Strike48: How agentic AI is reducing decision variability across security operations

STRIKE48

According to Tim Leehealey, Vice President of Corporate Strategy and Operations at Strike48, agentic AI is starting to show its value in security operations in a place that most teams don’t measure directly. It’s not in how quickly alerts are processed, and it’s not in how many detections are generated.

It shows up in how consistently similar situations are handled, particularly when different analysts are working across different environments. That’s where most SOCs begin to drift as they scale. Most teams are aware of it, but it’s rarely something that shows up in reporting.

If you look at performance metrics, speed still tends to dominate. Alerts are triaged, investigated, and responded to within expected timeframes, and from the outside, the operation looks stable. What those metrics don’t always capture is how much variation sits underneath that surface. In practice, two alerts that look almost identical can still be handled differently. One might be escalated sooner, another investigated in more depth, or handled with a slightly different level of confidence depending on who is reviewing it. None of that is necessarily wrong, but it does mean that outcomes are not always as aligned as they appear. That variation doesn’t come from process gaps. It comes from interpretation.

Even with strong playbooks in place, the part of the workflow where analysts are making decisions isn’t fully defined. Context needs to be understood, signals need to be weighed, and the situation has to be mapped against what’s been seen before. That’s where experience comes into play, and it’s also where consistency becomes harder to maintain over time. As volume increases, so does the number of those decision points.

You start to see patterns emerge. Certain analysts become the ones who handle more ambiguous situations. Some alerts are double-checked more often than others. Decisions that look similar on the surface begin to diverge slightly depending on who is involved. Over time, that creates a level of variability that’s difficult to control through process alone. This is where agentic AI starts to change how that layer operates.

Instead of leaving interpretation entirely to the analyst, agentic systems build structure into how context is assembled and presented. As alerts move through triage, the system is already correlating signals, pulling in relevant history, and shaping the information in a consistent way before the analyst steps in. That creates a more aligned starting point.

Without that alignment, consistency tends to depend on informal calibration between analysts. Teams develop a shared sense of what “good” looks like, but it’s not always applied in exactly the same way. Over time, those small differences accumulate, particularly in environments where volume and variation are both increasing.

Without that, consistency tends to rely on informal patterns. Teams know which analysts to trust with certain types of alerts, and over time those patterns become embedded in how work is distributed. It works, but it doesn’t scale cleanly, and it introduces dependencies that are difficult to manage as environments grow. Aligning the starting point of each decision reduces that reliance and makes consistency something that can be maintained more deliberately.

Analysts are still making decisions, but they’re doing so from a position where the key signals have already been surfaced and structured in a similar way each time. The effort required to interpret the alert is reduced, and the likelihood of similar situations being handled very differently begins to decrease. Over time, that has a noticeable effect on how the SOC behaves. Decisions begin to follow more consistent patterns, not because the process has become rigid, but because the inputs to those decisions are more aligned. The need to revalidate or escalate simply to confirm interpretation reduces, and the overall flow becomes more stable, even as the volume of alerts increases.

As Keven Knight, CEO of Talion Cyber Security, describes: “Variability in decision-making is one of the more difficult issues to address because it rarely presents as a failure. Individual decisions may appear reasonable in isolation, but over time, divergence introduces uncertainty into how risk is being handled. At an executive level, that uncertainty becomes problematic, particularly when organisations need to demonstrate that control is being exercised consistently across different environments. Reducing that variability is not about constraining judgement, but about ensuring that judgement is applied within a framework that produces outcomes the organisation can stand behind.”

For MSSPs, this becomes more than an operational detail. Clients expect not just a fast response, but a reliable one. Similar situations should be handled with the same level of care and judgement, regardless of which analyst is responding or which environment the alert appears in. Maintaining that level of consistency across multiple clients is one of the harder aspects of scaling the model. By supporting the decision layer directly, agentic AI allows that consistency to be built into the workflow itself.

Instead of relying on individual experience as the primary mechanism for alignment, the workflow begins to carry more of that weight. Context is assembled more consistently, signals are interpreted in a more structured way, and decisions are made from a more uniform foundation. That doesn’t remove flexibility, but it reduces unnecessary variation and that’s where a lot of the friction in security operations tends to sit.

Speed will always matter, but it’s no longer the part of the system that defines performance on its own. As SOCs continue to scale, the ability to make consistent, well-supported decisions across a wide range of scenarios is becoming just as important. Agentic AI is starting to address that directly, by shaping the part of the workflow where those decisions are made. And in most SOCs, that is the part of the process where consistency has historically been the hardest to maintain.

For more cybersecurity news, click here

Share this

Related News

As we welcome new Vendor Member OpenEye, VP of…

News

VPS Group provides customised solutions for their customer’s temporary…

News

Anekanta AI has published a new blog on its…

News

Scroll to Top