ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

teissTalk:From manual triage to machine speed investigations - the rise of the Agentic SOC

On 18 June 2026, teissTalk host Thom Langford was joined by Edward Wu,CEO, Dropzone AI; Ken Payton, Director of Detection and Response, Avalara; and Mike Johnson, Global Cyber Threat, Incident Response, and Security Operations Manager, Verifone.

Linked InXFacebook

Views on news


On the evening of 12 June 2026, three days after Anthropic had launched its most capable AI models to the public, the U.S. government ordered them taken down. The trigger seemed to be a reported technique for bypassing Fable 5’s safety guardrails – the filters used to stop the model from accessing the advanced cybersecurity capabilities baked into the underlying Mythos architecture. The concern was that if those guardrails can be defeated, a consumer-facing AI product effectively becomes an unrestricted cyber tool. The identity of the “trusted partner” who flagged the jailbreak was not officially confirmed, but reporting by Semafor and the Wall Street Journal points to Amazon. Anthropic pointed out that similar vulnerability discoveries can be made with other lates generation models as well. Another reading of the story is that Anthropic’s doom marketing proved too successful and the ban – at least to some degree – is an unintended consequence of that. One of the lessons from this news item is that companies that develop frontier models must make sure they are able to control the models they release. Post-trained open source models are also available, offering criminals better capabilities than the ones they’ve been using until recently.  


Letting AI do everything or using AI to get better at what we humans do


New technologies are making detection engineering and threat hunting more important than ever. They also have the potential to address the alert overload problem, but human validation remains necessary to avoid the blind spots that AI may create. However, companies will incur huge costs implementing agentic AI tools. Agentic AI may also deteriorate cybersecurity professionals’ institutional knowledge – a shift that must be counterbalanced as it progresses. Changes in the role of the security engineer will most probably mirror those that have recently taken place in software engineering, which no longer involves coding but running and reviewing several AI-generated codes parallelly. A future scenario is that cybersecurity professionals will work more like SOC managers or special forces with AI agents operating as foot soldiers. Old SOC career paths are likely to disappear too, removing the opportunity for professionals to expand their knowledge as they move through the ranks. While junior SOC analysts can learn from what AI looks into, we shouldn’t get to a point in the future where AI becomes the only reference manual of junior analysts’.  One way of keeping human experts sharp is programming AI to let 1 per cent of the alerts though to see if humans detect the anomaly. But even with machine-speed investigations becoming the norm, critical and out of the box thinking will remain key analyst assets. 


The panel’s advice

  • AI is software-based staff augmentation.
  • LLMs are great tools for upskilling your staff.
  • SOC analysts should not only understand the script LLMs churn out but also what the script does.
  • For a start, answer the question why you’re using AI to see if you have a genuine purpose for deploying it and understand what exactly you want the AI to do for you – automation or empowering analysts. Don’t just go for agentic as default.  
  • To decide what sort of AI you need, do a mental exercise: if you had five more staff, what tasks you would assign to them – whether it’s writing more detections, threat modelling or monitoring low information alerts. Then work backwards to see what type of AI could do the job. 
Linked InXFacebook
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543