The future of SOC in an AI-driven landscape
AI is changing cyber attacks by making reconnaissance, intrusion and adaptation dramatically faster. This session explores what defenders can do to keep pace, from strengthening attack surface management and patching to using automation, AI assisted triage and autonomous response more effectively.
The changing threat landscape
AI is accelerating cyber attacks, from agentic ransomware and AI assisted phishing to attacks targeting exposed AI systems themselves. Attackers can now automate reconnaissance, adapt to failures and execute many actions at machine speed, increasing pressure on organisations that rely on traditional detection and response alone.
How defenders can respond
Security teams need to shift from reacting to incidents towards reducing opportunities before attacks progress. That means continuously managing external exposure, prioritising vulnerabilities based on real attacker access, strengthening endpoint disruption and using AI assisted triage. Good data, business context and pre-authorised responses can help humans and machines work together at speed.
The future of SOC in an AI-driven landscape
AI is changing cyber attacks by making reconnaissance, intrusion and adaptation dramatically faster. This session explores what defenders can do to keep pace, from strengthening attack surface management and patching to using automation, AI assisted triage and autonomous response more effectively.
The changing threat landscape
AI is accelerating cyber attacks, from agentic ransomware and AI assisted phishing to attacks targeting exposed AI systems themselves. Attackers can now automate reconnaissance, adapt to failures and execute many actions at machine speed, increasing pressure on organisations that rely on traditional detection and response alone.
How defenders can respond
Security teams need to shift from reacting to incidents towards reducing opportunities before attacks progress. That means continuously managing external exposure, prioritising vulnerabilities based on real attacker access, strengthening endpoint disruption and using AI assisted triage. Good data, business context and pre-authorised responses can help humans and machines work together at speed.
View transcript
Today we have a very long list of participants for our webinar. What we are talking about is security concepts and platforms that have been here for a decade And we also believe that most participants already have some kind of monitoring on the systems. But the security discipline has changed, and it changed a lot. On our session today, we have three colleagues that have worked in security industry between 12 and 25 years. And like the rest of the industry, we have only a small clue about the changes AI will cause to the security, cyber attacks, and how it will impact the society around us. On the other hand, we are pretty sure on the foundation we can start with. We'll be a bit technical today, but CyberTech Service, our mission is to be concrete. So we hope you can follow us the next 30 minutes. In the first of those minutes, my slide was blank for 26 seconds. That was the time it took attackers to get to initial access from lateral move last year. Is that what we are going to see now or in the future? We don't know, but my colleague, David Clayton, which lead our Threat Intel team, he will start a session just to quick overview on the threat landscape as today. So welcome, David. David Clayton, Cool. Thank you, Lars. I'm going to be presenting a little bit about the most recent trends that we're seeing in the AI threat landscape, especially since February this year. So I brought along four cases or four things that we can actually talk about. And these have been the shifts that we've been seeing since February this year. So again, we focus a lot on the whole AI threat landscape and the changes over the course of the last year. But at least in the last period, we've seen quite a lot of different things happening. So we've seen, number one, we've seen fully agentic ransomware arrive on the scene. So a group called Jade Puffer. This was documented back in July this year. And this was very interesting because the whole attack chain was ran via AI agents. So this is something that, again, we're going to talk about later, what we can do about this. But this was really interesting because, again, we're seeing, we've been seeing agents being used for a while to do various types of initial access and other actions. But this was most interesting because it was fully agentic. And secondly, we've also seen nation state actors take up AI in a very, very wide way. We've seen it being used to do by at least by North Korea for carrying out AI to get hired into different organizations and trick those organizations, so faking, using deep fakes and things like that. We've seen state actors also use AI to do malware development and also to carry out vulnerability research. And there's a number of reasons why this is, and we'll come into that in a second. For number three, AI-assisted intrusion has become far more routine. We've seen it in some of our clients, there's a whole phishing campaigns that have been run completely via AI, at least with the tells you can see that it's been carried out via AI. And also looking at the site that they're landing on, which is also then fully AI developed. So it's actually getting much harder for users to do good user awareness when the campaigns they're seeing are so well built. And finally, for number four, this has also been developing over the last period, which is AI itself became a target. So looking at utilizing exposed LLMs to gain initial access into organizations, so something simple like a chatbot that someone's exposed, using that to then get access to the back end and carry out some initial access techniques that they want to carry out. We've seen prompt injection on a wider scale. We've seen also LLM credential hijacking, but another area that's also very, very prevalent is injecting into skills. And skills are a really interesting case because depending on how you use them, skills can get updated silently by