Lessons From the Agentic Frontier: How the SOC is Winning in the AI Era
John Morgan (Senior Vice President and General Manager · Splunk Security), Fred Frey
RSAC 2026 Conference · Main Stage Keynote
Overview
The modern Security Operations Center (SOC) faces an unprecedented challenge: an overwhelming volume, sophistication, and speed of cyberattacks that consistently push human analysts to their limits, leading to burnout and missed threats. In this critical talk from RSA Conference, John Morgan and Fred Frey of Splunk Security introduce the concept of the agentic SOC, a paradigm shift where artificial intelligence (AI) agents collaborate with human analysts to automate responses, enhance investigations, and proactively prevent incidents. This vision, while promising, also acknowledges a significant paradox: the very agents designed to fortify security can simultaneously represent the biggest insider threat due to their non-deterministic nature and potential for catastrophic errors at machine speed.
Key moments
- 0:00 Introduction to Agentic SOC, its promise, and insider threat challenge.
- 2:00 Understanding and embracing the power of non-determinism.
- 4:10 Rationalizing AI agent threats: essential yet dangerous.
- 6:20 The essential opportunity: automating SOC to combat threats.
- 6:50 Core components and architecture of an effective Agentic SOC.
- 8:10 Introducing the critical Agentic Trust and Governance Model.
Lessons From the Agentic Frontier: How the SOC is Winning in the AI Era
Speakers: John Morgan, Senior Vice President and General Manager, Splunk Security; Fred Frey, Colleague with 25 years of cybersecurity experience
Conference: RSA Conference
YouTube: https://www.youtube.com/watch?v=iz7CSvrvFys
Overview
The modern Security Operations Center (SOC) faces an unprecedented challenge: an overwhelming volume, sophistication, and speed of cyberattacks that consistently push human analysts to their limits, leading to burnout and missed threats. In this critical talk from RSA Conference, John Morgan and Fred Frey of Splunk Security introduce the concept of the agentic SOC, a paradigm shift where artificial intelligence (AI) agents collaborate with human analysts to automate responses, enhance investigations, and proactively prevent incidents. This vision, while promising, also acknowledges a significant paradox: the very agents designed to fortify security can simultaneously represent the biggest insider threat due to their non-deterministic nature and potential for catastrophic errors at machine speed.
The speakers delve into the core tension between the immense power of non-deterministic AI and the security community's inherent need for control and predictability. They argue that just as natural phenomena and advanced technologies like quantum computing harness unpredictability for groundbreaking results, so too can AI agents unlock capabilities previously unimaginable in cybersecurity. However, this requires the development of a robust agentic trust and governance model—a critical, yet currently undefined, framework to mitigate the inherent risks of autonomous agents. The talk outlines key components of this model and provides compelling practical examples of how agents can transform reactive SOCs into proactive, highly efficient security powerhouses, ultimately empowering human analysts rather than replacing them.
This discussion is particularly timely given the rapid acceleration of AI adoption and the emergence of tools like OpenClaw, which democratize agent development. The speakers emphasize that the new battleground for cybersecurity is AI itself, necessitating an urgent embrace of agentic capabilities while simultaneously establishing stringent controls. By addressing the dual nature of AI as both an essential tool and a potential threat, the "Agentic Frontier" talk provides a pragmatic roadmap for security leaders to harness AI's transformative power, ensuring that SOCs can not only keep pace with evolving threats but also get ahead of them.
Background
▶ Watch: Introduction to Agentic SOC, its promise, and insider threat challenge. (0:00)
For years, the cybersecurity industry has grappled with the ever-escalating sophistication and volume of threats. Security Operation Centers, often considered the last line of defense, are under immense pressure. Analysts are frequently overwhelmed, leading to burnout and a reactive posture where they are constantly playing catch-up. Despite continuous modernization efforts, the fundamental challenge remains: human speed and capacity simply cannot match the machine speed of modern attacks.
The advent of artificial intelligence, particularly large language models (LLMs) and autonomous agents, presents both a revolutionary opportunity and a profound dilemma. On one hand, AI offers the potential to automate repetitive tasks, correlate vast amounts of data, and provide insights at a scale impossible for humans. This capability is seen as an "obligation" to stop analyst burnout and prevent threats from penetrating deeper into an organization's defenses. On the other hand, the very agents designed to help are also identified as a significant "insider threat." This threat stems from two primary characteristics: their potential for expressing malicious intent or making catastrophic mistakes, and their inherent non-determinism.
