For two years the industry sold copilots: assistants that answer questions about an alert. Useful, but the analyst still did the work. The real leap is the agent, software that executes a complete task with a goal, tools and a log of every step.
What to automate first
The rule we use: automate what is repetitive, verifiable and reversible. Volume triage meets all three. Containment that interrupts the business meets none, which is why it stays human.
WHERE OUR SIX AGENTS OPERATE
- Alert classification and enrichment, repetitive, verifiable against the log.
- Reconnaissance in offensive exercises, accelerates; the pentester decides and exploits.
- Detection hypothesis generation, measured against 90 days of history before deploying.
- Report drafting, the draft is the agent’s, the signature is the analyst’s.
The question is not how much we automate. It’s which decisions we keep reserving for a person with a name.
How to measure without fooling yourself
Vanity metrics abound: “alerts processed by AI”, “hours saved”. Three matter: how many real cases survived the filter (ours: all, audited monthly), time from critical alert to first action (under 15 minutes) and how many business decisions a machine took alone (zero).
If your security provider can’t show you the reasoning log of their automations, you’re not buying AI, you’re buying a black box with marketing on top.