Hello everyone, welcome to today's videocast. I'm Matthew Gardiner, a fellow analyst here at KuppingerCole, and we're going to get into the topic of security automation and the rise of the AI SOC. This is essentially a discussion around a report that we published last month called the Emerging AI SOC Leadership Compass, so hopefully you will or have read that. I want to welcome my color commentator, Rick Bosworth, who's head of product marketing. Give us a little introduction.
Yeah, sure. Rick Bosworth, product marketing with Torque. So I'm going to do a little play by play and then Rick's going to chime in with some color commentary about his experiences and the experiences of Torque with their customers.
Okay, so let's get into it. So first, just a level set for those of you who know KuppingerCole and our research, probably already know what a leadership compass is, but for those of you who are here for the first time, leadership compass basically is our pillar research in any particular area of cybersecurity, in this case, security automation.
And basically what we do in this sort of research is we look at the market, the trends, the customer requirements and needs, and of course, the vendors in the space and produce a report that among other things, assesses the vendors so that will help enterprises select the best vendor for themselves. The one graphic you often see when it's published is this overall leadership compass, which basically distills the vendor assessment into one single graphic and it takes into consideration product capabilities, essentially core capabilities of a given product domain.
It takes into consideration the market position, meaning, you know, number of customers, growth of customers, level of investment and other factors, and then importantly, it takes in innovation and particularly in this domain, innovation is really about the application of AI and AI agents to the needs of security automation. So you can see here, Rick is representing a company that did well on this report and so should be able to add a lot of color to what we're going to talk about.
One quick note is that you'll note that the vendors, there's some names you maybe recognize, some names you don't recognize, and that's, you know, endemic of the market space is this. You have platform vendors, you know, sort of the big security vendors that have security automation capabilities among many others. You have specialist or standalone vendors like Torque and others that are, you know, essentially a new entrance into the security automation market. And then you have some vendors that also provide managed detection and response services on top of their platform.
And that is, you know, just part of their service delivery. Not every vendor does it. Some vendors are supporting independent managed providers, but that's a factor that we are going to talk about as we begin. So just to, again, to level set, we're mostly going to talk about the use of AI agents in security operation centers.
So, you know, an agent is, you know, the top topic in the world with these days. But just to think about it, essentially it's a worker, you know, very simple, you know, definition. It's a worker that can perceive, reason, and act on your behalf toward a goal. Obviously when you bring agents into the SOC, it's about, you know, threat detection, triage, investigation, malware analysis, and, you know, response procedures and other things you might like to automate. So you have agents that are specialized in those domains. And that's really what we'll be talking about here.
And you know, Matthew, if I, if I could add right here in going out in the field and speaking with CISOs and practitioners, you know, sometimes the topic of the underlying model behind the agent comes up. And the best advice I offer around the underlying model, I think it's a discussion that misses the real issue. It's less about the underlying model behind the agent, because the CLAWD, OpenAI, you know, Anthropic, they're all going to be innovating and moving.
It's really more about what you have built, tested, iterated, hardened, and optimized atop that substrate that makes the AI agent able to act on your behalf. Yeah, totally.
I mean, I think of those foundational models are all the things you don't have to recreate to deliver these services, like interpreting language, you know, you don't want to have to create that. You know, it's not like, you know, understanding code, for example, or interpreting logs, you know, that's sort of a core function. But then what the specialized agents need to do is bring it down into the domain of security automation. And that requires different sorts of data integrations and other things to make it useful in the domain of a SOC.
So again, I presumably, what I've seen is that the providers of AI agents in the SOC are basically going back to any number of those foundational models based on cost and performance at any given time and using them, you know, switching around as necessary. All right. So let me move on. So there's basically some longstanding challenges that have existed since SOCs really have existed as a, as an entity over the last at least 10 years, probably more.
I mean, you have, you know, alert overload, you have, how do you provide 24 by seven coverage? How do you overcome the fact there's a lot of specialized knowledge needed, you know, the trade off between dialing in to reduce false positives, but perhaps getting more false negatives, but not overflowing yourself with alerts, having great expertise basically to know what an attack might look like. So these are challenges that, you know, every organization deals with.
