Skip to content
Draft. This page is in editorial review and is not indexed yet.

Protect cluster · SOC, security engineering

Technology Rewired: Cybersecurity Operations

Security operations moved from on-prem SIEMs and box firewalls to cloud SIEM, EDR, and SASE, then to ML detections and copilots. AI SOC agents now triage alerts and run investigations end to end, handing analysts a verdict and evidence. Containment actions that touch production or people still need a human to approve them.

The shift: Agents triage alerts and run investigations; analysts approve.

Verified
2.6

Supervised agents today
3.9 in five years

How has the cybersecurity operations team changed across five eras?

  1. Era 1 · On-prem

    Before 2005

    0.3

    Security was a few engineers running firewalls, antivirus, and an on-prem SIEM that collected logs few people read. Large companies built SOCs with tier-1 analysts watching consoles in shifts, escalating to tier-2 and incident responders. Most detection was signature-based.

  2. Era 2 · SaaS and cloud

    2005 to 2020

    1.0

    Cloud SIEM, EDR, email security, and SASE moved the stack to SaaS and multiplied the alerts. The SOC pyramid widened at the bottom: tier-1 analysts triaging queues all day, SOAR engineers writing playbooks, and MDR providers covering nights for teams that could not staff them. Burnout and turnover became structural.

  3. Era 3 · AI-assisted

    2020 to 2024

    1.7

    ML detections and vendor copilots helped analysts write queries, summarize alerts, and explain malware. The analyst still opened every alert and decided what was real. AI made each analyst faster without changing the shape of the queue.

  4. Era 4 · Agentic

    2024 onward

    2.6

    AI SOC agents now take an alert, gather context from SIEM, EDR, identity, and email, and return a verdict with the evidence attached. Analysts move from triage to review and response, which is the trade I weigh in human vs AI agents in cybersecurity. The same speed helps attackers: AI compresses the vulnerability lifecycle on their side too.

    The security team now also owns agents as a new class of identity and insider risk, including whether anyone can stop one, which is what the kill switch test measured.

  5. Era 5 · Next 5 years

    2026 to 2031

    3.9

    My bet: the tier-1 queue disappears into agents within five years, and the SOC becomes detection engineers, threat hunters, and responders who supervise agent verdicts and approve containment. Small companies get a SOC through agents and MDR rather than hiring one. The new failure mode is an attacker who targets the agent itself.

Which cybersecurity operations software is being rewired?

  • 2.9
    SIEM and SOC Platforms

    SIEM and SOC platforms are moving from log correlation that humans triage to AI agents that triage and investigate alerts themselves. ArcSight and QRadar collected events. Splunk Cloud and Sentinel moved them to the cloud. Today agents from Microsoft, CrowdStrike, Google and Torq close false positives on their own, while analysts still approve containment.

  • 3.2
    Email Security

    Email security moved from hand-tuned spam filters and on-prem gateways to cloud gateways, then to API-based behavioral AI that reads relationships instead of signatures. Since 2024, agents from Microsoft, Sublime and Abnormal triage user-reported phishing and remediate whole campaigns, while analysts approve the consequential calls. Next comes verifiable sender identity.

  • 1.8
    Firewall and Network Security

    Firewall and network security moved from hand-edited rule bases on Check Point and Cisco boxes, to next-generation firewalls and cloud-delivered SASE, to AI copilots that explain policy. In 2026, agents from Palo Alto Networks, Check Point, Fortinet, Zscaler and Cato troubleshoot, tighten rules and patch virtually, while humans still approve high-impact changes.

Coming next

  • Endpoint security (EDR/XDR)wave 2
  • Vulnerability and exposure managementwave 2
  • SOAR
  • SASE and ZTNA
  • Network detection and response (NDR)
  • Penetration testing
  • Threat intelligence
  • Cloud security (CNAPP)
  • Application security (SAST and SCA)
  • DLP and DSPM
  • Security awareness training
  • AI and LLM security

Also wired into this category: Coding Assistants and IDEs, SOC 2 and Compliance Automation, Help Desk and Ticketing, Identity and Access Management (IAM and CIAM), Incident Management and On-Call.