• Understand what is driving the surge of investment in AI-assisted security operations
• Explore why both traditional rule-based automation, along with AI-driven approaches are needed in modern SOCs
• Examine how AI is influencing the decision between building an internal SOC and leveraging MDR services
• Learn the current state of AI agents within security operations and where they deliver practical value
• Understand why the future SOC remains AI-assisted rather than fully autonomous
The AI SOC market is expanding rapidly as security vendors race to deliver security automation systems that help deliver smarter triage, improved investigations, and faster responses. But not every AI claim translates into meaningful operational improvement. This webinar examines what is driving the surge of investment, which solution patterns are emerging across the market, and how security leaders should evaluate AI-assisted operations.
The session will focus on measurable outcomes, analyst augmentation, governance, explainability, and the tradeoffs between traditional workflow automation and newer agentic approaches so attendees can separate real value from market noise and make more confident strategic security investment decisions.
Matthew Gardiner, Fellow Analyst at KuppingerCole Analysts will draw on the research behind The Emerging AI SOC Leadership Compass to explain how the market is being reshaped by heavy investment from both established providers and new market entrants. He will highlight which capabilities are becoming table stakes, where meaningful differentiation is emerging, and why the most credible approaches balance AI-driven analytics with evidence, explainability, and human control. Attendees will leave with a sharper understanding for evaluating offerings, prioritizing use cases, questioning bold claims, and distinguishing practical adoption from premature promises.
Who Should Attend
This webinar is intended for CISOs, SOC directors, SOC analysts, security architects, incident responders, security automation vendors, and GRC specialists responsible for evaluating and advancing modern security operations capabilities. It is particularly relevant for organizations exploring AI-assisted SOC strategies, automation, investments, and the evolving role of AI within security operations.
Hello, everyone. Welcome to this short webinar that I've entitled Beyond SOAR, The Rise of the AI SOC. So I want to give out my welcome to wherever you may be.
Clearly, the security automation market has moved forward and beyond SOAR, which I'll get into some of the reasons and drivers of that. But basically, the application of AI to the threat detection and response and exposure management equation has been hitting pretty strongly over the last, oh, say, one or two years.
Clearly, the application of AI to the security operations challenges of organizations has become the next wave of innovation in this space. But before we get into the content, I want to talk a little bit about some of the housekeepings for this webinar. Audio control, you don't need to worry about. We have it managed centrally. There will be a couple polls. So stay awake out there. I want to hear what you guys think about a couple of questions. And hopefully, we can all benefit from what everyone else is doing. There will be a Q&A section at the end.
I expect this content to go about 30 minutes. So please hang in there and throw in questions into the questions tab as you think of them. And I will address as many as I can at the end. And the recording and the slides themselves will be available and posted on the Coupling Your Call website in the very near future. So agenda-wise, introducing myself, I am Matthew Gardner. I'm a fellow analyst at Coupling Your Call. I joined in the fall of last year after about 25 years on the product side of security vendors.
So I've been building and helping sell and deploy security issues, many different types of security solutions for years. And recently, I've flipped over to the other side and have been evaluating markets like the security operations and security automation market. Trend-wise, I'm going to talk a little bit about some of the trends in the security operations center and why AI has sort of hit at a very good time. I'm also basically giving you a summary, a very high-level overview of a recently published research piece that I called the Emerging AI SOC. It's a leadership compass.
It's about 100 pages long, so don't expect a complete review of that document here. That would take too long. But hopefully, you get some value out of some of my key findings and then also interest you in actually getting a hold of the actual report itself. And then as I mentioned, I will talk about some key findings, recommendations, and go to your questions. So throw them in when you can.
So first, when people think of a security operations center, they often think of something that looks like this. The reality is these exist.
Actually, I used to work at RSA Security, which if you recall, was a division of EMC. And the EMC, Security Operations Center, was actually housed in our office at RSA for sort of obvious reasons. And our security operations center looked actually something like this. We had about 25 analysts in it, and it was 24 by 7, very sophisticated technology, some from RSA, some from other vendors. But the reality is, if you go to the next slide, you're going to see what most organizations' security operations center looks like.
Maybe it's more than just one guy, but maybe it's two guys, and their job is trying to do threat detection and response for their whole enterprise. The reality is, of course, security operations are anywhere between this picture and the previous picture. Levels of maturity, level of investment, staffing crosses a very wide range. And so the automation that AI brings is actually coming into the world as it exists. Go to the next.