And what, what my overall view of this is that we're sort of in this renaissance, this new approach, AI agent based approach to address these longstanding challenges. I assume you see it the same way, right? We sure do. When we think about the adoption of AI in the SOC to address these longstanding challenges, none of which we're going to solve by throwing people at them, right? This is the role that agentic AI is adding. But CISOs are telling me that transparency and control are fundamental to their willingness to adopt and expand. The adoption argument is really already over.
We see statistics out there that a plurality are already using some form of AI for some use case within the SOC. And that's published in research from TORC that we did a blinded study of 450 security SecOps professionals worldwide.
But yeah, with the transparency, the agent has to show its work. With the control, autonomy can't be a light switch. It can't be a binary choice between human or agent. There has to be some interaction. It needs to be more of a dial. And that's sort of a classic early adopter issue is, you know, clearly there are problems we haven't been able to solve with traditional SOAR or traditional rule-based systems. But in a new technique, it's exciting, but it has other challenges.
And so it's sort of gaining, your sort of summary is how do you gain trust and to know how much autonomy to allow versus how much control you need. It feels like we're in that discovery phase with the early adopters. I had the same read of the room. Good. Another sort of key driver is, of course, what the other side is doing. And the other side is doing what they always do, is they apply the latest and greatest technology to help them with their attacks. And so if you think about the attack chain, AI is very useful all the way down the attack chain.
And we've already started to see threat actors do it. You've seen publicly disclosed breaches and researchers talking about this issue. So I think it's inevitable that they will use this tool because it provides them ROI. And my view, as they accelerate and become more efficient at their attacks, it's only obvious that you need to use similar technology on the defense side. And that's essentially driving the need for AI and security generally, but also in the security automation space. So I don't think there's any controversy there.
No, no controversy. Fully agree. The basic one of the points that as I was putting together this report, I found myself sort of trying to explain the rationale at a high level of why you apply AI based techniques to the security automation challenges that we talked about a couple of slides ago. And the way I sort of think about it, it's essentially like a mirror image to a rule based system. Rule based systems are what we're used to. Rule based systems have their place, but they sort of hit a brick wall.
And so the weaknesses of rule based systems shown here are really addressed by a probabilistic based system that leverages AI. And so where rule based systems are weak, AI based systems are strong. And in many ways, vice versa that we'll talk about. Totally.
And, you know, when people think of SOAR, you know, that has a connotation associated with it, you know, inflated promises, difficulty extracting value. You said something in your research, Matthew, about it hitting a wall. I couldn't agree more.
That wall, people have been banging their head against it now for years, actually. But the one thing I wanted to add with regards to agentic AI, that can reside within your classic workflows or outside of those workflows. You can give declarative instructions and access to data and a certain set of tools that you define, that you limit. The agent is not going to run amok. It only does what you allow it to do. And the more specific the role you can define for the agent, the better results you will get. It basically provides determinism, providing a guardrail around what the agent will do.
Not dissimilar to the guardrails you might provide around your people. Kind of the same idea, just sped up a bit. Reminds me a little bit when I, previous life I worked, I had, I was a product on the product team of a store product. And we used to see, you know, customers make some good, get some good value out of it.
But we'd see other customers that I would sort of summarize as they were too busy to do any work to become less busy because it required them to have a, you know, an active engagement in the rule writing and the playbook writing that they could then use to automate other things historically were manual. So they were sort of caught that wall where they just couldn't spend the time and effort and or have the sufficient knowledge to essentially automate their way out of these problems.
So that's one of the value proposition of AI agent is it will do a lot of the work for you because it's, you know, it's a thinking thing in a way. Another sort of takeaway, something to think about is, you know, integrations have been critically important in security automation since security automation existed.
I mean, you need to integrate to alert sources, SIMs and EDRs and network detection devices. You need context, you know, to make a decision, you need data from threat intelligence services or your asset management systems or DHCP or other things that know about your environment. And you also need the ability to take action. You need the ability to quarantine machines or reset, you know, force password resets of users. That's all remains true in this new world. But then there are also a couple other new types of integrations that become increasingly important.
