< ciso
brief />
Tag Banner

All news with #soc tag

137 articles

Cloudflare’s Agentic Security Operations for Alerts

🔒 Cloudflare introduces an agentic security operations harness that uses multiple AI agents and deterministic reconnaissance to reduce analyst workload and speed alert triage. The Managed Defense AI harness aggregates evidence, employs Clef for decision scoring, and leverages approved OpenAI Daybreak and Anthropic models for deeper analysis. Specialist agents run in parallel with constrained scopes to avoid hallucinations, while application code enforces data collection, provenance, and reproducibility. The system produces advisory reports, preserves evidence and gaps, and keeps analysts responsible for final decisions.
read more →

Gartner’s ISOC: A New Layer for Security Ops

🔒 Gartner introduced the Integrated Security Operations Center (ISOC) category to address the limits of traditional SIEMs by unifying detection, investigation, case management and response. ISOC emphasizes native detection and response, centralized data ownership, persistent incident case objects and cross-domain correlation to reduce latency and operational friction. The aim is streamlined workflows and lower costs for lean security teams confronting AI-accelerated threats.
read more →

AI Expands SOC Capacity but Raises Skills Concerns

🔍 A Swimlane study finds AI increases SOC analyst capacity, freeing time for complex investigations and strategic work while reducing repetitive tasks. Respondents reported high confidence in spotting incorrect AI recommendations, yet many worry automation limits on-the-job skills development. The report urges formal AI oversight, redesigned training and clearer career paths to preserve investigative judgment.
read more →

SOC Operations Should Build Shared Operational Memory

🔍 AI is lowering the cost of retrying failed intrusions by accelerating troubleshooting and scripting, turning what was once time-consuming research into near-instant iteration. Public reporting through 2025–2026 shows state-backed and criminal actors incorporating generative AI into reconnaissance, exploit development, and automation, though confirmed widespread deployment remains unclear. The practical impact is faster attacker experimentation while defenders still suffer handoffs, telemetry gaps, and decision latency that lengthen response cycles.
read more →

Microsoft adds integrated SOC features to Defender

🔒 Microsoft now offers Integrated Security Operations Center (ISOC) capabilities inside Microsoft Defender for Microsoft 365 E5 and E7 customers at no extra license cost during public preview. ISOC combines SIEM-like functions with Defender XDR, threat intelligence, automation and AI in a single portal, and ingests Microsoft product logs without charges. From Oct. 1, third-party data ingestion will be metered at $2.40 per GB, and more advanced features require an ISOC workspace and Azure subscription.
read more →

Data Quality Now Top Barrier for Threat Hunters

📊 The SANS 2026 Threat Hunting Survey found that data quality and quantity have overtaken skills as the primary barrier for threat hunting programs, cited by 50% of 500 respondents worldwide. Skilled staff remain a close second at 45%, while formally defined methodologies fell to 37%, raising concerns about repeatability and defensibility. Other common constraints include budget, data standards, tool limits, and processes, and ransomware remains the most encountered threat.
read more →

Reimagining the SOC for the agentic era

🔐 Microsoft announces an Integrated Security Operations Center (ISOC) in Microsoft Defender to unify SIEM and threat protection into a single platform. ISOC provides combined signals, context, and actuators so humans and agents can operate as one system, enabling faster detection, investigation, and automated response. The preview is available now.
read more →

How AI Is Reshaping Cybersecurity Operations

🛡️ The rise of AI agents is already transforming security operations, shifting first-level triage and repetitive tasks to automated systems while leaving humans for escalation, oversight, and complex judgment. Experts warn of a surge in discovered vulnerabilities that defenders will struggle to absorb and remediate. Organizations should prepare for machine-speed attacks and containment, flattening team structures, new governance needs, and the use of AI as an interface across fragmented tools.
read more →

When an Entire Company Adopts AI: SOC Impact

🔍 Over the past year enterprise SOCs have seen a new class of alerts tied to everyday AI use, from coding agents to employees signing third-party AI tools into corporate accounts. AI-related alerts remain a small share (0.43%) of total alerts but climbed 685% from February to June 2026, making them the fastest-growing subset. The alerts fall into three buckets—noise (94.1%), genuine risk (5.8%), and real attacks (0.02%)—with most incidents resolved as benign developer activity or detection misfires.
read more →

When AI Guardrails Undermine SOC Operational Control

🔒 The article argues that poorly designed external AI guardrails can erode defenders' advantages by blocking or delaying agentic SOC investigations, giving attackers time to succeed. It urges organizations to retain operational sovereignty by embedding customizable guardrails within their own systems and testing LLMs against real workflows. Cisco Talos evaluated many models and stresses balancing efficacy, cost, speed, and consistency when selecting AI for security.
read more →

State of AI in Security Operations 2026 Findings

🔍 Prophet Security's 2026 report shows AI has become mainstream in security operations: 40% of teams use AI daily and 56% are testing it. Teams face massive alert volumes, slow triage, and rising AI-driven attacks, while AI adoption is reducing investigation times and shifting analysts toward advanced roles. Privacy, explainability, and DIY project durability remain key challenges for organizations.
read more →