Non-determinism, defined as producing different outputs even with the same input, directly clashes with the engineering mindset that prioritizes formulaic, predictable, and controlled systems. John Morgan rationalizes this by drawing parallels from nature and science. He cites the discovery of penicillin by Alexander Fleming, a serendipitous event born from uncontrolled circumstances, as an example of how non-deterministic events can lead to profound innovation. Similarly, quantum computing harnesses the non-deterministic states of qubits to achieve unprecedented computational power. Morgan argues that just as nature has always leveraged unpredictability, humanity is now at the brink of harnessing digital non-determinism to achieve outcomes and discover solutions that could never have been predicted or planned. The core idea is that a non-deterministic system might find a "better way" or a "better outcome" than a predetermined path.
Furthermore, Morgan addresses the threat posed by agents by comparing them to essential elements of life, such as air. Air is vital for existence, yet under certain conditions (like rapid ascent during scuba diving or fueling a fire), it becomes life-threatening. Similarly, AI is rapidly becoming essential for organizational competition and automation, but its inherent risks—lack of a "social contract," absence of empathy or reputation concerns—mandate the creation of robust constructs and processes to mitigate these threats. This foundational understanding sets the stage for the proposed agentic SOC, where the power of AI is harnessed but critically controlled.
Key Findings
▶ Watch: Rationalizing AI agent threats: essential yet dangerous. (4:10)
The talk presents several key findings and propositions regarding the integration of AI agents into security operations:
- The Agentic SOC as an Imperative: To combat the overwhelming volume and sophistication of modern cyberattacks and to alleviate analyst burnout, organizations have "no choice" but to automate more aggressively within their SOCs. The agentic SOC represents this necessary evolution, where humans act as orchestrators, collaborating with AI agents that make recommendations and, in some cases, take autonomous actions.
- Harnessing Non-Determinism for Innovation: While AI's non-deterministic nature is a source of discomfort and risk, it is also a powerful engine for innovation. By embracing and controlling this unpredictability, SOCs can achieve capabilities and discover threats that would be impossible with purely deterministic systems.
- Critical Need for Agentic Trust and Governance: The most significant contribution of the talk is the identification of a gaping hole in current security frameworks: the lack of a standard agentic trust and governance model. This model is presented as the essential ingredient for safely deploying autonomous agents, designed specifically to mitigate the unique risks of non-determinism and agent behavior. Without it, widespread adoption of agents is fraught with peril.
- Transformation from Reactive to Proactive: An effectively implemented agentic SOC allows security teams to transition from a constant reactive state to a proactive and preventative one, operating at both speed and scale. This shift is enabled by agents that can predict and block issues before they escalate into full-blown incidents.
- Empowerment, Not Replacement, of Analysts: The goal of the agentic SOC is not to replace human analysts but to empower them. Junior analysts can gain the "power and history of thousands of investigations" and the "small army of subject matter experts" through agent assistance, elevating their capabilities and confidence.
- The Superpower of Memory and Learned Behavior: A critical advantage of AI agents in the SOC is their ability to "consume, retain, and recall massive amounts of data" and, crucially, to learn from past investigations and human operator actions. This "tribal knowledge" makes every subsequent investigation better and allows agents to identify subtle TTPs (Tactics, Techniques, and Procedures) that even senior analysts might miss.
- Customized Agents are Paramount: Out-of-the-box agents are insufficient. For true efficacy and trust, agents must be customized to understand an organization's specific business practices, data structures, query patterns, and investigative workflows. This customization is key to building trust as agents learn the complexities of an environment.
- Gradual Automation: Humans in the Loop to Out of the Loop: The journey to an autonomous agentic SOC requires a phased approach. Initially, humans must remain "in the loop" to build trust and validate agent actions. However, to achieve necessary scale, SOCs must "quickly move and graduate towards these systems, towards humans out of the loop."
- The Expanding AI Battleground: The rapid proliferation of agent-building tools, such as OpenClaw, signifies an "unprecedented explosion of agents." This widespread adoption means that AI is the "new battleground" for hackers, demanding an equally rapid and robust response from defenders.