The other thing we need to keep in mind is that we think of a security operations center, but the reality is most organizations use some amount of outsourced services for specialized services, like maybe malware analysis or off-hours coverage, where others outsource the large portion of their security operations to a managed service provider or a managed detection and response service. The arrival of AI to this security automation space has basically disrupted the equation for maybe you have a DIY SOC, maybe you're using an MDR provider, and that equation is now being impacted.
And I'm going to get into this in more depth, but the opportunity to do more yourself is raised with AI in the SOC, but also the MDR providers themselves are adding AI functionality to their own services. And so it's early stage, but things are changing in sort of that market dynamic of outsource or insource for SOC. The use of AI, obviously, is probably not a secret to anyone here. It's going across many, many different industries, not just security, of course, but even within the security domain, it's being embedded inside almost every security domain you can think of.
But I will posit that, in my opinion, the threat detection and response or security automation or SOC automation space is probably the biggest impact to date where AI has entered, has innovating, and is changing how organizations do their security automation. So it's essentially the biggest place. If you want to see the impact on security of AI, I would encourage everyone to look closely at at its impact in the security automation or SOC automation space.
So moving on to kind of the philosophy or the analytic differences you have that AI brings versus a more deterministic or rule-based approach. So I ended up writing a whole paper, we call it an advisory note on this, that I entitled from deterministic to probabilistic security, why AI is foundational to cybersecurity. And if I had to bottom line it, it basically is where rule-based approaches, what I'll call traditional SOAR rules and playbooks and workflows, where that is weak, AI is strong, because they're essentially mirror image analytic techniques.
So if you look at the core paradigm, I flagged a few things that really demonstrate AI's strength relative to traditional, is that the core paradigm of a deterministic rule-based system is basically explicit. You have to author rules to have essentially some if-then-else functionality based on events and alerts that are coming into the security automation system. Whereas a probabilistic-based system like AI is, it's learned and statistical. It doesn't, you don't have to know really in advance. It comes up with the conclusions autonomously and through the consumption of data training.
How it adopts, you know, gets knowledge is, you know, on the rule-based side, you have manual rule creation and tuning, whereas on the probabilistic or AI side, it's all about the training for the most part, the training holistically about, you know, how to detect threats, how to investigate, how to triage, etc. Also trained with the customer's own data. And then there are other things that are the advantages of AI sort of generically, how it handles ambiguity, how it adapts to a changing environment, how it, you know, how brittle it is or isn't.
So where rule-based systems have, you know, low ambiguity handling and low adaptability and high brittleness, on the flip side, a probabilistic AI-based systems doesn't have those problems. Now, this is not to say that AI is a magic solution and has no faults. I'll get into some of those as well. But you can see how there's essentially rule mirrors of each other and where one is weak, the other is strong and where other one is strong, the other one is weak.
So before I get into the next, the findings and the leadership compass itself, the biggest impact in the AI SOC is the AI agent, is the autonomous specialized thinking system that is being applied to the various stages of security automation. So you need to understand what an agent is, presumably you've all come across it, but it's basically a software worker that can perceive reason and act on your behalf towards the goal. In this case, the goal is threat detection and response or exposure management.
So just keep in mind that I will talk a little bit about AI generically, but for the most part, the AI agent is where the action is in the AI SOC. So if you move to the next, you'll see that, of course, the use of AI is not new, but it has changed significantly. And there's some important things to keep in mind. So machine learning, essentially a core element of AI has been used for many years. It's essentially a system that helps with different types of behavior analytics.
It's data centric, meaning it essentially learns from real data, but essentially comes up with judgment as to, in the case of the security automation, is it a threat or is it not a threat? Has the account been taken over or not been taken over? So it's largely invisible to the analyst. It's sort of a backend functionality that in case the vendor or the backend system is applying, and it can be applied to a lot of behavioral detection.
So whether it's continuous authentication of users or what could be thought of as account takeover detection, insider threat detection, user and entity behavior analytics, looking at behavior of users and trying to find those that are anomalous and fraud detection. So it's a technique that's been used for quite a long time. But now when I'm talking about AI, I'm not really talking about machine learning. I'm talking about two other deliveries of AI.
First, the generative AI, which is essentially the, you know, you can think of a co-pilot or teammate that's a natural language. It's generative. It does incident explanations, case summarizations, recommendations. It essentially provides a chat interface in most cases within the security tool. And this is where AI moves from the back office to the front, where of course, you know, as a chat interface, it's very visible to the analyst. And that was the first area that AI started impacting security operations, you know, a couple of years ago.
