AI-driven cybersecurity: four ways to scale defense with agentic SOCs

The speed and power of AI have transformed the threat landscape, but agentic SOCs offer new possibilities for modernizing cyber defense.


In brief
  • AI-driven attacks are challenging traditional, human-led security operations centers (SOCs) to respond at the speed and scale now required.
  • Agentic SOC models combine AI-driven workflows with human judgment and decision-making to enable more adaptive cyber defense.
  • Cybersecurity managed services help organizations rapidly scale more proactive defenses and stay agile to evolve as threats and business needs change.

Ask leaders of large, complex organizations to name their biggest business priority, and cybersecurity may not top the list. But with AI accelerating the pace, complexity and volume of cyber attacks, security can no longer be treated as a supporting concern. Protecting an organization now requires the speed, adaptability and scale to respond as threats emerge.

The problem many leaders face, however, is that their organizations still depend on security operations centers (SOCs) that were designed for a different era – and far slower pace – of threats. Traditional SOC models were built around analysts manually assessing alerts, investigating incidents and coordinating response. While human judgment remains critical, the traditional SOC model can’t supply the proactive security, rapid cyber threat detection and sophisticated response that incidents now demand. As AI-driven attacks increase, cybersecurity leaders should consider taking four steps to modernize the operating model and strengthen defense in a machine-speed world:

1. Fight AI attacks with AI defense

High-speed, high-volume AI-driven attacks call for an AI-powered response – driving many organizations to move to an agentic SOC model. This approach uses AI agents to detect emerging incidents in near real time, assess risk and react in seconds, not days. Agents help reduce manual tasks, with the ability to plan and adapt, while working seamlessly across identity, cloud, endpoint and other security domains. Security data is continually monitored and collected from multiple sources to better identify threats that traditional SOCs may miss with fragmented, single-source monitoring.

Human judgment remains essential, but analysts have the capacity to focus on high level tasks and analysis, instead of routine, manual work. By combining human insight with AI speed, the agentic SOC enables organizations to more effectively combat the scale and pace of today’s cyber threats.

2. Scale with cybersecurity managed services

While AI-driven cyber defense is increasingly essential, few organizations have the in-house talent, bandwidth or resources needed to build and operate an agentic SOC at scale. The industry shortage of skilled cybersecurity professionals makes the challenge even harder. It’s why many companies enlist the support of a cybersecurity managed services partner, allowing them to modernize their security effectively without needing to build an in-house team.

 

For organizations that need to scale quickly, or lack resources for a significant upfront infrastructure investment, select managed services providers offer agentic SOC capabilities through a shared delivery model. In this approach, clients leverage a hosted platform that the provider operates and continually enhances across its client base. These SaaS-like models help deliver faster updates, standardized operations and lower run costs while unifying threat detection and response on one platform.

 

3. Refocus and upskill internal cyber teams

Moving to a managed services model for cybersecurity shouldn’t mean reducing investment in internal cyber teams. Instead, organizations should consider redirecting that investment toward higher-value work. With a managed services provider assuming platform management and an agentic SOC handling routine monitoring and first-line investigation, in-house professionals can focus on strategic priorities such as AI oversight, performance evaluation, proactive risk assessment and incident decision-making.

 

To make this new approach most impactful, it’s important to assess the skills and workflows that may be required to support the transition and improve resulting outcomes. Teams may need strong capabilities in provider governance, evaluation of AI outputs and coordination of enterprise-wide incident response. Aligning internal roles with the managed services model will help strengthen human oversight where it’s needed most, leverage institutional knowledge and realize better value from an agentic SOC.

 

4. Centralize data to strengthen AI-driven defense

In today’s AI-driven world, high-quality data is more critical than ever, both to drive today’s decisions and prepare for the future as the cyber landscape continues to evolve. When it comes to the agentic SOC, access to both security alerts and enterprise-wide data – such as identity and authentication logs, endpoint telemetry, network traffic, cloud activity, vulnerability data, asset inventory and threat intelligence – gives AI agents a more complete view of the threat environment, so they can correlate signals and respond more accurately.

 

This approach does require strong data governance. Access controls, data quality standards and oversight processes must be clearly defined to help protect confidential information and maintain trust in AI-driven decisions and processes. With a centralized, well-governed data foundation, agentic SOC models can help cybersecurity operations become faster, more consistent and easier to scale.

In a world where AI is both a tool for business and a cyber threat to the business, smart leaders are choosing to fight AI with AI and embrace the agentic SOC as a platform to shape and secure their future with confidence.

AI-driven cyber attacks have rapidly changed the cybersecurity landscape, but modernizing cyber defense requires more than adopting AI – organizations must clearly define roles, leverage trusted data and still rely on human judgment for the most critical decisions. Organizations that strike this balance will be better positioned to respond to evolving threats with confidence and resilience.

Dave Trollman, Principal, Technology Consulting Services, Ernst & Young LLP, contributed to this article.

Summary 

The pace and complexity of AI-driven cyber attacks will increase as technology continuously evolves. Leveraging an agentic SOC, especially as a managed services model, allows cybersecurity teams to scale their capabilities while giving human agents the capacity to focus on higher-value, strategic priorities and stay ahead of the ever-changing threat landscape.


About this article

Related articles

How telecoms can dial up cybersecurity in the age of AI attacks

Learn how telecom security leaders can use agentic SOC to build adaptive cyber defense.

In an era of technology transformation, three priorities matter most

Competitive advantage belongs to leaders who leverage technology and managed services to balance speed, cost and risk while continuously adapting to change.

5 steps to match AI cyber defense with advancing agentic threat

How to accelerate agentic cybersecurity to match modern AI threats

EY Agentic SOC

Learn how the EY Agentic SOC, built on the CrowdStrike platform, can improve detection and response with real-time cybersecurity.

How agentic AI will transform the SOC for strategic advantage

Security operation centers are on the cusp of transformation with agentic AI. Leaders must prioritize it for smarter, more adaptive security operations.