other people who have shared those skills with you, and you don't get any prompt to update the skills. So this is happening quite often. And again, you need to check your skills and see what's happening there. And just to focus on one of those cases, we've seen a, well, it's basically a China-linked actor that actually was able to run 12 separate attack waves spread out across four days. It started out with the automated recon, and we see this often, right? A lot of the initial access, a lot of the reconnaissance in the early stages is now automated. And it seemed like they were very much going after governmental sites, or government portals and other exposed systems there. And from then on to the same day was the first wave of initial access and initial recon looking for, again, the exposed API endpoints that they found in the recon and actually starting to try to authenticate against them. They were also using AI to solve the captures as well. And so that was quite interesting. And then by July 4th, given the level of access that they'd been able to attain earlier, we ended with this, which was basically the 12th wave of attacks, which were a compromise of 85 credentials. And then the inevitable disclosure of 2,500 personal records, secrets, and other credentials that were able to be extracted by this actor over the course of these four days. And what's really interesting about this is obviously that in the AI attack, it's not just single actions in each of those waves. There can be multiples upon multiples upon multiples of commands being executed. And so even though there was a 12th wave, which is also a lot of attacks to carry out across three days, there was also multiples of attacks within those attacks. And then it was disclosed finally on the 12th of August by a research lab that was able to have a look at this. And they were able to find that this actor had targeted many different governmental agencies. So one called the Nuclear Safety Agency, government emails, energy companies, and other IT vendors. So it was a very broad attack that they were running. And then where does this leave us based on what we've just talked about in the AI threat landscape? Well, from a defender's perspective, we are at a time disadvantage because the speed of these attacks has increased massively. We use this term, attackers are working at machine speed, which is what's happening now with AI. The other issue that we've got is that the attackers are able to gain insights on the fly. So what used to happen was they would spend a very long time doing reconnaissance against an organization, either from the outside or once they actually then got in. They would spend a lot of time looking around and seeing where they were and how they were operating or how they could operate. And this would lead to detections because they'd be in for a while and it would get easier to detect them the longer they were in. Whereas now attackers are able to do this all in the same in the same in the same few minutes. And we have the capability is unmatched where I used to have a actor who had to have skills to do these types of activities. Now with an agent framework, you get the ability to be able to carry out far more capable attacks. And you can carry out far more multiples of them as well, because, again, it's just the number of agents you want to fire off. You don't need to hire 10 people to hack into an organization. You can just use agents to do it. And then we have the ever expanding landscape and every different AI system that's being deployed is also a potential target as well, because of the level of access to AI systems generally have into the back end systems, too. And so together, these are all part of the AI exposure and what defenders need to do about it or should do about it or could do about it. And that's it. It's what we're going to talk about in the rest of this talk. Yes. And then we are back here in our seats and we are three old security guys that are going to talk about the new technology. We are open for questions, but please send a question and we will answer not in this session. We have we don't have that much time, but we will answer all the questions after the session. And with me, I have David that is leading our threat intel team. And I also have Vladimir that leads our detection platform and engineering. And let's just start with you, Vladimir. Can you just explain a bit about what is it that that you actually are doing with automation and AI nowadays in a SOC? Yeah, I think we didn't really have to get inspired by AI to actually automate our operations. And way before we started discussing the these challenges, we've been focused on the autonomous response, pre-authorized autonomous response in certain contexts that the clients are comfortable about. And then, of course, recently we started building the AI assisted triage so that our analysts could make better, faster decisions. Besides that, we help analysts with enriching their operational context, understanding of the situation beyond what they see on the alerts and and raised incidents. Yeah. And that's what we're going to come back to. So the question is, you know, how much can such a system actually help with? But but before we do that, I was a bit curious on on the on the threat landscape that you presented, David, because I was wondering with everything that happens here, then who is actually the first one that is able to kind of feel those changes that we see here? I mean, from what we've been seeing, the same organizations that were being targeted yesterday are also still in the crosshairs today. The only thing is that the ability of the actors to be able to convert what we call intent into an actual viable attack by gaining some additional capabilities is speeding up and getting greater. So if you had the intent before that you wanted to target a specific organization and that still existed, but now you can gain the capabilities to be able to carry out that attack. So those organizations were still in the crosshairs. But now even lower level actors are able to convert that that their intent into something that's