That's the RAG and the MCP, which are, you know, uniquely agent centric integrations. And so you need, when you're, when you're evaluating security automation in this new world, you need to think, still need to think about the systems that you have, the integrations you need, and then how to expose your, your resources using these more standard upcoming techniques from the agent world of RAG and MCP. So presumably Torque spends a fair bit of effort on, on integrations. Most certainly. And we have hundreds of integrations ready to use right out of the box. Every security stack is unique.
You know, obviously somebody might have a different EDR, different firewall vendor, what have you. So having an extensive breadth of integrations that are ready to use helps. But you know, ironically, we figured out that all the agentic AI that we, we are using ourselves, we figured out how to use agentic AI to immediately build integrations for us. So any integrations that don't exist, you know, as long as the API is documented somewhere and it almost always is, I can't imagine that it's not, I've not run into that. We build it in minutes.
I mean, it's super easy. And so you're vibe coding your integrations basically. Correct. Somebody comes to us and they have a special snowflake security stack.
Oh no, we would really love to use Torque, but you don't integrate with our favorite security vendor. We come back an hour later.
Hey, here it is. The beauty of AI coding, and it will be hard to, for a human to code an API that has no documentation either.
So let's, let's hope that if you have an API that you want people to use, you document it. Yeah. That's definitely a key breakthrough. And you know, with, if they're not using MCP or, or, you know, RAG, you know, that you can at least take their, you know, their API and build something relatively quickly. I can imagine a world where a lot of them will just build MCP or RAG interfaces and off we'll go, but not quite here yet, but coming.
So I, at the top, I talked a little bit about, you know, sort of the changing nature of how you do security automation from a strategic level. I mean, there's always been this choice between what I'll call a DIY or enterprise built SOC or a largely outsourced version of that with a managed security service provider.
Those worlds still exist right now, but because the arrival of AI agents, at least in theory, makes it easier to build your own SOC, perhaps you'll use less managed services, but on the flip side, the managed service providers are aware of this and need, you know, automation themselves to make their business more efficient and effective. So they're also adopting agents on the other side.
And what, you know, I don't think we know how this is going to sort itself out, but the optionality that organizations have has increased. And I assume you're seeing, you know, your customers become, you know, both enterprise SOCs as well as managed providers.
Yeah, most definitely, because agentic AI is fundamentally changing how we understand work. And there are reasons why some enterprises choose to have a DIY SOC in-house versus outsourcing that to an MDR service.
And, you know, now people are raising the question in the role of agentic AI, I'm using an MDR, do I bring that in-house and build my own? I think there is opportunity.
And we, before I get to the opportunity, Torque has customers on both sides of the house. We have Fortune 500 customers. We have people on the FTSE. We have global enterprises, thousands of employees. We also have their SOC in-house. We also have what we call M Partners, MDR, MSSP, all these things as customers. What agentic AI is doing is creating an opportunity for people to examine whether or not they want to bring their SOC in-house and also for the M Partners, the MDRs, to say, well, hey, wait a minute, I can add a value-added service on top of my business that relies upon agentic AI.
It's really interesting. It's early innings yet, Matthew. I don't think we've seen how this is going to shake out, but I do believe in the value of human ingenuity. So it's going to be interesting to watch.
I think, obviously, it's good for the customer to have this improved capabilities and optionality. I think about, you know, one reason people go to managed providers is 24 by 7 coverage. So they have some SOC on-house, but it doesn't make sense to run a 24 by 7.
Well, I mean, maybe we'll be at the point where agents can be your 24 by 7 coverage, at least on the initial triage and maybe, you know, basic remediation. So if that's the reason you're going to a managed provider, maybe that reason goes away. On the flip side, you know, you have managed providers that, you know, in the worst case are just sort of like, yeah, alert forwarding services, which, you know, doesn't have much value.
But perhaps if the alerts they forward or, you know, the incidents they forward have already been vetted by a reliable triage process, then those incidents are more valuable. So you know, there's definitely value that can be created on both sides. I agree with that. And you know, you mentioned the triage use case, that's the classic use case that usually the first thing that comes to mind when enterprises are looking at agentic AI in the SOC. Why? Because there's real pain there.
Their SecOps analysts are drowning, you know, maybe one in four, I can't remember the exact stat, but one in four alerts are going unvetted before they age out of SLA or they may not ever get to it and they just move on. Agentic AI delivers machine speed and scale. So naturally, there's a relatively low barrier to entry for agentic triage. And so that's why we see so many vendors chasing after, you know, the agentic triage use case.
