The result? Burnout, inefficiency, and a widening gap between detection and action. None of this should come as a shock to anyone who works in cybersecurity.
The promise of agentic AI has emerged as a potential turning point, though. This new class of artificial intelligence goes beyond traditional automation and machine learning. It’s designed to operate autonomously, learn from historical context, and make decisions that reduce the burden on human analysts—without turning the SOC into a black box.
The question is: Is agentic AI just the latest buzzword? Or could it truly reshape how security operations are run?
From Noise to Clarity
Today’s SOCs face a volume problem. A 2024 MSSP Market News study found that SOC teams receive an average of nearly 4,000 alerts per day, and almost two-thirds of them are ignored. Many alerts are false positives or duplicates, but the triage still eats up valuable analyst time. Traditional SOAR tools promised relief through automation, but most have failed to deliver beyond workflow ticketing and basic orchestration.
I recently spoke with Brian Murphy, CEO of ReliaQuest, about these challenges. He explained, “All SOAR really is is a ticket workflow distributor. It is a thing that moves a process from one team to another. That's what the majority of customers have used it for, because it was too hard to use it to actually automate.” He cited a recent session with hundreds of customers: almost all had SOAR solutions, but only three had more than two true automations running.
That disconnect is what agentic AI aims to resolve.
What Makes Agentic AI Different?
A post from Deloitte Center for Technology, Media & Telecommunications explains, “As its name suggests, agentic AI has ‘agency’: the ability to act, and to choose which actions to take. Agency implies autonomy, which is the power to act and make decisions independently. When we extend these concepts to agentic AI, we can say it can act on its own to plan, execute, and achieve a goal—it becomes ‘agentic.’ The goals are set by humans, but the agents determine how to fulfill those goals.”
Unlike static playbooks, agentic AI systems are dynamic. They not only ingest data but actively learn from historical incidents, analyst feedback, and environmental context. They can retrieve telemetry from disparate systems—endpoint, network, identity, threat intel—and synthesize it to make real-time, transparent decisions.
Murphy strssed that in ReliaQuest’s GreyMatter platform, for example, agentic AI doesn’t operate behind closed doors. It makes decisions that analysts can review, audit, and adjust. “The other thing about our AI is it’s transparent to the customer,” said Murphy. “They see every decision that that agentic model made along the way and why. Each customer is essentially training their own model in a protected way.”
This is a critical distinction in an industry rightfully wary of handing over too much control. While agentic AI can act independently on routine actions—such as resolving alerts based on travel patterns or resetting accounts for terminated employees—it should still defer to human oversight for higher-stakes decisions.
Burnout, Tiered Models, and the End of “Tier One”
Perhaps the most compelling argument for agentic AI isn’t the tech—it’s the human impact. Cybersecurity burnout is real and escalating. A core contributor is the rote, disconnected work of triaging Tier One alerts, many of which are repetitive and low-value.
Murphy doesn’t mince words here: “We should stop using human beings to do Tier One alerts. We should stop using human beings to do Tier Two alerts.” He believes AI should handle the grunt work—pulling logs, cross-referencing IPs, contextualizing user behavior—so that humans can focus on meaningful decisions.
The implications are profound. Removing the tiered model could free up time not just to reduce fatigue, but to develop more strategic, business-aware security professionals. That, in turn, strengthens the security program holistically—giving teams the breathing room to hunt for threats, analyze risk trends, and build cross-functional leadership capabilities.
Not a Replacement—A Reboot
Despite the acceleration of autonomous capabilities, Murphy is clear that Agentic AI isn’t about cutting jobs. The cybersecurity need is still far beyond the capacity of most security teams. Rather, the vision is to up-level skillsets, fill in operational gaps, and create capacity where none exists today.
“We're a long, long way before we see this as like a reduction in the amount of jobs,” he said. “It’s actually going to give us time to build leaders in security and give our cybersecurity teams time to learn the business and develop themselves”.
In other words, the goal isn’t fewer people—it’s smarter work.
The Bigger Picture
ReliaQuest’s recent $500 million funding round, valuing the company at $3.4 billion, shows that investors are betting big on this new model. The company now serves over 1,200 enterprise customers, with annual recurring revenue exceeding $300 million and a growth trajectory aimed at going public. Unlike many peers, it’s doing so profitably, reinvesting in product innovation and global expansion—not just sales.
But while ReliaQuest may be leading the charge, the trend is industry-wide. CISOs are increasingly prioritizing AI-powered platforms that reduce dwell time and boost analyst effectiveness without further fragmenting the toolset.
The risk isn’t that agentic AI will take over—it’s that organizations who ignore it may fall behind.
Bottom Line
Agentic AI may not be the silver bullet for every SOC, but it’s a step toward something security professionals have been demanding for years: visibility, speed, and sanity. If it delivers even a fraction of its promise—fewer false positives, faster containment, and analyst relief—it could very well represent the beginning of a smarter, more sustainable era in cybersecurity operations.
Because in the end, it's not about replacing people. It’s about empowering them—with time, tools, and clarity.
The above is the detailed content of What Agentic AI Could Mean For Security Operations. For more information, please follow other related articles on the PHP Chinese website!

