{"id":58184,"date":"2026-06-01T20:26:16","date_gmt":"2026-06-01T20:26:16","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/58184\/"},"modified":"2026-06-01T20:26:16","modified_gmt":"2026-06-01T20:26:16","slug":"why-the-agentic-ai-powered-roc-is-the-new-frontline-of-defense","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/58184\/","title":{"rendered":"Why the agentic AI-powered ROC is the new frontline of defense"},"content":{"rendered":"<p>For decades, cyber defense\u00a0operated\u00a0on a timeline measured in weeks. When a new vulnerability was discovered, an\u00a0adversary\u00a0typically took 15 to\u00a020 days\u00a0to analyze the code, develop an exploit and weaponize it. This buffer gave defenders a window to patch systems or adjust firewalls.<\/p>\n<p>That window has closed.<\/p>\n<p>As nation-state actors incorporate artificial intelligence and generative AI into their offensive strategies, the window between discovery and exploitation has diminished from weeks to hours, often occurring before a vulnerability is\u00a0officially announced. In this\u00a0new environment, the security of the Defense Department, its agencies, the defense industrial base (DIB) and critical infrastructure\u00a0depends on how well\u00a0the\u00a0department\u2019s AI-driven reconnaissance and countermeasures can outpace the adversary.<\/p>\n<p>A significant example of a recent AI-driven attack with\u00a0broad national security\u00a0implications\u00a0is the\u00a0<a href=\"https:\/\/industrialcyber.co\/critical-infrastructure\/us-homeland-security-committee-warns-of-rising-cyber-threats-as-federal-shutdown-and-lapsed-law-hamper-defenses\/#:~:text=The%20Homeland%20Security%20Committee%20snapshot%20disclosed%20that%20roughly%2070%25%20of,data%20from%20nearly%20every%20American.\" rel=\"nofollow noopener\" target=\"_blank\">2024-2025 Salt Typhoon campaign,<\/a>\u00a0in which China-linked hackers used AI-accelerated techniques to breach U.S. telecommunications providers, affecting critical infrastructure and government communications,\u00a0and potentially compromising data from\u00a0nearly every\u00a0American.<\/p>\n<p>]]><\/p>\n<p>In response to AI-driven attacks, the military can deploy an\u00a0agentic-AI-powered Risk Operations Center (ROC) that goes beyond passive monitoring to autonomous, real-time threat neutralization.\u00a0The best way to match AI attack speed is for defenders to understand how to\u00a0leverage\u00a0the same AI tools\u00a0themselves;\u00a0but do it better.\u00a0Agentic AI\u00a0\u2014\u00a0autonomous, goal-driven software\u00a0\u2014 enables AI systems to defend themselves, detect threats and make decisions.<\/p>\n<p>The ROC complements\u00a0but\u00a0moves\u00a0beyond\u00a0the SOC\u00a0<\/p>\n<p>A ROC signals a shift from risk detection to risk mitigation. While a traditional security operations center (SOC) focuses on incident and log monitoring to\u00a0identify\u00a0breaches, the ROC emphasizes protecting the\u00a0asset. Success\u00a0isn\u2019t\u00a0judged by how many alerts are resolved but by how much the agency\u2019s risk index has decreased,\u00a0indicating\u00a0a lower likelihood and impact of a security incident.<\/p>\n<p>For commanders and the warfighter, this means the ROC offers an ongoing cycle of:<\/p>\n<p>Contextualization:\u00a0Precisely\u00a0identifying\u00a0assets on a ship or at a forward operating base that\u00a0need\u00a0to be secured.<br \/>\nPrioritization:\u00a0Identifying\u00a0which vulnerabilities\u00a0matter\u00a0to the mission, such as\u00a0bugs\u00a0in the ship\u2019s navigation system\u00a0or flaws in the Army\u2019s Command\u00a0and\u00a0Control systems connecting leaders with units in the field.<br \/>\nRemediation:\u00a0Automating the fix before an adversary can weaponize the flaw.<\/p>\n<p>The rise of agentic AI-powered ROCs<\/p>\n<p>Unlike traditional AI, which might simply flag a suspicious login\u00a0and alert a human analyst,\u00a0agentic AI is\u00a0goal-driven. It\u00a0doesn\u2019t\u00a0just perceive a threat; it acts to resolve it. In an AI-powered ROC, agents\u00a0can\u00a0operate\u00a0as a\u00a0connected\u00a0chain of\u00a0command.