EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
How EY can help
-
Seamless, strategic cybersecurity operations can give you the confidence to focus on innovation and growth. EY Cybersecurity Managed Services can help.
Read more
2. Scale with cybersecurity managed services
While AI-driven cyber defense is increasingly essential, few organizations have the in-house talent, bandwidth or resources needed to build and operate an agentic SOC at scale. The industry shortage of skilled cybersecurity professionals makes the challenge even harder. It’s why many companies enlist the support of a cybersecurity managed services partner, allowing them to modernize their security effectively without needing to build an in-house team.
For organizations that need to scale quickly, or lack resources for a significant upfront infrastructure investment, select managed services providers offer agentic SOC capabilities through a shared delivery model. In this approach, clients leverage a hosted platform that the provider operates and continually enhances across its client base. These SaaS-like models help deliver faster updates, standardized operations and lower run costs while unifying threat detection and response on one platform.
3. Refocus and upskill internal cyber teams
Moving to a managed services model for cybersecurity shouldn’t mean reducing investment in internal cyber teams. Instead, organizations should consider redirecting that investment toward higher-value work. With a managed services provider assuming platform management and an agentic SOC handling routine monitoring and first-line investigation, in-house professionals can focus on strategic priorities such as AI oversight, performance evaluation, proactive risk assessment and incident decision-making.
To make this new approach most impactful, it’s important to assess the skills and workflows that may be required to support the transition and improve resulting outcomes. Teams may need strong capabilities in provider governance, evaluation of AI outputs and coordination of enterprise-wide incident response. Aligning internal roles with the managed services model will help strengthen human oversight where it’s needed most, leverage institutional knowledge and realize better value from an agentic SOC.
4. Centralize data to strengthen AI-driven defense
In today’s AI-driven world, high-quality data is more critical than ever, both to drive today’s decisions and prepare for the future as the cyber landscape continues to evolve. When it comes to the agentic SOC, access to both security alerts and enterprise-wide data – such as identity and authentication logs, endpoint telemetry, network traffic, cloud activity, vulnerability data, asset inventory and threat intelligence – gives AI agents a more complete view of the threat environment, so they can correlate signals and respond more accurately.
This approach does require strong data governance. Access controls, data quality standards and oversight processes must be clearly defined to help protect confidential information and maintain trust in AI-driven decisions and processes. With a centralized, well-governed data foundation, agentic SOC models can help cybersecurity operations become faster, more consistent and easier to scale.