actually a viable attack and can cause some level of initial access into that organization. And then also other organizations that weren't even necessarily being targeted now via automated scanning. We're seeing a lot more organizations being here because the improvement in the level of reconnaissance is also getting better. And so AI agents and things are learning as they go and able to build really good reconnaissance. And so much more organizations are becoming targeted. So those organizations that are used to being attacked, they still see the attacks. They might have more attacks and more advanced attacks. And then you have the others that are not being faced those more real attacks. They would also start to see attacks because it's easier to carry out in a scale. Exactly. Okay. So there is a change already. There is definitely a change. Yes. And we're also seeing, of course, our clients as well, that there is a change happening. Yeah. Okay. But if you are, let's say, a good, normal, standard company, Vladimir, and you run a good, healthy Microsoft platform with, you know, the best practice configuration, you have a security operations center that monitor alerts and respond to that. Would you then be good now? Maybe, but not for long term. I think it's rather short term. The change in the capabilities of the threat actors essentially dictates us a little bit more, like brings us a little bit more strict requirements and expectations towards the organization on how they prepare. So the detection capabilities themselves become your last resort. You have to prepare much earlier before the attack happens. And essentially knowing what you're actually after, what you're trying to protect becomes even more important these days. Since the attacks are essentially starting with recon, the organizations need to understand better their own exposure to those attacks. They need to do it on a daily basis the same way as the threat actors are doing. So you have to be very much up to date with your external exposure, whether it is information or your identities, your services. And then, of course, the part that everyone is talking about is the vulnerabilities that have been so far being patched on a cycled base now have to be patched more frequently, continuously. So you're saying that in reality, at least short term, then a good detection setup can still last for a bit of time. But everything around it needs to be tightened up because you need to in some way make sure that you address the whole attack surface where the gap might be. Yeah, I would say that the classic concept of defense in depth is actually very much applicable here because we want to disrupt and break that speed down into small, containable actions that the defenders can work with. So the more obstacles we put in front of the attacker, the better our chances are actually to contain and withstand that attack. Okay. But what is it that SOC can do in this case? Yeah. So like the SOC in a traditional way is not just detection response, right? But if we look at the detection, of course, you have to fight speed with speed, right? Meaning that your current detection capabilities, if it's dependent on the ingestion of logs and logs analysis, is already not real time. So you have to shift detection and containment to the closest point of entry, meaning that it has to happen at the end point. Therefore, the attack disruption capabilities that most of the vendors are already offering have to be actively used by the organizations. We understand the concerns of potentially containing perfectly legitimate actions, but that's why you have to also test those. And in many cases, the current technology allows you to actually get quite high confidence in the containment actions being performed. And you can also scope those actions to a narrow scope of high critical assets in the first place, or make sure that you're more aggressive in those scopes where the impact might not be as high, but the consequences because of the breadth and spread of the potential attack could be quite significant. Yeah. Okay. But we have a slide that shows some of the increase in speed in terms of the time attacks from you on the computer and until you are able to move from that computer. In this case, on the screen, we have a slide from a quite recent cross-strike report. And that's where we got 26 seconds as the record last year. But that was the record, but the average is just below half an hour. And as we can see on the slide, that has been decreasing quite a lot. And we also know that this is based on 25 numbers. So, that was even before AI was used as much as now. So, with that speed and the future speed, we will see, do we have a chance for MDR or SOC to keep up with that? Yeah, I think we still have a chance. And the important part, as I said, is that the early detection and disruption helps the defenders and especially the analysts to make perfectly adequate decisions in these time frames. So, I mean, like good security operations teams, good management, manager detection and response teams, they operate within those time frames. Like within 15 minutes, they typically engage with that attacker, let's say, and can actually execute containment. The challenge now is that the speed and progression of those threat actors in the environment is much higher. Therefore, we have to actually automate triage as much as we can so that the analysts do not have to spend time on collecting, collating information, trying to reconstruct the chain of the attack before they make decisions. So, we do automated agentic assisted AI assisted triage and present our analysts with perfectly reasonable progression so that they can make the calls on containment or actions that need to be taken. But it also sounds like it's a very tight process. So, there is less and less time to actually run the process. Just handover between human and machine and human and human is just taking minutes, which is actually very important minutes now. That's very true. So, that's why we always encourage our clients to actually agree on the pre-authorized response, autonomous response, that we