Trending Topics

Rob Demain, CEO at e2e-assure: “UK businesses and service providers need to look beneath the hood when looking for a sovereign AI SOC”
Artificial Intelligence (AI) tools have national significance as demonstrated by the temporary export ban of Anthropic’s Mythos 5 and Fable 5 by the US government. That ban acted as a wake-up call, with politicians from the UK, France and The Netherlands all calling for more investment in homegrown AI models in a bid to create a national AI Cyber Shield in the UK and across Europe.
At the same time, the Five Eyes cyber security agencies has warned we are just months away from frontier AI models being able to cause catastrophic damage to businesses and governments. It stated that organisations that integrate AI tools into their security operations can detect vulnerabilities earlier, improve software quality, monitor unusual behaviour, and respond faster to incidents.
For Rob Demain, CEO at e2e-assure, none of this came as a surprise. With over 20 years’ experience in building Security Operation Centres (SOCs) for large corporations and organisations, such as national telcos, financial institutions, national public sector and defence organisations, his life goal has been to re-engineer the traditional SOC, developing the Cumulo platform to eradicate reliance on third-party technologies and now to harness AI.
In this exclusive interview, Rob explains the difficulties of constructing an AI SOC and the advantages conferred by using a purpose-built sovereign, AI-driven, zero-day platform to secure IT and OT environments.
Cyber sovereignty is now top of mind politically but has UK PLC got the memo?
AI security is not a future consideration – it needs to be addressed as a matter of urgency. AI lowers the barrier of entry for malicious actors and increases the speed and complexity of attacks and that means it shrinks the window between vulnerability discovery and exploitation. So it’s not just a matter of telling organisations they need to invest in UK cyber, it’s also a matter of re-educating the market on HOW to defend against these types of threat and what to look for when they go to market. Unfortunately, there has been a great deal of AI-washing which has seen AI bots tacked onto solutions rather than being engineered from the ground-up as AI-native offerings. That’s caused confusion and left CISOs unsure of how to proceed.
AI is seeing the speed and volume of attacks increase and the SOC struggle to keep pace. Why is that?
Most AI SOCs are still alert-led. In response to an alert, the analyst opens and begins investigating a case resorting to AI for triage, enrichment, summarisation, correlation, and to provide recommendations. But, by the time the alert exists, the events that produced it have already happened. They live upstream in raw telemetry, process trees, authentication flows, network sessions, package execution traces, cloud control-plane activity, endpoint state, and identity context. So the alert is not really the starting point, it’s actually the end. This poses a problem for detection and response in four ways.
Firstly, the SIEM is currently underutilised. It’s already ingesting enough data to potentially cover 90% of MITRE ATT&CK techniques but the actual detection rate last year was only 22%, according to The State of the SIEM report. As AI is being forced to query backwards from the alert, the raw event data it needs may also no longer be available in the form it needs.
The second problem is latency. Queries require lookbacks, joins, pivots, enrichments, and timeline reconstructions to give the AI sufficient context to reason well all of which take time while attack timeframes are collapsing, reducing response times.
The third problem is cost which can quickly spiral because the architecture forces the AI to rediscover context each time which creates a cost curve that scales badly. And the final issue is a lack of decision context. Because of where the AI is situated in the stream, it has no prior knowledge of what preceded an event which then degrades reasoning.
The truth of the matter is the SOC cannot be retrofitted with AI. It has to be redesigned from the beginning around AI-assisted reasoning.
Applying AI in the SOC is notoriously difficult. How have you tackled this problem?
AI can lead to problems due to inference but there are ways to deal with this. Hallucination can be resolved by verifying every conclusion against raw events before taking action. Prompt injection can be addressed by always treating log content as data, not instruction. The agent taking action stemming from a misread can be prevented from doing so by bounding its autonomy and setting per action classes, while over-confident and wrong responses to novel attacks can be prevented by using a ‘council’ of diverse models and modes so that no one model is allowed to mark its own homework. That diversity of judgement then catches what a single judgement misses. Finally, the drift we see with AI that can develop over time can be overcome by planting ‘canaries’ i.e. known synthetic attacks that prove the AI is still working correctly and so provide continuous validation.
All of that sees the SIEM treated as the single system of truth – as it always has been – with the AI treated as a component. AI can then play to its strengths because it’s grounded in your telemetry, knows the baselines and asset context, the controls, and what normal looks like. But what neither can address is the cadence in how swiftly threats are dealt with and the increase in alert volumes. Any detection path that depends on ingesting, indexing, and then running scheduled analytics will be working in minutes while parts of the attack are unfolding in seconds. Both cadence and capacity can only be increased by making detection happen in the stream, with AI used afterwards for judgement, and that’s what we have re-engineered with Cumulo. The decision-making process still needs to be defensible and so must always rest with a human analyst.
What do you see as being the principal role of the analyst going forward? How will the AI SOC equip them?
We have built Cumulo to continuously build understanding as data is generated, while keeping expert analysts at the centre of decision-making. Cumulo uses multiple AI models that cross-check every investigation from different perspectives (the council), building an auditable view of each alert, known as the Cumulo Analyst Helper (CAH) and findings are validated against threat intelligence and deterministic detection engines before results reach the analyst. The platform carries the volume so people are free for the high-value judgement, so that the SOC security team remains at the core of every decision using a ‘human in the loop’ structure that avoids giving the AI autonomy.
Those organisations with operations technology (OT) environments can find threat detection and response particularly painful. How can the AI SOC help them to address threats while minimising downtime?
For these critical organisations, the imperative isn’t just about identifying threats faster; it’s about ensuring their ability to defend remains intact during a crisis. The Cumulo platform provides a continuously maintained digital twin of each customer environment via passive discovery across IT and operational technology (OT) systems, enabling safe attack simulation, risk identification before exploitation and immutable preservation of analytical integrity. This is particularly valuable within operational technology and critical infrastructure environments where live testing is often impractical or carries unacceptable operational risk.
For organisations operating in regulated or high-dependence environments, reliance on external AI infrastructure can introduce risks around data residency, transparency and continued access to critical defensive capabilities. Cumulo addresses these challenges by keeping sensitive operational knowledge within customer-controlled environments, reducing exposure to external disruption and helping organisations maintain visibility and cyber defence capability even during major incidents, connectivity outages or wider infrastructure disruption.
What are the benefits of using a layered AI architecture?
Cumulo utilises a layered AI architecture that separates sensitive operational reasoning from broader intelligence and research capability. A local model layer handles environment-specific detection and analysis, a security intelligence layer aggregates and correlates threat data at scale, and a frontier model layer is used for non-sensitive enrichment and broader analytical tasks. This structure ensures that sensitive data remains contained while still enabling advanced AI capability where appropriate, supporting both compliance and performance requirements.
How can the AI SOC be used predictively to anticipate threats and deal with vulnerabilities?
Cumulo heralds the era of the zero-day SOC, meaning that live/new threat intelligence can be applied immediately as detection rules, driving down the risk from emerging threats. It combines predictive modelling capability with sovereign local AI models and expert human oversight for millisecond detection of known and emerging indicators of compromise. That effectively means the platform can be used to turn threat intelligence into live hunts across the estate rather than a feed you read after the fact. But that predictive capability is only made possible if you have that faster, cleaner reaction layer underneath. One enables the other and it’s the reengineering that detection pipeline that allows Cumulo to carry out the early identification of threats and vulnerabilities before incidents even occur.