But now, as I mentioned, the action is where, is it with the AI agent or where you can sort of think as a specialized agent or a specialized analyst or a junior analyst. It does functionality that you would recognize as something that a human user traditionally has done, triaging alerts, conducting investigations, doing threat hunting, you know, initiating response actions in some cases.
At the end of the day, it's a very visible functionality to the analyst because it's essentially acting like a specialist analyst, or you could think of maybe as a level one analyst, you know, or as an augmentation to your, you know, your more senior analysts. So keep in mind that AI has been around for a long time, but has evolved a lot in the last year or two. So now I'm going to go into the leadership compass itself.
But before we get to that, I want to talk a little bit, if you go to the next slide, the leadership compass itself is a, is a report that I published last month that talks about, that delves in deep depth to this marketplace and the vendors and the trends. And one of the big problem spaces that the solution is addressing are these longstanding challenges that have existed that have existed in the SOC. So I haven't listed them all, but the big ones are alert overload. So most organizations face way more alerts than they can actually investigate.
They have the challenge of needing 24 by seven coverage, but not necessarily having 24 by seven coverage, which is what drives managed services and, you know, people having to wake up at 2am when there's an alert that needs to be investigated. So it's a challenge, you know, from a staffing point of view, expertise is a challenge.
You know, if you have specialists in malware analysis, for example, or have specialists in, you know, threat intelligence, those are all things that, you know, building out of SOC with people has been challenging. And so there are many other challenges. And it turns out that the AI agents can be used to address all of these challenges. So which is why the adoption of AI in the SOC has been gaining steam. So moving to the next slide. So at a high level, the leadership compass looks at three things. From a vendor point of view, it looks at product leadership.
So this is sort of core functionality that is necessary for a security automation system to operate. It looks at market leadership. So that is, you know, the number of customers, the growth of customers, the investment into the companies to enable it to grow and to serve customers. And then importantly, innovation leadership.
Now, most of the innovation leadership for this leadership compass is in the AI area, not surprisingly. And basically what the leadership compass on the vendor side is, assesses the various vendors that take part in this research, and then comes up with leaders, overall leaders in innovation market leadership, product leadership, and then the combination of that is about overall leadership.
The point, one quick takeaway, other than the chart itself, is that you have a wide range of vendors taking part in this market. You have what I'll call the platform vendors. So that's the big, broad security automation or security vendors that have automation as part of their solution. You have standalone vendors. These are sort of new entrants into the market. And then you have some of those vendors also provide managed protection and response services on top of their own platforms.
So you can get this sort of AI generated security automation in multiple different ways from some of the vendors you know, and maybe some of the vendors that are new to the market. So going next. So in terms of key features, this, I tried to boil just the four key features that are, you know, the most important, this is, you'll see it sort of at the end, there are a lot more features that I evaluated. But the four big ones are obviously the use of generative AI, natural language AI, and AI agents, was a big part of the evaluation.
Because of course, this is where the innovation is happening in the market. Number two, the, the, you have to be able to collect and correlate events and alerts. It's a long standing SOAR functionality, it doesn't go away with the AI SOC at the end of the day. The AI SOC, it's mostly about triage, investigation, and various aspects of response management. So you still need your the detection happening, whether your endpoint, your network, human generated detections, so all that data needs to come into the into the system to be evaluated. And it acts as a, as a clearinghouse.
Number three is broadly integrations are absolutely critical. This is both to security systems that you have in your ecosystem, but as but your IT environment, like ITSM systems, for example, because because the, the security operations system is sort of the hub of all security automation, it needs to be able to consume and interact with with many, many different functions within your inside that exist inside an enterprise. And then finally, it needs to essentially manage and conduct and support investigations and orchestration with automation.
And so that's really what this solution space is all about is adding efficiency to the whole threat detection and response lifecycle. Okay, moving to the next. This one talks about this, you know, gives you a visual about all the integrations that are relevant in this space. And it's intended to be quite comprehensive.
And, and it shows you that to be a vendor in this space is not easy, because there are many different sims, there are multiple endpoint detection and response systems, there are sources of threat intelligence, there are multiple sandboxes that you might use to do malware analysis, you know, network systems, your, your service management systems. So that's all critical and has been true for SOAR for a long time. But if you notice on the on the left side, the MCP and RAG, those are agentic specific systems for that are now critical for your AI agents to operate.
