Protect cluster · SOC, security engineering
Technology Rewired: Cybersecurity Operations
Security operations moved from on-prem SIEMs and box firewalls to cloud SIEM, EDR, and SASE, then to ML detections and copilots. AI SOC agents now triage alerts and run investigations end to end, handing analysts a verdict and evidence. Containment actions that touch production or people still need a human to approve them.
The shift: Agents triage alerts and run investigations; analysts approve.
Supervised agents today
3.9 in five years
How has the cybersecurity operations team changed across five eras?
Era 1 · On-prem
Before 2005
0.3Security was a few engineers running firewalls, antivirus, and an on-prem SIEM that collected logs few people read. Large companies built SOCs with tier-1 analysts watching consoles in shifts, escalating to tier-2 and incident responders. Most detection was signature-based.
Era 2 · SaaS and cloud
2005 to 2020
1.0Cloud SIEM, EDR, email security, and SASE moved the stack to SaaS and multiplied the alerts. The SOC pyramid widened at the bottom: tier-1 analysts triaging queues all day, SOAR engineers writing playbooks, and MDR providers covering nights for teams that could not staff them. Burnout and turnover became structural.
Era 3 · AI-assisted
2020 to 2024
1.7ML detections and vendor copilots helped analysts write queries, summarize alerts, and explain malware. The analyst still opened every alert and decided what was real. AI made each analyst faster without changing the shape of the queue.
Era 4 · Agentic
2024 onward
2.6AI SOC agents now take an alert, gather context from SIEM, EDR, identity, and email, and return a verdict with the evidence attached. Analysts move from triage to review and response, which is the trade I weigh in human vs AI agents in cybersecurity. The same speed helps attackers: AI compresses the vulnerability lifecycle on their side too.
The security team now also owns agents as a new class of identity and insider risk, including whether anyone can stop one, which is what the kill switch test measured.
Era 5 · Next 5 years
2026 to 2031
3.9My bet: the tier-1 queue disappears into agents within five years, and the SOC becomes detection engineers, threat hunters, and responders who supervise agent verdicts and approve containment. Small companies get a SOC through agents and MDR rather than hiring one. The new failure mode is an attacker who targets the agent itself.
Which cybersecurity operations software is being rewired?
- SIEM and SOC Platforms
SIEM and SOC platforms are moving from log correlation that humans triage to AI agents that triage and investigate alerts themselves. ArcSight and QRadar collected events. Splunk Cloud and Sentinel moved them to the cloud. Today agents from Microsoft, CrowdStrike, Google and Torq close false positives on their own, while analysts still approve containment.
- Email Security
Email security moved from hand-tuned spam filters and on-prem gateways to cloud gateways, then to API-based behavioral AI that reads relationships instead of signatures. Since 2024, agents from Microsoft, Sublime and Abnormal triage user-reported phishing and remediate whole campaigns, while analysts approve the consequential calls. Next comes verifiable sender identity.
- Firewall and Network Security
Firewall and network security moved from hand-edited rule bases on Check Point and Cisco boxes, to next-generation firewalls and cloud-delivered SASE, to AI copilots that explain policy. In 2026, agents from Palo Alto Networks, Check Point, Fortinet, Zscaler and Cato troubleshoot, tighten rules and patch virtually, while humans still approve high-impact changes.
Coming next
- Endpoint security (EDR/XDR)wave 2
- Vulnerability and exposure managementwave 2
- SOAR
- SASE and ZTNA
- Network detection and response (NDR)
- Penetration testing
- Threat intelligence
- Cloud security (CNAPP)
- Application security (SAST and SCA)
- DLP and DSPM
- Security awareness training
- AI and LLM security
Also wired into this category: Coding Assistants and IDEs, SOC 2 and Compliance Automation, Help Desk and Ticketing, Identity and Access Management (IAM and CIAM), Incident Management and On-Call.
Keep reading
Essays and analysis
- Human vs AI Agents in Cybersecurity: Who Should Guard Your Data?
- From Zero-Day to Zero-Hour: How AI Compresses the Vulnerability Lifecycle
- The Kill Switch Test: Only 11 of 47 Checked AI Agent Security Vendors Publicly Claim You Can Stop a Rogue Agent
- The CISO's AI Defense Playbook: A Practical Framework
- How to build a cybersecurity team for startup
What died (Tech Graveyard)
What comes next (Future Tech)
Comparisons
- Top 5 SIEM Tools of 2026: Microsoft Sentinel vs Splunk vs the Rest
- Top 5 SOAR Platforms for 2026: Cortex XSOAR vs Splunk SOAR vs Tines vs Torq vs Swimlane
- Top 10 EDR/XDR Platforms of 2026: CrowdStrike vs SentinelOne vs the Rest
- Top 5 Email Security Platforms of 2026
- Top 5 NGFW (Next-Generation Firewall) Platforms of 2026: Palo Alto vs Fortinet vs Check Point vs Cisco vs Juniper