Balancing Model Tradeoffs for AI in SOCs

🔎 Cisco Talos evaluated 66 model-and-reasoning combinations from Anthropic and OpenAI on a tool-assisted log-review task to determine practical tradeoffs for SOC and DFIR workflows. Reviewers used common Unix tools to decide if a synthetic dataset was real, and every condition was scored by four persona-based reviewers across multiple panels. Results measured investigative quality, cost, time, and consistency, revealing that the highest accuracy models were often slower, costlier, and sometimes unreliable due to refusals or format failures. Talos recommends using a Pareto-frontier approach and benchmarking each reasoning level and persona for operational selection.
read more →

Seven Ways AI Strengthens Security Operations

🔒 AI is reshaping enterprise security by automating monitoring, analysis, and routine tasks to help teams focus on the most critical threats. Experts highlight uses such as enhanced network and user monitoring, deeper visibility into security posture, SOC streamlining, and connecting benign events into meaningful attack signals. Organizations should integrate AI into existing programs, validate models continuously, and phase automation in cautiously while retaining human oversight.
read more →

Wazuh Integrates AI to Streamline SOC Workflows

🛡️ Wazuh introduces AI-assisted capabilities to help Security Operations Centers reduce alert fatigue and accelerate investigations. The Wazuh AI Analyst on Wazuh Cloud delivers automated, scheduled security reports using Amazon Bedrock and Anthropic’s Claude, with encrypted processing and no model training on customer data. Self-deploy options include local Llama 3 via Ollama and FAISS-backed vector search for private threat hunting, while cloud-hosted Claude 3.5 Haiku can be integrated through OpenSearch Assistant for conversational guidance.
read more →

Data quality drives SOC AI performance gains

🔍 Security operations research shows that AI-driven SOC workflows depend more on the fidelity of underlying telemetry than on specific LLM choices. The Provably Better Data project evaluated multiple LLMs across controlled CTF and incident response benchmarks using Corelight, firewall, Snort, and NetFlow telemetry normalized to OCSF. Results found that high-fidelity protocol-aware logs produced 2–4x better outcomes in accuracy, evidence coverage, and investigation time, and reduced analyst rework and hallucinations. The study advises SOC leaders to prioritize data quality and structured telemetry when investing in AI automation.
read more →

Four gaps slowing AI adoption in enterprise SOCs

🔍 Enterprise SOCs are investing in AI but struggle to convert tools into measurable operational gains. Many initiatives add complexity and fragmented workflows instead of reducing analyst workload. Successful deployments prioritize explainability, augment existing playbooks, and unify access to disparate security tools. Clear governance and incremental automation help turn AI pilots into repeatable operational improvements.
read more →

Identity-Driven Attacks and SOC Response Trends

🔐 Unit 42 finds identity compromises underpin most modern incidents, with the 2026 Global Incident Response Report showing identity weaknesses in nearly 90% of investigations and 65% of initial access events. Attackers increasingly use phishing, social engineering, MFA manipulation and third-party account misuse to gain entry, then move laterally, escalate privileges and blend into administrative behavior. Unit 42 recommends correlating identity, endpoint, cloud and network telemetry, applying AI-driven correlation and centralized investigations, and investing in continuous threat hunting and SOC engineering to detect and contain identity-driven intrusions earlier.
read more →

Black Hat 2026: AI-driven security products emerge

🛡️ Black Hat 2026 showcased a wave of AI-integrated security products that go beyond copilots to embed automation into operational workflows. Vendors emphasized attack path analysis, threat intelligence integration, and purpose-built AI agents to accelerate investigations while preserving existing infrastructure. Announcements included vulnerability remediation agents, AI observability, recovery validation, identity exposure intelligence, sovereign AI SOC agents, and expanded autonomous security platforms.
read more →

Why AI Platforms Belong Above an Autonomous SOC

🤖 AI platforms such as Claude, Codex, and Cursor are valuable tools for analysts, helping to write detections, summarize incidents, and assist decision-making. However, they are designed to augment human expertise rather than act as continuous, high-volume investigators. An autonomous AI SOC performs real-time investigations, maintains organizational context, and keeps costs predictable by reserving large language models for high-value tasks. Together, both layers improve SOC efficiency and outcomes.
read more →

The containment paradox in ransomware response

🔒 This article examines a recurring operational gap in ransomware incident response: SOC analysts often have the authority to isolate systems, but business owners hold accountability for service availability. It argues that isolation can itself become the damage when applied to business-critical systems and proposes a governance-based remedy: a no-touch register tied to a RACI model and time‑boxed escalation with pre-agreed safe-state fallbacks. The piece rebuts the objection that operational vetoes slow response by showing how narrow, timed vetoes protect crown-jewel services without paralyzing detection and containment.
read more →