However, I'll add that if all you're doing is triage, all you've done is move the bottleneck. And I think we'll be talking a little bit later. You have a really compelling graphic, a few slides down the road.
Yeah, no, definitely. We'll talk about when we go into the sort of recommendations. That's a key topic. Where do you apply it? Right here.
Oh, there's this one. Yeah. There's this one. So the old fallback for, you know, I don't trust the agent or I don't trust the AI is the old human in the loop backstop. Our lead analyst, Martin Kubinger, the way he talks about this is that AI agents hate people because they're slow.
You know, you're essentially attaching a slow human to a fast computer and that kind of defeats the purpose. However, on the flip side, you know, it's not like we're going to go to full autonomy. So the challenge that a lot of early adopters have is to find that right balance. Clearly you don't want a dump truck loading every approval request on people or just making the person push a button every time the AI agent makes a decision.
However, having said that, you need to find those areas that that's absolutely critical. So how do you find your customers kind of dealing with this quandary between human in the loop and automation? Yeah. So they're dealing with it by building trust and everyone's on a journey.
So it's, I'm a stats geek. So it's a distribution. On one hand, we have a fortune 500 retailer who today, 51% of their tier one and tier two alerts are handled completely autonomously using Torque Agentic AI from alert triage through resolution of root cause. It's all automated. Now with Torque, autonomy is a dial. It just so happens that this one customer has turned the dial up to 11. Most customers, and this customer has been with us for a while. So they have learned a great deal of trust in using agentic AI within their SOC with their policies.
They bent the AI to their will, as everyone should. This is a matter of trust. As you build your trust in your SOC with your instances of agentic AI, I would advise everybody as we do our customers to start small. Take a value added use case in a certain green scope of assets that makes sense for you and your business. Take it for a test drive. See how it's working. Find the potholes on the road and plug them. And I think that's going to be the playbook for success.
You know, nothing breeds success like success. So start small and build that trust.
And then, you know, 51% is essentially fully automated, that means 49% aren't. So it's not like they've gone 100. They're just, you know, presuming down the road or 51 will be 60, you know, and that helps a lot. And I speak with the CISO on occasion. And then I speak also with the people that speak with the CISO more regularly than I do. They have a line of sight to 75% fully autonomous of tier one and tier two by the end of this year. So that's interesting. Another point, and, you know, I'll never dox our customers, this person is not interested in firing any humans.
Their humans are very skilled. And they see agentic AI is working alongside their skilled staff. And that actually is Torque's perspective on using agentic AI in the SOC. I think we are light years away from being able to replace humans with robots. It actually brings me to recommendations. First recommendation, you hit it already.
For me, and it's clearly Torque agrees, it's about augmentation, you know, not autonomy, maybe partial autonomy. There's a lot of efficiency gains that are low hanging fruit.
And sure, maybe some executives will make the wrong decision and think they're going to go to autonomy just to save money. But I think they're going to get bitten.
Yeah, I think so. The whole idea with automation in every domain is to elevate the people out of the grinding, low value work and help them, you know, be the supervisors of these automation systems. You hit the nail on the head right there. So second thing is where to start. I have a couple comments on it consistent with what you said is, you know, if you think about the spectrum of triage or alert triage investigation and response, it makes sense. And generally, my research organizations are on the front end of that.
They're focusing on the use of AI on the triage side, partly because it's a great weakness. You know, the alert overload is essentially a lack of sufficient triage. The second thing is it's, you know, a triage decision doesn't necessarily lead to an automatic response. It leads to a bucket of clearly bad things, clearly OK things. And the ones in the middle and the ones in the middle can, you know, can be handed over to a person to further evaluate. So start on the front end.
Things like, you know, suspicious email triage or a certain other types of triage or threat hunting where you're going out and looking for suspicious activity based on perhaps other threats that have been found out in the wild. I think over time, the organizations, as trust is built, will move towards more response procedures, things that are, again, probably low risk, like quarantining a machine that's not a critical machine, like an end user machine, or, you know, forcing a password reset.
You know, again, you're not, you know, booting the person from the environment entirely. You're just saying, hey, let's let's do a password reset because we're a little suspicious of your activity. So I assume that that's essentially what you're recommending, what you're seeing. Most certainly. And one size does not fit all. So depends upon your SOC, your industry, your high impact use cases. So if a prospective customer is looking for some consultative discussion around where should they start first, TORC will begin by asking many questions.
We have a Fortune 500 retailer that within 48 hours of using TORC had deployed Agentic AI for email phishing across their enterprise. That was amazing. They were really appreciative of that. And earlier I said, success breeds success. They very quickly climbed that learning curve. And then they were like, all right, one down. What's the next one? Okay. Typo squatting is most important to us because of our brand reputation as an online retailer. So Agentic AI, now humans don't have to do this. It's all fully automated. They're like, all right, that's two.
And then three, you know, it was amazing how many of this specific customer said goodbye to their legacy SOAR. They were up for renewal and they did not want to do that. They knew that the technology had changed fundamentally. And then they said, we want to be into this AI SOAR platform business, TORC, can you help us? We had taken this Fortune 500 retailer and fully transferred four years of legacy work, technical debt, all these playbooks, some of which were redundant. We transferred everything, we optimized it, and we created that cognitive space for them to get creative.
We did all the grunt work in days, not weeks. And once that was done, it was, okay, what's next? What's fun? What's imaginative? What we can do?
So, I mean, it's a really interesting use case in that it really would thrill any executive upline or board of directors with what this team accomplished. My comment earlier was, you know, in my traditional SOAR role, you know, I'd find customers that were too busy to do any work, become less busy. So essentially what you're saying is you've taken away those two busy things so they could be creative to do things and to work with agents in this case to become less busy. Absolutely.
So, you know, that's the snowball rolling downhill that we all want to see. Another sort of recommendation takeaway is that we talked about, but integrations and data remain key. It probably, I should have said, is more important now because of course an AI system is inherently a data consumption system and it draws inferences and it bases its conclusions and recommendations on the data that it's consuming. So the better the data, the more of the data, the different flavors of the data that are related to the decisions you're trying to make, the better.
And so unfortunately or fortunately, the data is the core element of making your AI smarter. And I think this speaks to control and transparency once again. So in terms of control for agentic AI with Torque, we call this Torque hyperagents. The customer can start from a template and we have dozens of templates and hundreds of integrations or you can start from scratch. Give the hyperagent a declarative instruction or a role, a goal, tell it what it is authorized to do and what it must never do. It's really easy. And then tell it what it can access.
It's not going to run amok amongst your enterprise. It's not going to do anything untoward. Give it the guardrails.
Tell it, I can access this dataset, this tool, this dataset, and these three other tools. And then let it go do its job. That's the control. And then the transparency aspect comes into play when, all right, show me your work. Let me inspect. What was your reasoning? What artifacts led you to draw this conclusion? And you know, it's like any interaction that you have with Claude, right? You give it an instruction and it tells you what it's doing and then it does the things and you can go back and rewind the tape and see exactly what it was doing along the way.
Once customers get a taste of Torque hyperagents, in my experience, they can't get enough. That makes sense. And then it's sort of like AI use in general, once you get a taste of whatever your use case is and you get comfortable with like telling it, no, no, no, I don't do that.
You know, give me a graphic that's more like this and then it iterates and it actually, you figure out how to better explain what you want. And particularly if you're not doing automated remediation, which is where things are changing in your environment, that's part of the trust building and, you know, you're learning how to use the tool in an optimal way. So the final thing we sort of were touching on already, but, you know, the guardrails, approval boundaries, the reality is, you know, this is the learning is you have a non-deterministic system.
You know, in the rule-based world, you write a rule that's if, then, else, and, you know, you can reliably, you know, conclude that it will make those decisions because it's mathematically deterministic. In this world, not so much. The advantage is that you have a thinking, a thinking system, if you will, but these thinking systems, you know, might make decisions that you didn't expect or that might change over time.
And so sort of combining the need for determinism and this flexibility you get from a non-deterministic system is this learning and this trust building that we're all sort of starting to live through right now. Matthew, I believe you said it earlier in our discussion, something about the agentic AI being your junior analyst, you know, junior analysts make mistakes, right? But as long as you have the ability to coach up the analyst, help them learn from the mistakes and then limit the blast radius and then unwind what they did, you know, you're helping them be better.
And then that ties back to our trust. No one's going to throw a junior analyst on day one into something that they can break and cause irreparable damage. Build that trust, build that success and move forward.
Yep, totally. So before we close out, I'll ask the sort of big question is how fast do you think AI and AI agents are going to be adopted in the world of security automation in the SOC?
Well, first of all, the adoption is much faster and it's already there. With regards to agentic AI adoption, as of January of 2026, Torque did a sampling of the market for 150 security practitioners and leaders, 56% of those respondents are already using agentic AI. Now I will tell you back in April, just what, two, three months after we did the survey, subject to sampling bias, right, I went out and I met with over 200 CISOs over the course of some roundtables, you know, perfectly scientific survey by show of hands, right? How many of you are using agentic AI? It was a lot more than 56%.
It was approaching 75%. So the appetite is there, you know, and this is changing fast and I'll share a little anecdote. About two years ago, I was extremely frustrated with agentic AI.
You know, it cost me more time to tell it and coach it to do what it is I wanted it to do. The technology, the foundational models that we were talking about were not ready for what I needed it to do. Then something happened about a year ago. It suddenly became a thought partner or not, if not a thought partner, it became, you know, a junior marketer that I could trust. I was like, okay, could you outline a blog for me? Could you outline social media? Could you do these things for me? Give me something to react to. And then it evolved even further.
And now it's acting more like a, I would dare say, a fourth year college student, you know, instead of a high school or middle school student, now it's actually an intelligent person that's synthesizing insights and giving me something really needed to react to. So I think these are the reasons why there's, I'm not unique, you know, everyone else is seeing the same thing I see. And so we're all adapting to the changing universe. And I guess this was a lot of words. My apologies. I'll close by saying, you know, first there was Bill Gates and Microsoft Windows. Then there was Dell and the PC.
Then there was the internet. I really do believe that agentic AI is another one of these foundational transformative technologies that I call it a market externality. It's a positive externality that's coming in and fundamentally changing how we work. I see that and I see it happening.
Yeah, totally. It's obvious. If you read, you know, listen to the news, it's happening all over the place. In our little world of security and within our little world of security automation, it feels to me that this is one of the critical use cases because it's the area of, again, maybe it's bias because I've lived in this security world for 25 years, is that we're so out of control, you know, we're not in control using techniques up till now.
And it's not necessarily because of incompetence, it's just the complexity and the fact that we have a human threat actors on the other end, you know, forcing, you know, they're not trying to play by the rules for sure. You know, we need a new approach to address these challenges we haven't been able to address. And within security automation, I think it's like the front end of that insecurity, like this is where the innovation is happening, even within security.
So an advantage of many is that if you apply security, AI agents and AI and security automation, you're actually going to learn a lot, not just about the application of AI and security in general by doing it in security automation, but you're actually going to learn about the application of AI in general to your business. So you can use this as a lead for your whole business.
And I do see some companies funding this effort that way because they have a requirement from the board to apply AI to their business and they're raising their hand and say, we have a great area to apply it in the SOC and they're like, check, that'll meet the requirement of the board. And then those people can become thought leaders in the application of AI more generally. You got it, you know, it is totally exciting because, I mean, you mentioned the board, the CEO, Val Schult, use agentic AI, everybody's, okay, what does that mean?
Meanwhile, the CISOs are looking at that, oh boy, you know, what do we do to prevent data loss and all the things. But there's also that opportunity that you alluded to, everyone is struggling with how to use agentic AI. What if the cybersecurity leaders recognize the opportunity, we're going to apply agentic AI in our SOC and we will be the template, the guiding light, the roadmap for the rest of the enterprise to use and apply agentic AI, build that trust, find those use cases, find success, how to use agentic AI securely, rationally, and for profit.
Because all the challenges of the application of AI in general apply to security animation, apply generally to the other areas that you can apply. You got it. So thanks very much. I just put up a reference to some other Coupling Drink Coal content that, you know, that informs this topic. Thanks Rick for your color commentary on this topic and thanks to everyone for listening all the way to the end and hopefully this has provided you some value.
Matthew, thank you so much.