Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Agentic AI in the SOC: what it means for identity, cloud, and response


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Agentic AI in the SOC is a shift from manual triage to governed, multi-tool investigation and response, according to torq. A Virgin Atlantic case study showed large reductions in repetitive work and faster incident handling, while the security issue is not whether AI can act, but whether its actions across identity, endpoint, cloud, and SaaS are sufficiently constrained to remain auditable and safe.

NHIMG editorial — based on content published by torq: Black Hat Europe 2025 recap on agentic AI in the SOC

By the numbers:

Questions worth separating out

Q: How should security teams implement agentic AI in SOC workflows safely?

A: Start with narrow, high-confidence use cases such as alert triage and evidence gathering, then require explicit policy gates before any remediation action.

Q: Why do agentic security tools change identity governance requirements?

A: Because the risk is no longer only whether the tool detects accurately.

Q: What do security teams get wrong about hyperautomation in the SOC?

A: Teams often focus on throughput and ignore authority.

Practitioner guidance

  • Inventory every privileged connector used by SOC automation Map the IAM, SaaS, endpoint, and cloud accounts that the agent can call, then classify each by blast radius, remediation power, and logging coverage.
  • Separate recommendation from execution in every workflow Allow the agent to summarise, enrich, and propose next steps, but require explicit policy logic before it can perform identity changes, token revocation, or incident containment.
  • Bind automation to identity-enriched case data Make IAM, service account, and machine identity signals part of the investigation record so the SOC can see who or what initiated an action and what privileges were present at the time.

What's in the full article

Torq's full article covers the operational detail this post intentionally leaves for the source:

  • A live-event walkthrough of the HyperSOC workflow across SIEM, EDR, IAM, CSPM, and SaaS tooling, showing how the automation chain is assembled in practice.
  • Virgin Atlantic’s implementation story, including how the team introduced the platform mid-incident and what changed in day-to-day analyst work.
  • The specific demo behaviours that distinguish alert enrichment, case building, and policy-constrained response in a real SOC setting.
  • The vendor’s framing of what analysts, CISOs, and peers were reacting to at Black Hat Europe, including the audience response to the live demonstration.

👉 Read torq’s Black Hat Europe recap on agentic AI in the SOC →

Agentic AI in the SOC: what it means for identity, cloud, and response?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Agentic AI in the SOC is becoming an NHI governance problem, not just a SOC efficiency story. The article shows AI systems planning and executing actions across identity and security tooling, which means they operate as non-human identities with delegated authority. That shifts the control question from model accuracy to privilege design, policy enforcement, and auditability. The decisive issue for practitioners is whether the automation layer can be governed like any other high-trust identity path.

A question worth separating out:

Q: What should teams do before letting agentic AI touch production response workflows?

A: Start with low-risk use cases, then prove that every automated action can be observed, approved where needed, and reversed if the outcome is wrong. The first production rollout should prioritise containment, auditability, and identity checks, not maximum autonomy. That approach protects both the SOC and the business.

👉 Read our full editorial: Agentic AI in the SOC is moving from hype to governed execution



   
ReplyQuote
Share: