Agentic artificial intelligence is changing the way security operations centers detect, investigate and respond to cyberthreats by integrating AI into every stage of the workflow. But organizations can realize the greatest value when AI supports analysts, improves operational efficiency and enables deeper investigations instead of replacing human decision-making, said Ben Spencer at Optiv and Wayne Kearns at Google.
The modern AI SOC extends beyond just automating repetitive tasks such as alert triage. AI helps analysts develop detections, summarize investigations, validate findings and accelerate remediation. These capabilities are needed because threat actors are already adopting AI for faster and more sophisticated attacks, though the SOC still needs human oversight.
“The reality is, the attackers have the exact same access to the tooling that we have,” said Spencer, product director at Optiv. “I think human beings are critically important to not just implement these sorts of things, but also to provide human reasoning about what might be missed.”
Organizations need structured frameworks for deploying agentic AI. Optiv and Google Cloud have developed an Agentic MSSP Operations Framework to help managed enterprises mature their security operations while avoiding costly implementation mistakes.
“It’s not just a matter of is AI involved in your SOC operations, but is AI pivotal to every stage of your SOC operation?” said Kearns, senior partner architect at Google Cloud. “Does it help and assist your operators do their tasks as data traverses the pipeline from log ingest to remediation? Is AI there to help them and accelerate them in that process?”
In this audio interview with ISMG, Spencer and Kearns discussed:
How agentic AI can integrate into every stage of modern SOC operations. Why human expertise remains essential despite increasing AI autonomy.
How MSSPs can help organizations move AI initiatives from pilot projects to production deployments while improving security outcomes.
Spencer has worked in IT and security for over 10 years, specializing in Incident response,
detection and response, and threat intelligence. Previously an MDR director and lead incident
responder, he works as product director at Optiv with internal and external stakeholders, as well as
leading multiple teams to make Optiv managed services the best in the market.
Kearns, a senior partner architect for Google Cloud, has been working with companies that do large-scale deployments or assisted appointments for 20 years, and he has focused on cybersecurity for 30 years, supporting companies of all sizes.