could execute against the attacks that have very high confidence of being malicious activities. Besides that, we also want to prevent, again, break the progression through the environment by extending security operations capabilities through the initial phases. So, we want to be sure that the opportunities of the attackers are actually significantly reduced by actively managing attack surface, by making sure that the attack paths are breaking in between so that it's not that easy and not that fast for, even for the machine speed operator to actually execute a perfectly open path for them. So, they still have to discover their path. They still have to execute hundreds, as David mentioned, hundreds of actions before things actually happen to work. The agents, however much they actually develop the precision, they're still not as precise. They have to try and fail, try and fail, and that's where our advantages are. We can see how they fail. The pattern recognition, the rate-based detection becomes very important. Besides that, most of the attacks end up with exploitation of credentials, not just human credentials, but service credentials. So, implementing monitoring and containment of those credentials that have not been pre-authorized, that are outside of the good known state, should be actually implemented and practiced in the operations. But it also sounds like that we still have some, let's say, extra information on our side, because we know the environment. We don't need to kind of trial and error to understand what is the environment. We know that from the beginning. AI needs to map it out in some way. And also, we know the identities and we know what they are supposed to do. So, we know all those patterns that are the usual ones that we're looking for. So, that must be still on our side if we are able to use it, at least. I think it still is for a little bit longer. But I think AI is, the agents are becoming so fast at carrying out these types of things, that advantage that we had of knowing our infrastructure and knowing that the actor had to come in and spend days and days, like, investigating where they were, how they'd get to a domain control, all those things are now getting an injection of steroids and are being speeded up. Yeah. But I think we still have this advantage of knowing our environment and securing our environment up front. The business context matters. Understanding what is the normal function of the organization, what is a normal activity for a particular product or a particular operational process is very important for defenders and specifically for analysts to make proper decisions. But that also means that this setup now is very, very dependent on a very good, stable setup and platform with enough business information, I would assume. I will just move to that. We have another slide. And this one is a slide that is presenting based on qualities. All their clients, they are patching speed. So that is around 10,000 clients globally. And we see those specific vulnerabilities here are those that are CCKV. So they are the ones that are the most important. And even with that, we see that they are, you know, companies are not really patching that fast. And it's within a week, most of those vulnerabilities are still open. You mentioned that it's also all the other things around the SOC that is the detection, which are important. Yeah, security operations teams, specifically with vulnerability management and remediation, have been struggling with these patch cycles for years. And the organizations are very conservative in nature. They want to protect their business in many ways. And of course, they want to reduce opportunity for disruptions. But these days, you have to understand that not patching a vulnerability that is on exposed system is essentially an entry point that the attackers can exploit much faster and progress much, much faster. Therefore, prioritization shifts from, let's say, the CVSS score into whether the vulnerability is actually exposed to the attacker and how far the attacker can progress through those vulnerabilities and do it daily, not on two weeks or like on a month's patch cycle. And this is also just because we kind of agree that it's really hard to keep up with the speed and having detection and response as the last protection. So we have to get a bit out, making sure that the attack surface is reduced and these healthy stuff around vulnerability and configuration management is managed as well. And just to go on another slide that is also touching on what you said, David. So we have from a recent study of incidents, we have these data that actually points out that it's overwhelming many incidents that have cost that is directly related to AI and AI agents in the client infrastructure. And we don't see that a lot from clients we speak to. So the SOC is actually able to work and address a lot of those areas. This is housekeeping, this is detection as well. But right now we just see that very widespread deployment of agents. Yeah, I think it's very important to understand that that part of discovery is as critical as the discovery, like reconnaissance that we're doing from outside. The internal agents become a latent threat. They're essentially sitting there waiting for either to be abused, exploited, especially when the governance is weak and the development practices are not yet polished. Yes, that's great. And we're also approaching the end. So just to have a few takeaways from everyone attending. We have put a few takeaways here on the slides. And one of the things that is just so important for our point of view, the most important is to make sure that the system actually knows enough to be able to build on automation and AI. Because if you build on a bad data, then you are not getting there at all. And the other takeaway should be that you just make sure that you are also managing the attack surface as such, not only on detection, but also on the protection. And for that, it concludes our session. So thanks a lot for being here. And again, if you have questions, we will go back to them and see if we can reply. Thanks. Thanks.