Strike48: Why the future of security operations is defined by execution, not detection

STRIKE48

In this exclusive piece, Tim Leehealey, Vice President of Corporate Strategy and Operations at Strike48, discusses how agentic AI tools can be used to help analysts working in Security Operations Centres (SOCs) and to enhance efficiency of SOCs. A major bottleneck of threat detection and analysis has been humans themselves: there’s only so much a single analyst can do before being overwhelmed. Traditional SOCs do not scale easily, and this becomes a problem as companies grow and the amount of data and monitoring available to analysts increases.

Agentic AI is starting to reshape security operations in a way that doesn’t immediately show up in detection metrics, but becomes obvious when you look at how work actually gets done inside a SOC. It’s not about seeing more. In most environments, that problem has already been addressed to a reasonable extent. Alerts are generated, enriched, and prioritised with enough accuracy to signal that something needs attention. The gap is not in identifying potential issues, it’s in how consistently and effectively those issues are acted on once they enter the workflow. That’s where execution starts to matter more than detection.

If you follow an alert through a typical SOC, the early stages are relatively structured. Data is collected, signals are correlated, and initial context is applied. After that, the process becomes less defined. The analyst has to interpret what they’re looking at, decide how relevant it is, and determine what action should follow. That part of the workflow doesn’t always move cleanly, particularly when the situation doesn’t match something that’s been seen before. Most teams recognise this, even if it isn’t always described directly.

You can see it in how work slows down in certain situations, or how decisions are escalated simply to confirm interpretation rather than because the alert itself requires it. The process is there, but it relies on judgement to carry it through the final stages. That’s where variation tends to sit, and it’s also where performance starts to diverge. Agentic AI is beginning to change how that layer operates.

Instead of leaving execution entirely dependent on how each analyst interprets the situation, agentic systems introduce structure into how decisions are formed and applied. As alerts move through the workflow, the system is already assembling context, correlating relevant signals, and shaping a clearer picture of what is actually happening before the analyst steps in.

That changes where execution begins. Rather than starting from interpretation, analysts are starting from a position where the key context has already been structured in a consistent way. The decision still requires judgement, but the path to that decision is clearer, and less dependent on reconstructing the situation manually. In practice, that has a noticeable effect on how the SOC performs under pressure.

Analysts spend less time working out what they’re looking at and more time deciding what to do about it. Situations that would normally require additional validation begin to move more smoothly, not because they are simpler, but because the information needed to act is already in place.

“Execution is where risk is ultimately realised or mitigated, and it is also where inconsistencies tend to emerge as complexity increases. From a governance standpoint, the challenge is ensuring that decisions taken at the point of execution align with the organisation’s broader understanding of risk. That becomes more difficult as environments scale and variation increases. Supporting execution in a way that maintains that alignment is what allows organisations to operate with confidence, rather than simply reacting to what has already been identified,” explains Keven Knight, CEO of Talion Cyber Security.

That distinction becomes more important as environments grow. Detection can scale with data, but execution doesn’t scale in the same way. The more alerts you introduce, the more decisions need to be made, and the more pressure is placed on how consistently those decisions are applied. Without additional support, that tends to result in more escalation, more revalidation, and more reliance on individual experience to maintain quality. Agentic AI shifts that dynamic by supporting execution directly.

It doesn’t replace the analyst, but it changes how the analyst interacts with the workflow. Context is assembled earlier, decisions are guided by a more structured view of the situation, and the effort required to move from signal to action becomes more consistent across the team. Over time, that begins to change how performance is defined.

It becomes less about how quickly alerts can be processed, and more about how reliably the SOC can move from detection to action without introducing unnecessary variation. Execution stops being the part of the process that depends most heavily on individual effort, and becomes something that is supported as part of the system itself. For MSSPs, that shift is particularly significant.

Operating across multiple clients introduces a level of variation that cannot be eliminated through process alone. Each environment brings its own context, and maintaining consistent execution across those environments is one of the harder aspects of scaling the model. By introducing more structure into how decisions are formed and applied, agentic AI allows that consistency to be maintained in a way that holds up under pressure.

Detection still matters, but it is no longer where performance is defined. That is determined by how effectively organisations can execute on what they already know, and how consistently those decisions hold up as complexity increases. Agentic AI doesn’t change the need for that execution, but it does change how well it can be sustained. And in most SOCs, that is where the real work has always been.

For more AI news, click here

Share this

Related News

Octave Intelligence has announced it has been named Frost…

News

Save time, reduce expenses, and optimise operations with OpenEye’s…

News

Zimperium has announced Zimperium Deep Insights, designed to unify…

News

Scroll to Top