So your RAG system, your retrieval augmented generation is about getting data from your enterprise to help the you know, to get essentially customer or domain specific information into your AI agents to make them, you know, more useful inside of your given enterprise. And then the MCP is essentially enables the arms and legs of an agent to be able to use tooling. So now in addition to the traditional points of integration and systems, because the agentic AI SOC has arrived, you have the need for integrations into more agentic specific systems like MCP and RAG.
But at the end of the day, all of these were evaluated as part of the assessment. So moving to the next. So key findings. So I brought down some key findings and recommendations that hopefully you can take away from this presentation. So the first one is, this is the Renaissance, you know, this is the SOAR market, security animation market, was basically born about 10 years ago. I was at RSA security, as I mentioned earlier, we had a SIM solution at the time, and we had been creating a security animation layer on top of it.
At the same time, other vendors were entering the market, both independent and other SIM vendors adding security automation. And so for the last 10 years, that has moved the ball, it hasn't solved all problems, for sure. I mentioned earlier, the existing problems that the AI SOC has been born to address. But if the world is now in a renaissance, it's a combustion of innovation and investment going on. And clearly AI and AI agents are the clear path for that innovation. Second one is threat actors are starting to use AI enabled tools. That's been reported on quite broadly, it makes sense.
I mean, threat actors use the best tooling available. That is what they do as part of the competitive technology race. So as they speed up their use of AI for their attack support, it only makes sense that the defenders do the same thing. And that's why you're seeing this cat and mouse game continue now with AI on the front lines. In the last 10 years, while the ball has moved down the field with SOAR, and it has certainly helped improve things, it has basically hit a brick wall at a lot of organizations. This is not to say that a rule deterministic based approach should go away, it shouldn't.
It needs to be complemented with an AI centric non-deterministic approach. Both have their values that I mentioned a few slides ago. But at the end of the day, I've come across many organizations that in effect, they were too busy to invest in the rule based automation necessary to become less busy. And the level of expertise and attention necessary to improve security automation beyond a certain base case is essentially the brick wall that SOAR systems have hit generally.
I mentioned on the top that you have the do it yourself SOC versus the managed detection or response has been out there for a long time. Most organizations use some level of managed services to cover 24 by 7 or to get specialized services. That is a dynamic that's now in flux. If you think of AI agents as being effective at adding analysts without adding people, perhaps the ability to invest in your own DIY SOC becomes easier and more affordable. And maybe it'll change the equation and bring more in-house security automation.
However, on the flip side, the managed detection response vendors are not asleep at the wheel. They understand that to keep competitive, they also need to apply AI based automation to their side of the equation. But at the end of the day, what has become a common outsource first for most organizations now is at least in question. And so it's something that can be considered. So off of those findings, I have a bunch of recommendations, just more than it's listed here or in the paper itself. But the first takeaway that I have in recommendation is it's really about augmentation, not autonomy.
You're not trying to replace your security automation or security analysts. You're trying to augment them to make them more efficient and effective. There's lots of opportunity for efficiency gains. But at the same time, organizations need to build trust in their agents as they don't just turn them on and set them loose. So if you're looking to replace people with AI agents, you're probably thinking of it the wrong way. You need your people to help essentially deploy and manage these agents and get the most out of them and build trust as you do.
The other recommendation is the classic sort of start small. Pick off a couple pain points as you're starting to deploy agents in your SOC. And if you think about the triage investigation and response cycle, think more on the front end. Think more on the triage investigation side versus the response side. So if you get lots of alerts that aren't reviewed, that's a great place for a triage agent.
If you have emails that are being submitted by your users because they're suspicious, maybe you never look at that inbox, you can apply a triage, a specialist triage agent to those emails to assess them automatically. Integrations remain critical. Data remains critical.
I mean, the AI systems and AI agents are very dependent on data. The more and better data that you feed into it is essentially the smarter the decision-making can be. So just because you move from traditional SOAR to an AI SOC, integrations are hypercritical and you have to think through what data you have that's necessary for the agent to be the best it can be. The final point I'll make here is that guardrails and approval boundaries, you need to think about them. Nondeterminism has its challenges, meaning you can't necessarily rely on the same output for the same input over time.