Technical Deep Dive
▶ Watch: The essential opportunity: automating SOC to combat threats. (6:20)
The architecture of an agentic SOC is envisioned as a sophisticated ecosystem designed to integrate human expertise with AI capabilities seamlessly. It comprises several critical components:
- Open Distributed Data Platform: This serves as the foundation, centered around various security tooling and analytics platforms. It's designed to ingest and process massive amounts of data from diverse sources.
- Collaboration Platform: This is the interface where humans and agents interact. Humans maintain control, while agents provide recommendations and, increasingly, take autonomous actions.
- Large Data Management Plane: Essential for managing the immense scale of data generated by agents and the overall environment, ensuring comprehensive visibility.
- Purpose-Built Agents: These are specialized agents designed to access federated data, machine data, and other forms of information, ingesting them into the platform.
- Security Controls: The traditional security controls (network, Cloud, Email, identity, endpoint, etc.) remain vital, providing the protective layers within the environment.
- Tight Integration for Automatic Responses: This ensures that agents can trigger automated responses across integrated security tools when threats are detected or prevented.
The most crucial and novel component, however, is the agentic trust and governance model. This model is designed to directly address the unique risks associated with non-deterministic AI agents, for which no industry standard currently exists. Key elements of this proposed stack include:
- Identity as a Control Plane: Beyond traditional identity management, this model mandates robust identity controls at runtime for agents. The speaker suggests that current Zero Trust implementations might appear "soft" in comparison to the rigorous runtime identity checks required for agents.
- Separation of Duty (at Build Time): A fundamental security principle, separation of duty, is applied to agent design. Instead of a single agent performing an entire complex task, a job is broken down into multiple sub-jobs, each assigned to a different agent. This "need-to-know" mentality not only enhances security by limiting the scope of any single agent's potential misuse but also helps manage context windows and memory more efficiently for LLMs.
- Output Validation: Given AI's non-deterministic nature and the potential for hallucinations or slight deviations ("5 or 10 degrees off"), rigorous output validation is paramount. This must occur at machine speed and scale, focusing on verifying the agent's "intention" behind its output.
- Data Security and Governance: As organizations move towards automated business decisions directly from data, the integrity and security of this data become paramount. The concept of "data as code" is introduced, implying that data needs to be managed, audited, and version-controlled with the same rigor as source code. Auditing who accessed or modified data at what time becomes critical.
- Agentic Detection and Response: This involves leveraging AI, including LLMs and potentially MCP servers, to detect threats within the agentic environment itself. The entire agent ecosystem—workflows, processes, the agents themselves, and new components—constitutes an expanded attack surface that requires continuous monitoring and rapid response capabilities. The speaker highlights the need for this to happen at "much more speed and scale, and probably right now."
- Compliance: The rise of AI introduces new compliance challenges and complicates existing ones.
- New Compliance: Areas like bias and transparency (e.g., "how did your agents come to a particular conclusion?") require novel approaches to auditing and explanation.
- Existing Compliance: Regulations like GDPR with its "right to forget" become significantly more complex. Data can exist in multiple transformations (e.g., in an LLM transform, a vector database, a context window, or a KB cache). Ensuring that data is completely wiped from all these distributed and transformed locations within an agentic infrastructure poses a substantial challenge.
- Other Elements: The talk briefly mentions other emerging considerations for agentic governance, such as sovereignty and tokenomics, indicating the breadth of the challenges the industry is currently attempting to address.
Demo / Proof of Concept
▶ Watch: Core components and architecture of an effective Agentic SOC. (6:50)
Fred Frey illustrates the practical application and transformative power of the agentic SOC through two compelling examples, showcasing both reactive and proactive capabilities.
Example 1: Reactive Incident Response – The Impossible Traveler Alert
- The Scenario: At 3:00 AM, a junior analyst named Samir receives an "impossible traveler" alert. An employee logged in from New York 20 minutes ago, but now the same credentials are used from a different IP address and device fingerprint in Eastern Europe. Traditionally, Samir would face hours of manual correlation across "12 tabs open across five different products," trying to piece together IP addresses, threat intelligence, and pattern of life data—a high-stakes task where mistakes are costly.
- The Agentic SOC Solution: In an agentic SOC, Samir transitions from an "operator" to an "orchestrator." Before he even reviews the ticket, a "small army of subject matter experts" (AI agents) has already performed the initial triage:
- An agent provides a full authentication timeline and 30-day pattern of life for the user.
