How much control should AI get? A CISO roundtable takes on SOC autonomy
Security operations centers have struggled with alerts for years, and AI agents offer a new way to tackle it: Enable The post How much control should AI get? A CISO roundtable takes on SOC autonomy appeared first on The New Stack .
Security operations centers (SOCs) have long grappled with managing security alerts, and artificial intelligence (AI) agents now present a potential solution. These AI agents can analyze signals across various systems, investigate suspicious activities, and suggest next steps to security analysts collaborating within the loop. The appeal is clear: SOC analysts possess limited time and attention, whereas the volume of potential threats does not share this constraint.
However, as attackers also gain access to AI tools, the question arises: to what extent should organizations permit AI agents to operate autonomously? This was the central focus of The New Stack's AI-Speed SOC CISO Roundtable held on September 15, where security leaders deliberated on the extent of AI autonomy and when human oversight is necessary.
The level of autonomy granted to AI agents varies significantly. For instance, while an AI agent could investigate a suspicious login, it may not be permitted to disable the corresponding account. Similarly, an agent could isolate an endpoint or block network traffic, potentially impacting the business on a larger scale than a human analyst could manage.
A crucial aspect of this equation involves trust: security teams must understand what the AI agent is doing, determine when human intervention becomes necessary, and have the ability to rectify any mistakes. This may entail implementing stringent limitations on autonomy, including methods to halt the AI agent's functionality if it deviates from acceptable parameters.
The delegation of responsibilities also influences the roles of the security analysts involved. As AI tackles a substantial portion of routine investigations, analysts might find themselves spending less time sifting through alert queues and more time focusing on threat hunting, making critical decisions, and overseeing the agents handling repetitive tasks. In this scenario, the SOC analyst transitions from a mere investigator to a more orchestrator-like figure.
Moreover, the concept of "continuous detection and response" gains new relevance with AI agents. Rather than seeing detection, investigation, and response as distinct stages, an AI agent could transition between these phases, with insights gained during one investigation directly influencing the detection of subsequent threats. This could mark a departure from traditional SOC operations, evolving into a fundamentally different operating model.
This transformation also raises concerns about cybersecurity tooling. Security teams already manage complex stacks, and vendors are rapidly incorporating AI capabilities into their products. The result could be a proliferation of additional tools rather than a cohesive, continuous system as initially envisioned.
Written by urgent.news from The New Stack's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.