And you have to understand what impact that would have. So again, you need to build trust and you need to build guardrails and understanding of what risks you can take and what decisions you'll allow the agent to make and what the decisions essentially require the old human in the loop. So moving next. As I mentioned, you think about the threat actors, they use AI extensively and it's not surprising because it's a tool that's useful for both vulnerability discovery, but also further down the attack chain.
So in every one step of the attack chain, we've seen in publicly disclosed automated recon and creating phishing attacks. And once they've landed to help assess, they drop in their own agents to help assess the next steps and how to move laterally and how to exfil data. And the agents themselves that you may be deploying can become subject to prompt injections and other ways that a threat actor interacting with an agent can extract data from a rogue agent. So at the end of the day, this is to get across the point that just as threat actors using AI, so do the defenders. Moving to the next.
Now the issue about guardrails, I found a couple of these comics that really get across the point. Clearly you can't operate all of your AI decisions with a human in the loop, or that would defeat the purpose of the autonomy and automation speed of agents. So you don't want to dump every step into a person because then people act very slowly and agents need they're there to act quickly.
However, you can't totally eliminate the user. So you have to think about the decisions that an agent's making like a triage decision and decide how much oversight you need, but not have too much oversight. And I think that's the area that most organizations are struggling with now as to how to find the right balance between augmentation and human in the loop. So moving next, there is no free lunch. I'm a proponent of the use of AI and SOC for sure, but there are a lot of issues that need to be addressed as you do that. And of course, vendors are helping with this.
They're aware of these challenges. For example, I mentioned data quality and data engineering, that doesn't go away.
In fact, in many ways it becomes more important because the data is what is fed into the agent to help it make its decisions. And so the better data you have, the better the decisions. I talked about non-determinism. So the model can drift over time and the outputs can vary even with the same inputs. So you need to understand your system with that reality. You get operational costs. Just the final one I'll mention here is depending on how you're paying for the AI SOC, and it varies across the board right now, at the end of the day, tokens are being generated and someone has to pay for them.
And because it's somewhat non-deterministic, the steps that an agent or an AI system will take, the actual cost in the back end is kind of variable right now. So what that means is that someone has to pay, whether it's the vendor or the customer, and right now it's somewhat unpredictable. We don't really know when you sign up for these systems, how much it's costing. And so we think that that's an area where the whole industry as a whole needs to gain experience. So before we close up, I just want to give you a view of the vendors that were rated.
So you'll see probably vendors, you recognize their name and logo right off the bat and others that are new, maybe you don't recognize. And that's sort of the beauty of this kind of report is that we assess as broad a swath of vendors as we possibly can, but then come up with these sort of general findings and best practices that are sort of true across all vendors. So to delve into which each vendor brings to the party, strengths and weaknesses, obviously I'd point you at the report itself. And then just to give you a little visibility from one of the pieces inside, go to the next slide.
There is a much more detailed assessment of every vendor. I just use CrowdStrike here as just an example, but the spider chart here covers a very broad swath of capabilities that are assessed inside the report from the security of the system itself to the ease of deployment, all the way down to the types of events and alert systems that are integrated to the reporting that it's able to do to support your KPIs and your governance, your system governance.
So I haven't touched on any great detail of the underlying capabilities of these sorts of solutions, but be aware that inside the report itself goes into great depth into all of these categories of capabilities. So I'll leave you with one thought before going to your questions. Go to the next slide. We're in the midst of a journey here, a representative journey that I think we can all understand is the self-driving car. And the self-driving car has been something we've been talking about for more than 10 years as well.
When the self-driving car is created in a laboratory, they didn't just sell it and put it out on the market and have it driving in the public roads. It's been going through a very meticulous testing and refinement in case with the human in the loop, behind the wheel in some cases, but also continued refinement of the technology, the governance, the regulations, et cetera. We've all been sort of as an industry, that industry has been sort of feeling its way through going from no autonomy to full autonomy.
I don't think it's going to take that long for the AI SOC, but in principle, we're going through the same process where these systems are being invented and innovated right now and being applied in the real world. And it's not like we're the industry suggesting just turn it on and get rid of everybody and turn off the lights and let the SOC do its thing with the AI agents. We're not there yet, probably never will be. It's an augmentation technology, but philosophically, we need to go through the trust building process that's kind of parallel to what's been going on with the self-driving cars.
So next. So I'm going to go to push this poll out and I'll read it off for you. The question I'm asking here is we are or will bring more of our SOC services in-house, meaning you in the audience, over the next year or two. So are you planning to bring more of your SOC services in-house versus having an outsourced managed provider over the next year or two? Do you essentially agree with that statement? Do you disagree with it? Do you think you're going to stay about the same?
