Complex and advanced, AI-powered attacks are driving urgent change in the way telecoms approach cyber defense.


In brief
  • Machine-speed cyber attacks are creating alert fatigue for telecom cybersecurity teams.
  • Traditional security operations center (SOC) models aren’t capable of responding in the time needed to fight today’s threats.
  • An agentic SOC that combines machine-speed defense with strategic human judgment can help telecom cyber leaders adopt adaptive defense.

AI-enabled cyber attacks are increasing the urgency for telecom organizations to rethink how they detect, investigate and respond to threats. Attackers are using automation and AI to accelerate reconnaissance, identify vulnerabilities and execute attacks in minutes or seconds. As the time between discovery and exploitation shrinks, security teams have less room for manual investigation, fragmented decision-making or delayed response.

 

For telecoms, the challenge is especially acute. Large distributed environments, legacy systems, high volumes of customer and operational data, third-party ecosystems, ongoing M&A activity and nation-state threat exposure all increase operational risk. These factors make telecom environments difficult to secure at speed and scale. They also create significant operational complexity. A single security incident may span enterprise IT, telecom networks, operational technology (OT), cloud platforms, customer-facing systems and third-party networks, requiring security teams to correlate vast amounts of data and make decisions under significant time pressure.

 

The result is a widening gap between the pace of AI-enabled threats and the capacity of traditional security operations centers (SOCs) to respond. Closing that gap requires more than new cybersecurity tools. It requires a clearer view of where the current SOC model is under strain, where automation can reduce risk and where human judgment remains essential.

 

Here are the steps leaders can take to assess their current model and move their SOC into the future.
 

1. Identify the foundational challenges

Before changing the SOC model or investing in additional cybersecurity software, telecom leaders should assess the operational problem they are trying to solve. The most important questions are not only technical. They are also questions of scale, governance, consistency and accountability, such as:

  • How can security operations scale without a proportional increase in cost?
  • How do we maintain consistent standards across multiple networks, entities and environments?
  • How do we respond to the shrinking window between vulnerability discovery and active exploit – now measured in hours or days instead of weeks or months?
  • How do we protect both customer-facing and backend environments from AI-enabled attacks?
  • How do we prioritize the highest-risk alerts while reducing analyst fatigue?
  • Where can we leverage AI, and where is human judgment still essential?

The answers to these questions should give leaders a sharper view of where current security operations are most exposed and where change can create the greatest value. From there, they can prioritize the areas where AI-enabled automation can reduce manual effort, improve consistency and accelerate responses while also defining the points where human oversight is required to manage risk and accountability.

2. Look critically at traditional SOC pain points

While fragmented automation has increased over time, traditional SOCs were built around human-led workflows, tiered escalation and manual investigation. That model still has value, but it is increasingly difficult to scale against AI-enabled attacks. Alert volumes continue to rise, analysts are asked to investigate more signals with limited capacity and fragmented tooling can slow correlation, prioritization and response.

Expanding headcount alone is rarely practical, particularly as telecom organizations face cybersecurity talent shortages and ongoing cost pressures. Even highly capable teams can struggle to investigate every alert, correlate every signal and respond quickly enough when threats are moving at machine speed. This is where re-examining the SOC operating model itself becomes critical. 

For telecom organizations, the impact of these challenges can spread beyond security operations. Delayed threat detection or response can increase the risk of service disruptions, customer impacts, regulatory scrutiny and reputational damage. As attack speeds accelerate, the ability to respond quickly becomes a business resilience issue as much as a cybersecurity issue.

3. Consider new SOC operating models

Faced with the limitations of traditional SOC models, many telecom leaders are moving toward agentic SOC solutions. These models offer a potential path forward by using AI-enabled agents to automate selected detection, triage, investigation and response tasks. These agents can help shift routine, repeatable work away from analysts, enabling faster responses while freeing analysts to focus on areas where higher-value judgment is required.

For telecom leaders, an agentic SOC can help address challenges that traditional operating models struggle to solve at scale. AI-enabled agents can continuously analyze telemetry across networks, cloud platforms, customer environments and security tools, helping identify patterns that may be difficult for human analysts to detect quickly.

Agentic capabilities can also help reduce alert fatigue by correlating events automatically, prioritizing high-risk incidents and initiating predefined response actions. This can allow analysts to spend less time on repetitive investigation tasks and more time focusing on strategic decisions, emerging threats and complex incidents.

In environments shaped by acquisitions, distributed operations and large technology estates, agentic SOC models may also help organizations apply more consistent processes and controls across the enterprise.

As telecom leaders evaluate future-state security operations, some may also consider how managed services can support this evolution. A managed services operating model can provide access to cyber talent, AI-enabled capabilities and scalable processes, enabling organizations to adopt new approaches while maintaining focus on strategic priorities.

The goal is not to replace analysts with AI. Human experts remain essential for setting risk thresholds, validating AI-generated recommendations, reviewing high-impact actions, managing governance and adjusting response strategies as threats evolve. The value of an agentic SOC lies in combining machine-speed action with human oversight and decision-making. Together, these capabilities can help telecom organizations adapt security operations to a rapidly changing threat landscape.

Final takeaway: Adaptive defense is becoming a strategic requirement

For telecom security leaders, an agentic SOC is not simply a technology upgrade. It represents a shift toward security operations that can learn, scale and adapt as threats evolve, protecting the increasingly complex networks and business environments at the rapid speed that defense now requires.

By combining machine-speed analysis and response with human judgment and oversight, agentic SOC models can help organizations manage growing operational complexity, reduce analyst burden and respond more effectively to AI-enabled threats. For many telecom leaders, the next step is a focused assessment of where automation, AI-enabled agents and human oversight can work together to reduce risk and strengthen resilience more quickly.

Telco leaders are leveraging AI’s machine speed backed by human judgment to succeed in this new world.

Summary 

The message is clear for telecom cyber leaders: It’s time to answer the call and embrace more adaptive cyber defenses, agentic cybersecurity tools and managed services approaches that can help organizations keep pace with advancing AI-powered threats.

About this article