- An enrichment agent checks the Eastern European IP against Tor exit nodes, VPNs, and threat intelligence feeds.
- A correlation and hunt agent simultaneously fans out to analyze recent Email logs, endpoint telemetry, and network proxy events to identify any post-breach activity or assess the potential blast radius.
- The Outcome: What used to take hours now takes seconds. Samir is presented with a dashboard offering full context, allowing him to make a confident decision without writing a single query.
- The "Memory" Superpower: Crucially, during this investigation, the correlation agent flags something Samir (and potentially even a Tier 3 analyst) would have missed. It researches a threat hunt previously conducted by a senior analyst months ago, identifies similar TTPs (stolen credentials), and recalls that the senior analyst had added an Email filter via API based on those TTPs. The agent then applies this learned "tribal knowledge" to the current incident, kicking off a hunt that identifies the same activities. This demonstrates how every investigation in an agentic SOC automatically improves the system and every analyst's capabilities.
Example 2: Proactive Incident Prevention – Data Leakage
- The Scenario: A retail company generates a weekly sales report posted to an S3 bucket, used by the CFO, customer service, and a third-party analytics partner. Initially, the S3 bucket is meticulously cleaned of PII (Personally Identifiable Information), ensuring compliance. Months later, "drift happens." The customer support team identifies a legitimate business need to include customer Email and home addresses in the report for proactive campaigns. Developers implement this change. The problem arises because this seemingly innocuous change now unintentionally sends PII data to the third-party vendor, violating data policies and potentially leading to fines or reputational damage. These types of misconfigurations can lay dormant for months or years.
- The Agentic SOC Solution: With a preventative AI agent in the loop, this scenario is entirely averted. This agent operates before the code merge occurs:
- It understands the proposed code change.
- It comprehends the organization's infrastructure (because it's defined as infrastructure as code).
- It traces the data flow to the S3 bucket and identifies who it's shared with.
- It understands the company's data policies and PII classifications.
- The Outcome: The agent integrates all this information, recognizes that the merge will cause a policy conflict and data leakage, and proactively blocks the merge before it can become an incident. This showcases the agent's ability to prevent issues by understanding intent and context across complex systems.
These examples vividly demonstrate how agents can significantly enhance both reactive response capabilities and, more importantly, enable a truly proactive security posture by leveraging contextual understanding, learned behavior, and predictive analysis.
Defensive Implications
▶ Watch: Introducing the critical Agentic Trust and Governance Model. (8:10)
The rise of the agentic SOC carries profound implications for defensive strategies, demanding a proactive and structured approach to integrating AI while mitigating its inherent risks. Defenders must recognize that AI agents are not merely tools but powerful, non-deterministic entities that require a new level of governance and control.
Firstly, organizations must embrace AI agents as an essential component of their security operations, acknowledging that human capabilities alone cannot keep pace with the evolving threat landscape. The goal is empowerment and scale, not replacement. This means investing in AI technologies, developing internal expertise, and fostering a culture of human-agent collaboration.
Secondly, the most critical defensive implication is the urgent need to design and implement an Agentic Trust and Governance Model. Since no industry standard exists, organizations must actively contribute to defining and adopting best practices. Key areas of focus for this model include:
- Rethinking Identity and Access Management: Traditional Zero Trust principles must be extended and hardened for agents, focusing on rigorous runtime identity as a control plane. Every agent's access and actions must be continuously authenticated and authorized based on its specific, minimal required permissions.
- Implementing Separation of Duty for Agents: At the design and build phase, break down complex tasks into smaller, distinct functions, assigning each to a separate agent. This "need-to-know" principle for agents limits the blast radius of a compromised or malfunctioning agent and enhances overall system resilience.
- Developing Robust Output Validation Mechanisms: Given the non-deterministic nature of AI, defenders must implement advanced systems to validate agent outputs at machine speed. This includes not only checking for data leakage or errors but also assessing the "intention" behind an agent's conclusion to detect hallucinations or subtle deviations from expected behavior.
- Adopting "Data as Code" Principles for Data Governance: Treat all data, especially data processed or transformed by agents, with the same rigor as source code. Implement version control, audit trails, and strict integrity checks to monitor who accessed or modified data and when. This is crucial for maintaining data integrity and accountability in an AI-driven environment.
