risk Operations Center (ROC) that goes beyond passive monitoring to autonomous, real-time threat neutralization. The best way to match AI attack speed is for defenders to understand how to leverage the same AI tools themselves; but do it better. Agentic AI — autonomous, goal-driven software — enables AI systems to defend themselves, detect threats and make decisions.
The ROC complements but moves beyond the SOC
A ROC signals a shift from risk detection to risk mitigation. While a traditional security operations center (SOC) focuses on incident and log monitoring to identify breaches, the ROC emphasizes protecting the asset. Success isn’t judged by how many alerts are resolved but by how much the agency’s risk index has decreased, indicating a lower likelihood and impact of a security incident.
For commanders and the warfighter, this means the ROC offers an ongoing cycle of:
Contextualization: Precisely identifying assets on a ship or at a forward operating base that need to be secured.
Prioritization: Identifying which vulnerabilities matter to the mission, such as bugs in the ship’s navigation system or flaws in the Army’s Command and Control systems connecting leaders with units in the field.
Remediation: Automating the fix before an adversary can weaponize the flaw.
The rise of agentic AI-powered ROCs
Unlike traditional AI, which might simply flag a suspicious login and alert a human analyst, agentic AI is goal-driven. It doesn’t just perceive a threat; it acts to resolve it. In an AI-powered ROC, agents can operate as a connected chain of command.
For example, during an active intrusion, an initial agent detects an anomaly. Instead of waiting for a human analyst, it activates a downstream agent to gather context. This second agent queries the Configuration Management Database (CMDB), reviews patch history and evaluates the system’s stability. It considers: If I shut down this port to stop the attack, will I disrupt the agency’s network? By analyzing these dependencies, the agentic AI ROC can update firewalls or apply Intrusion Prevention System (IPS) signatures at machine speed.
Pushing AI to the edge for the disconnected warfighter
The United States has a distinct advantage in this new era of AI-driven cyberwarfare. The country possesses energy resources, skilled talent and robust infrastructure. However, the current defensive stance remains overly manual, especially when human-dependent processes fall short against machine-speed attacks.
Consider a Navy destroyer in the middle of the Pacific. It is a floating city with severe bandwidth constraints. It cannot reach a cloud-based AI at a land-based location to ask how to handle a cyberattack. If AI isn’t on the ship, the ship is undefended.
]]>
AI capabilities must be deployed to the edge — to the individual Marine unit, the aircraft and the disconnected ship. This enables the warfighter to stay protected even without connectivity. This edge AI also serves as a force multiplier for junior personnel. In the field, a junior sailor or Marine might not have 20 years of cybersecurity experience, but with a GenAI interface, they can use natural language to request a risk assessment. This instantly turns basic operators into defenders.
The architecture of a distributed ROC
To manage threats, defense agencies cannot rely on a single, centralized command. Instead, they need a distributed system of risk prioritization that works across agencies and commands, providing:
The asset intelligence engine: As the adage goes, “You cannot protect what you cannot see.” This layer provides a machine-readable inventory of every asset. In the modern theater, this includes not just IT but also operational technology (OT), industrial Internet of Things (IoT) and edge devices.
The agentic reasoning layer: Connected agents work together to automate risk mitigation and gather relevant data for analysis. If one agent finds a threat, it triggers others to investigate the mission impact.
The threat intelligence feed: Agent-based AI relies on strong connections to threat databases. These agents make decisions a human would normally make — such as updating firewalls or applying IPS signatures — based on specific system needs, whether it’s a desktop or a ship’s engine control system.
The paper fortress is the real vulnerability
The most sophisticated agentic AI in the world will fail if it is fed a diet of paper. Currently, the military’s approach to cyber risk is heavily document centric. Agencies generate 800-page System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms) to comply with policy.
However, you cannot fight a cyber war with paper.
To achieve the speed required for AI-driven defense, every aspect of cyber risk management must be machine-readable. Cyber teams need to understand the state of an application — its assets, vulnerabilities and dependencies — and present it in a format that an AI agent can quickly ingest and act upon.
Until defense and government agencies shift from static documentation to dynamic, machine-readable data, manual processes will remain a bottleneck that adversaries can exploit. Defense agencies are trying to compete in a digital race while tied to a paper-based system.
]]>
But the future is promising.
The future shift from static checklists to real-time risk management
The future of national defense isn’t just about faster software; it’s about real-time risk management. The Pentagon is currently moving to expand risk management beyond the era of static checklists, PDFs and manual snapshot-in-time processes.
In September 2025, the Cyber Security Risk Management Construct (CSRMC) was introduced to lead the Pentagon leaders and warfighters into a new era of automation, live dashboards and continuous monitoring. The agentic AI-driven ROC easily aligns with this new standard.
Achieving continuous ATO
The core of the CSRMC is the requirement for ongoing monitoring to sustain continuous Authority to Operate (cATO). Previously, a system might be authorized once every three years. In a world with AI-driven attacks, that three-year-old paper approval becomes meaningless.
An agentic AI-powered ROC aligns with this risk management construct by providing:
24/7 persistent vigilance: AI agents operate around the clock, continuously analyzing data and identifying threats within seconds rather than waiting for periodic reviews.
Active control validation: Agents continuously monitor critical controls, ensuring they are not just on paper but actively protecting production environments in real time.
Automated dashboards: Instead of an 800-page SSP, the ROC provides live telemetry that shows commanders the mission’s actual risk posture at any moment.
The AI-powered ROC is a strategic pivot
The shift to an agentic AI-powered ROC is more than just a technical upgrade; it is a strategic necessity. The adversary has already automated their offensive weapons. Defense agencies must automate their defensive shields. By deploying goal-oriented AI at the edge, streamlining data-flow command structures and digitizing compliance frameworks, the Pentagon can ensure its applications, networks and systems have the capability and resilience to identify, prioritize and mitigate cyber risks in the age of AI-driven attacks.
Jonathan Trull is executive vice president and general manager of risk management, and chief information security officer at Qualys.
Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.