<\/p>\n<p>For example, during an active intrusion,\u00a0an initial\u00a0agent detects an anomaly. Instead of waiting for a human analyst, it activates a downstream agent to gather context. This second agent queries the Configuration Management Database (CMDB), reviews patch\u00a0history and\u00a0evaluates the system\u2019s stability. It considers: If I shut down this port to stop the attack, will I disrupt the agency\u2019s network? By analyzing these dependencies, the\u00a0agentic\u00a0AI\u00a0ROC can update firewalls or apply Intrusion Prevention System (IPS) signatures at machine speed.<\/p>\n<p>Pushing AI to\u00a0the edge for the disconnected warfighter<\/p>\n<p>The United States has a distinct advantage in this new era of AI-driven cyberwarfare. The country\u00a0possesses\u00a0energy resources, skilled talent and robust infrastructure. However, the current defensive stance\u00a0remains\u00a0overly manual, especially when human-dependent processes fall short against machine-speed attacks.<\/p>\n<p>Consider a Navy destroyer in the middle of the Pacific. It is a floating city with severe bandwidth constraints.\u00a0It cannot reach a cloud-based AI at a land-based location to ask how to handle a cyberattack.\u00a0If AI\u00a0isn\u2019t\u00a0on the ship, the ship is undefended.<\/p>\n<p>]]><\/p>\n<p>AI capabilities must be deployed to the edge \u2014 to the individual Marine unit, the\u00a0aircraft and the disconnected ship. This enables the warfighter to stay protected even without connectivity. This edge AI also serves as a force multiplier for junior personnel. In the field, a junior sailor or Marine might not have 20 years of cybersecurity experience, but with a GenAI interface, they can use natural language to request a risk assessment. This instantly turns basic operators into defenders.<\/p>\n<p>The architecture of a distributed ROC<\/p>\n<p>To manage threats, defense agencies cannot rely on a single, centralized command. Instead, they need a distributed system of risk prioritization that works across agencies and commands, providing:<\/p>\n<p>The asset intelligence engine:\u00a0As the\u00a0adage\u00a0goes, \u201cYou cannot protect what you cannot see.\u201d This layer provides a machine-readable inventory\u00a0of\u00a0every asset. In\u00a0the\u00a0modern\u00a0theater, this includes not just IT but also operational technology (OT), industrial Internet of Things (IoT) and\u00a0edge devices.<\/p>\n<p>The agentic reasoning layer:\u00a0Connected\u00a0agents work together to automate risk mitigation and gather relevant data for analysis. If one agent finds a threat, it triggers others to investigate the\u00a0mission\u00a0impact.<\/p>\n<p>The threat intelligence feed: Agent-based AI relies on strong connections to\u00a0threat\u00a0databases. These agents make decisions a human would normally make \u2014 such as updating firewalls or applying IPS signatures \u2014 based on\u00a0specific\u00a0system\u00a0needs,\u00a0whether\u00a0it\u2019s\u00a0a desktop or a\u00a0ship\u2019s\u00a0engine control system.<\/p>\n<p>The paper fortress is the real vulnerability<\/p>\n<p>The most sophisticated\u00a0agentic AI in the world will fail if it is\u00a0fed\u00a0a diet of paper. Currently, the military\u2019s approach to cyber risk is heavily\u00a0document\u00a0centric.\u00a0Agencies\u00a0generate 800-page System Security Plans (SSPs)\u00a0and\u00a0Plans\u00a0of Action and Milestones\u00a0(POA&amp;Ms) to\u00a0comply with\u00a0policy.<\/p>\n<p>However, you\u00a0cannot fight a cyber war with paper.<\/p>\n<p>To achieve the speed\u00a0required\u00a0for AI-driven defense, every aspect of cyber risk management must be machine-readable. Cyber teams need to understand the state of an application \u2014 its assets, vulnerabilities and dependencies \u2014 and\u00a0present it in a format\u00a0that an AI agent can quickly ingest and act upon.