Running large language models at home with ease: LM Studio User Guide In recent years, advances in software and hardware have made it possible to run large language models (LLMs) on personal computers. LM Studio is an excellent tool to make this process easy and convenient. This article will dive into how to run LLM locally using LM Studio, covering key steps, potential challenges, and the benefits of having LLM locally. Whether you are a tech enthusiast or are curious about the latest AI technologies, this guide will provide valuable insights and practical tips. Let's get started! Overview Understand the basic requirements for running LLM locally. Set up LM Studi on your computer

Guy Peri is McCormick’s Chief Information and Digital Officer. Though only seven months into his role, Peri is rapidly advancing a comprehensive transformation of the company’s digital capabilities. His career-long focus on data and analytics informs

Introduction Artificial intelligence (AI) is evolving to understand not just words, but also emotions, responding with a human touch. This sophisticated interaction is crucial in the rapidly advancing field of AI and natural language processing. Th

Introduction In today's data-centric world, leveraging advanced AI technologies is crucial for businesses seeking a competitive edge and enhanced efficiency. A range of powerful tools empowers data scientists, analysts, and developers to build, depl

This week's AI landscape exploded with groundbreaking releases from industry giants like OpenAI, Mistral AI, NVIDIA, DeepSeek, and Hugging Face. These new models promise increased power, affordability, and accessibility, fueled by advancements in tr

But the company’s Android app, which offers not only search capabilities but also acts as an AI assistant, is riddled with a host of security issues that could expose its users to data theft, account takeovers and impersonation attacks from malicious

You can look at what’s happening in conferences and at trade shows. You can ask engineers what they’re doing, or consult with a CEO. Everywhere you look, things are changing at breakneck speed. Engineers, and Non-Engineers What’s the difference be

Simulate Rocket Launches with RocketPy: A Comprehensive Guide This article guides you through simulating high-power rocket launches using RocketPy, a powerful Python library. We'll cover everything from defining rocket components to analyzing simula


Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

AI Hentai Generator
Generate AI Hentai for free.

Hot Article

Hot Tools

SecLists
SecLists is the ultimate security tester's companion. It is a collection of various types of lists that are frequently used during security assessments, all in one place. SecLists helps make security testing more efficient and productive by conveniently providing all the lists a security tester might need. List types include usernames, passwords, URLs, fuzzing payloads, sensitive data patterns, web shells, and more. The tester can simply pull this repository onto a new test machine and he will have access to every type of list he needs.

EditPlus Chinese cracked version
Small size, syntax highlighting, does not support code prompt function

Zend Studio 13.0.1
Powerful PHP integrated development environment

SublimeText3 English version
Recommended: Win version, supports code prompts!

PhpStorm Mac version
The latest (2018.2.1) professional PHP integrated development tool