Or, you know, it's not really relevant because you don't use managed services or you don't know the answer. So please answer this poll and I will report on what you guys saw in a minute. So just want to, before I take your questions, there are a number of resources that Cooper & Drew and Cole has that all relate to this. There's the leadership compass itself, which I'll point you to here. There's an advisory note that was published by my colleague called Navigating the Eugenic AI Security Landscape.
There's the AI Security Fabric, which is an analyst chat done by Martin Kupinger, the founding analyst of this firm, which is really, really good and it's available to anybody. There's the Emerging AI SOC Buyer's Compass, which I wrote focused more on the enterprise and how they should think about selecting and adopting AI in their SOC more generally. And then there's a paper, the advisory note I mentioned, that talks about generically about determinism versus probabilistic security and why AI is, you know, a nice mirror image to a rule-based approach. Okay.
So this is just a little bit of promotion on some services that Cooper & Drew & Cole provides to you, to anyone out there. We provide this kind of research on an ongoing basis on many different identity, cybersecurity, and AI security topics. We do events and webinars like this. We also have an arm of our business, which is advisory focused on enterprises and how they, you know, essentially helping them come up with a roadmap and a strategy and tactics on adopting technology, security technology such as this and many others. So keep that in mind as you're thinking about Cooper & Drew & Cole.
And go to the next. That's just a little bit about advisory services. So if you're interested, if you're an enterprise and you're looking for some expert consulting help, take a snap of that screen and, you know, take it right to a description of our advisory services. Go next. And then I also want to point out an important event. We just last week had our European identity conference and cloud conference in Berlin, Germany.
All that content is now on the Cooper & Drew & Cole website, but there are other what we call impact days that are coming that really talk about the use and the need for better identity management to help address not just AI, but to help address cyber security more broadly. And if you have any questions of me, now is the time to ask them. I will go to the questions tab right now and see what's there. So post a question. There is a couple that I will consume now and give my answer.
So here's kind of like the AI washing question, I guess I would say is, you know, how do we distinguish a real AI SOC capability from vendors simply adding AI branding to existing SIM, SOAR, XDR, MDR offerings? I'd say the ability to sort of fake your way through AI is basically gone away.
You know, remember I talked about machine learning is a back office function, which the end user can't really see. The day of generative AI and AI agents is right in the face of the analysts. So it's really not possible to do any more. You really have, you know, from a buyer's point of view, they're right there. You can use them. You can use them in a POC.
You can, you know, build trust with them as you deploy them. So that AI greenwashing thing has more or less gone away with the trends in AI. Question really relates to how quickly do I think AI will be adopted in the SOC? I guess my quick answer is it's kind of slowly and then all of a sudden.
You know, lots of organizations, particularly if we're in the early adopter phase, for sure. So it's, you know, the usual suspects that adopt new security technologies are, you know, are putting their foot into this, these new capabilities. And so as we exit the early adopter phase and as, you know, the innovations, you know, turn from theory into practice, I think you're going to see a pretty fast adoption because the pain that it's addressing is pretty high.
And the early signs are that the AI agents are quite effective in doing things that we really need them to do, like doing triage or providing 24 by seven coverage because, you know, they don't need to go to sleep. Final question I'll pick off is, you know, where is your traditional rule-based automation still a better choice and where does AI-driven or authentic approaches provide operational value?
So I'll bring forward an AI expert that I used to work with a number of years ago, and he told me once, and I'll never forget, that, you know, if you can write a rule to do what you want, you should do that because there's lots of advantages of determinism and speed and low cost and, you know, the same response with the same inputs. But if you can't do that, AI could be a good possibility. So like I said a number of times, I view this marketplace as being a combination of rule-based automation and AI probabilistic non-deterministic based automation because they're natural complements.
And so I think both sides of security automation will operate together for the foreseeable future as AI sort of gains its position in the security automation market. So let me close it out there. Let me just check if there's anything else.
No, I don't see any other questions. So thanks so much for everyone's interest, and I hope you'll go to the Coup & Dracul website and pick up on our blogs and our reports, some of which are available publicly, some of which require a license, but we're here to help you sort your way through the use of AI in security generally, but also specifically in your security automation programs. So thanks very much for taking part.
See All Locations
See All Locations