Trending Topics

When the SOC acts at machine speed, one bad decision can travel just as fast
Fast responses to attacks have remained elusive for most security teams due to the sheer nature of the dynamic threat landscape. But there appears to be some good news. Zscaler’s new Agentic SOC promises exactly that: AI agents that investigate threats and automate containment using zero-trust telemetry, a decoy network and third-party security controls. Zscaler says its platform processes 750 billion zero-trust transactions daily.
While that scale creates opportunity, one must also ask the inevitable question: what happens when an automated response is wrong?
Speed changes the stakes
A mistaken alert is inconvenient when an analyst can dismiss it. A mistaken action can disrupt a legitimate user, block business traffic, or interrupt an application before anyone reviews the evidence.
The pressure to automate is real.
In a 2025 survey of 739 cybersecurity professionals, 72% identified faster investigation and response as an objective for AI in the SOC; 65% wanted fewer alerts and false positives. Those figures describe priorities, not proof that automated containment is safe.
| What SOC teams want from AI | Survey respondents |
| Faster investigation and response | 72% |
| Fewer alerts and false positives | 65% |
Zscaler says its agents can draw on inline telemetry and use integrated controls to stop threats at machine speed. The value depends on the quality of the evidence and the authority given to each agent. Bad telemetry, a false positive, or a compromised signal could otherwise turn fast containment into fast disruption.
Give automation boundaries
Not every response needs the same approval. An agent might enrich an alert or recommend a block without interrupting operations. Isolating a user or changing access to a critical application deserves a higher threshold.
That means tiered authority, least-privilege access for agents, reversible actions, and records showing why a decision was made. Human approval should remain available where the business impact could be significant.
In one of our interviews, Zscaler’s Marc Lueck argued for simpler security. Our zero-trust checklist likewise stresses understanding assets and access before applying controls. An autonomous SOC needs that groundwork more than ever.
The goal is not to slow every decision to human speed. It is to ensure an agent’s power to act never outruns the organisation’s ability to understand, and undo, what it has done.