<\/p>\n<p>Until defense and government agencies shift from static documentation to dynamic, machine-readable data, manual processes will\u00a0remain\u00a0a bottleneck that adversaries can exploit. Defense agencies are\u00a0trying\u00a0to compete in a digital race while tied to a paper-based system.<\/p>\n<p>]]><\/p>\n<p>But the future is promising.<\/p>\n<p>The future shift\u00a0from\u00a0static checklists to real-time risk management<\/p>\n<p>The future of national defense\u00a0isn\u2019t\u00a0just about faster\u00a0software;\u00a0it\u2019s\u00a0about real-time risk management. The\u00a0Pentagon\u00a0is currently moving to expand risk management beyond the era of static checklists, PDFs and manual snapshot-in-time\u00a0processes.<\/p>\n<p>In September 2025,\u00a0<a href=\"https:\/\/media.defense.gov\/2025\/Sep\/24\/2003808112\/-1\/-1\/1\/DOD-CIO-CYBER-SECURITY-RISK-MANAGEMENT-CONSTRUCT.PDF\" rel=\"nofollow noopener\" target=\"_blank\">the Cyber Security Risk Management Construct<\/a>\u00a0(CSRMC) was introduced to lead the Pentagon\u00a0leaders and warfighters\u00a0into a new era of automation, live dashboards and continuous monitoring. The agentic AI-driven ROC easily aligns with this new standard.<\/p>\n<p>Achieving continuous ATO<\/p>\n<p>The core of the CSRMC is the requirement for ongoing monitoring to sustain\u00a0continuous\u00a0Authority to Operate (cATO). Previously, a system might\u00a0be\u00a0authorized\u00a0once every three years. In a world with AI-driven attacks, that three-year-old paper\u00a0approval becomes meaningless.<\/p>\n<p>An\u00a0agentic AI-powered ROC aligns with\u00a0this risk management\u00a0construct by providing:<\/p>\n<p>24\/7 persistent vigilance:\u00a0AI agents\u00a0operate\u00a0around the clock, continuously analyzing data and\u00a0identifying\u00a0threats within seconds rather than waiting for periodic reviews.<\/p>\n<p>Active control validation:\u00a0Agents\u00a0continuously\u00a0monitor\u00a0critical controls, ensuring they are not just on paper but actively protecting production environments in real time.<\/p>\n<p>Automated dashboards:\u00a0Instead of an 800-page SSP, the ROC provides live telemetry that shows commanders the mission\u2019s actual\u00a0risk\u00a0posture at any moment.<\/p>\n<p>The AI-powered ROC is a strategic pivot<\/p>\n<p>The shift to\u00a0an\u00a0agentic AI-powered ROC is more than just a technical upgrade; it is a strategic necessity. The adversary has already automated their offensive weapons. Defense agencies must automate their defensive shields. By deploying goal-oriented AI at the edge, streamlining data-flow command structures and digitizing compliance frameworks, the Pentagon can ensure its applications, networks and systems have the capability and resilience to\u00a0identify, prioritize and mitigate cyber risks in the age of AI-driven attacks.<\/p>\n<p>Jonathan Trull is executive vice president and general manager of risk management, and chief information security officer at Qualys. <\/p>\n<p class=\"article-copyright\">Copyright<br \/>\n                            \u00a9\u00a02026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.\n                    <\/p>\n","protected":false},"excerpt":{"rendered":"For decades, cyber defense\u00a0operated\u00a0on a timeline measured in weeks. When a new vulnerability was discovered, an\u00a0adversary\u00a0typically took 15&hellip;\n","protected":false},"author":2,"featured_media":58185,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,7493,33780,33781],"class_list":["post-58184","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-agentic-artificial-intelligence","tag-jonathan-trull","tag-qualys"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/58184","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=58184"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/58184\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/58185"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=58184"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=58184"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=58184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}