Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

Swimlane updates security operations center with intelligent routing

Agentic artificial intelligence cybersecurity automation company Swimlane Inc. today announced the expansion of the company’s AI security operations center to support automatic routing for security investigations. The new capability enables routing of incoming alerts to different paths: deterministic automation, AI-assisted investigation or agentic automation. The company said the front-end…

Swimlane updates security operations center with intelligent routing

Cybersecurity automation provider Swimlane, Inc. has announced an update to its Security Operations Center (SOC) to incorporate intelligent routing for security investigations. The new feature allows for automatic routing of incoming alerts to different paths, including deterministic automation, AI-assisted investigation, or agentic automation. This triage capability enables the system to quickly evaluate the complexity of the task and determine the level of AI assistance required.

Swimlane's AI-assisted system aims to enhance the investigation capabilities of security teams without incurring high costs associated with defaulting every task to expensive AI models. Co-founder and Chief Executive Cody Cornell explained that as the consumption of AI continues to rise, the next generation of the SOC cannot run every task through AI by default. He emphasized that the SOC should know which work truly requires AI.

The objective of Swimlane's routing system is to provide the appropriate level of assistance to security teams without incurring unnecessary costs. If an alert is deemed simple, it can still be routed to a deterministic automation model, but if it turns out to be a tip of the iceberg, it can be routed to a higher-reasoning model. This ensures that the security team always maintains control and the AI remains a tool rather than a replacement for human ingenuity or judgment.

The new router prevents complex work from being handled by expensive agentic AI evaluations. Sometimes an alert is just a simple occurrence and can be placed in a pile, while other times it may be part of a larger trend requiring further examination and surfacing, along with clear reasoning. In such cases, the agentic AI goes into action, and the SOC learns which alerts the team wants evaluated, creating repeatable playbooks.

This establishes a continuous, adaptable, and configurable cycle that can be fully automated, focusing AI budget on complex work while maintaining scale for routine investigations.

Cornell noted that the problem arises as AI-driven platforms promise to reduce manual labor and investigation work but also route simple tasks to generative AI models that could be handled with simpler methods, such as Python scripts. He emphasized that the vision behind the AI-first SOC is to give security professionals control over the extent of their investigations behind the scenes and manage their tools through an orchestrator guiding alerts to appropriate "buckets." This approach leads to real financial impact.

A healthcare customer, which deals with over 180 threats daily, achieved a 90% cost savings by using Swimlane's intelligent routing, reserving agentic AI evaluation for only the most complex 10% of threats across investigations. Cornell concluded that Swimlane pairs the speed and predictability of automation with AI where reasoning and judgment create real value.

Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at siliconangle.com →

More in Tech

More from Wednesday 19 August →