- Adapting Compliance Strategies for AI: Defenders must proactively address the new compliance challenges introduced by AI, such as bias and transparency. Furthermore, existing regulations like GDPR's "right to forget" require entirely new approaches to ensure data erasure across all AI-related data transformations (LLM caches, vector databases, context windows, etc.). This necessitates a comprehensive understanding of how data flows and resides within agentic infrastructure.
- Expanding the Attack Surface View: Recognize that the entire agentic ecosystem—including LLMs, MCP servers, agent workflows, and the agents themselves—constitutes an expanded attack surface. Implement continuous detection and response capabilities specifically tailored to monitor and secure these new components.
- Prioritizing Customized, Learning Agents: Generic, out-of-the-box agents will have limited efficacy. Defenders should focus on developing or acquiring agents that can be customized to understand their organization's unique business processes, data structures, and threat intelligence. These agents should be designed to learn from human analysts, building a "memory" of past investigations and TTPs to enhance future performance.
- Phased Automation with Human Oversight: Begin with a "humans in the loop" approach to build trust and validate agent actions. Gradually, as agents demonstrate reliability and efficacy, transition to "humans out of the loop" for specific, high-volume tasks that require machine-speed execution. This iterative approach allows for controlled scaling of automation.
The rapid proliferation of agent-building tools like OpenClaw means that the AI battleground is already here. Defenders cannot afford to wait; they must proactively integrate AI agents into their SOCs while simultaneously building the rigorous trust and governance frameworks necessary to control this powerful, yet potentially perilous, new frontier.
Key Takeaways
- AI Agents are Essential for Modern SOCs: Overwhelmed human analysts and machine-speed threats necessitate the adoption of AI agents to automate, scale, and prevent burnout, moving SOCs from reactive to proactive.
- Non-Determinism is a Double-Edged Sword: While AI's unpredictable nature is a source of powerful innovation, it also presents significant risks, demanding a robust agentic trust and governance model to ensure control and safety.
- New Governance Principles are Critical: Key elements of this nascent governance model include separation of duty for agent design, stringent output validation to counter hallucinations, and treating data as code for integrity and auditing.
- Agents Empower Analysts and Leverage Organizational Memory: Agentic SOCs can elevate junior analysts, accelerate investigations from hours to seconds, and harness "tribal knowledge" by learning from past incidents and human expertise to identify subtle TTPs and prevent future attacks.
- Customization and Trust are Foundational: Out-of-the-box agents are insufficient; successful deployment requires agents customized to an organization's specific business practices, data, and workflows, with a phased approach that builds trust from "humans in the loop" to "humans out of the loop."
- The AI Battleground Demands Urgent Action: With the rapid proliferation of agent-building tools like OpenClaw, AI is the new frontier for cyberattacks, necessitating immediate and comprehensive defensive strategies and governance frameworks.
About the Speaker(s)
John Morgan is the Senior Vice President and General Manager of Splunk Security. In this role, he leads Splunk's efforts in security operations, bringing extensive experience to the challenge of modernizing SOCs with advanced technologies like AI. His insights in this talk reflect a deep understanding of the industry's need to balance innovation with security, particularly concerning the non-deterministic nature of AI.
Fred Frey is a colleague of John Morgan and contributes 25 years of cybersecurity experience to the discussion. His practical examples and real-world scenarios in the talk underscore his extensive background in the field, providing tangible demonstrations of how agentic AI can be applied effectively within a security operations context.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A Splunk SVP and colleague deliver a polished but ultimately hollow vendor keynote dressed up as forward-looking research. The 'agentic SOC' framing is genuinely timely, and there are flickers of real substance around governance and trust models, but the talk never escapes its gravitational pull toward Splunk marketing. The demos are illustrative cartoons, not technical proof-of-concepts. The governance framework they call groundbreaking is a restatement of principles security engineers have applied to SOAR platforms for a decade. This is RSA Conference content — which is to say, it's exactly what you'd expect from RSA Conference, and that's not a compliment.
Heather Calloway (CISO) — SOLID
Morgan and Frey make a credible case that the agentic SOC is coming and that governance frameworks for AI agents don't yet exist — a real and important gap. The demos are well-constructed and the concept of an agentic trust and governance model is genuinely useful framing. But this is a Splunk talk, and it reads like one. The governance framing is introduced and then left mostly empty. The business risk case is asserted rather than evidenced. And the talk never quite crosses over into the territory where a CISO leaves knowing what to actually do differently next quarter.