Karthik Kannan is Founder and CEO of Anvilogic.
Every security leader I meet is fielding the same board question: What’s our AI strategy for the SOC? In most cases, the honest answer is a pilot here, a copilot there—AI sprinkled onto processes that were never designed for it.
That instinct is understandable—and may even deliver some early efficiency wins. But it’s also the fastest path to disappointment.
You don’t just deploy AI into the SOC, nor turn loose agents inside it. An AI agent bolted onto a broken workflow doesn’t fix it; it compounds the problem, noise and all.
For AI and Agentic SecOps to work, AI agents must first understand the work itself: the domain, the personas who perform it, their daily tasks and where those tasks intersect.
That understanding doesn’t come for free. It must be architected.
The Problem Not Technology, But Silos
Ask any CISO about the relationship between their detection team and their response team. You’ll hear the same story. There’s tension.
Productive tension between the two sharpens both sides. But too often it turns corrosive—each team siloed, unaware of how the other works.
It plays out predictably. Detection produces alerts with coverage in mind: these are the threats we can’t afford to miss. Response sees noise. They push back: your detections are too loud. Detection answers: tune everything down and you’ll miss the signal.
Both sides are right. Neither can resolve it alone.
The real constraint is scale. Responders complain about noise because the volume exceeds what any human team can handle. Detection engineers resist tuning because they can’t risk flying blind. Different applications. Different operational languages. No bandwidth to reconcile competing priorities.
So the tension remains—not productive, just unresolved. This is exactly the environment Agentic SecOps is being asked to operate in, before the foundation is ready for it.
Your Biggest Security Blind Spot, Data You Already Have
There’s a second silo problem, and it lives in the data layer.
Security-relevant data sits everywhere—logs, endpoints, identity systems, cloud, SaaS. For cost and scale reasons, teams onboard a slice and build detections on it. The rest gets left out, knowingly or not. That’s dark data: the blind spot you don’t know you have.
Every excluded source is a bet that nothing important is happening there. Some bets lose.
Early SIEMs proved it: ingest everything, see nothing. Agentic SecOps risks the same trap: more agents, same broken foundation.
The result is a SOC simultaneously drowning in alerts from the data it has and blind to threats in the data it doesn’t. The worst of both worlds. No Agentic SecOps strategy survives contact with that reality without the right architecture underneath it.
AI agents don’t work faster. They work differently.
The Gap Not Speed, But Structure
That’s what Agentic SecOps delivers—not a smarter copilot, but a fundamentally different operating model.
AI agents work around the clock, faster than any human team, without fatigue. Alert volume that buries a response team isn’t a burden for a system built to triage continuously. Noise ceases to be a problem when it no longer consumes scarce human attention.
More importantly, AI agents communicate across silos in ways humans can’t—same language, no boundaries. Detection and response agents compare notes continuously, across tools, formats and teams. Noisy detections get refined. Unaddressed alerts get escalated. Productive tension takes hold. Corrosive tension disappears.
The same logic applies to data. AI agents can interrogate it where it lives—no upfront onboarding, no centralization required. Normalization happens on demand, not as an advance tax. The SOC finally sees all its data, not just the slice it could afford to bring in.
Intelligence Without Context, Just Noise
None of this happens by pointing an LLM at an alert queue. Raw intelligence without context produces outputs that are confident, fast and wrong. Local knowledge isn’t optional. Without it, triage and investigation stay half-baked.
The fix isn’t another tool. It’s a foundation. We call it an Enterprise Security Graph, and it’s built on four elements:
1. A model of the environment: what assets exist, where they live, what normal looks like.
2. A map of domain ontologies: what a detection is, what an alert means and how entities, threats and coverage relate.
3. A model of workflows and personas: the daily tasks of detection engineers, responders and threat hunters, and where those tasks collide.
4. An accumulation of local knowledge: the best practices and past decisions of this specific SOC, learned over time.
Together, these four elements dissolve the silo problem. Shared ontologies bridge detection and response. Workflow knowledge crosses organizational boundaries. And local knowledge gets preserved—instead of walking out the door every time an analyst does.
Stop Adding Agents, Start Building Foundation
The question isn’t where to add AI agents. It’s whether your systems give them the foundation to actually work.
Before deploying at scale, ask harder questions: Are our workflows instrumented for machine reasoning, or only for human execution? Is our domain knowledge encoded somewhere an agent can access? Are we measuring success by deployment volume or by outcomes?
Teams that answer those questions well will discover that AI agents don’t just reduce toil—they dissolve the silos that have defined security operations for a decade. Faster detection. Higher-fidelity triage. Investigations that scale without adding headcount.
Agentic SecOps won’t be defined by how many agents a SOC deploys. It will be defined by how deeply those agents understand the work.
That understanding is the architecture. And the architecture is the advantage.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

