Agentic SOC Alliance Хочет Установить Правила Киберзащиты С Помощью Искусственного Интеллекта
Новый альянс Agentic SOC, состоящий из 15 членов-основателей, включая ExtraHop и CrowdStrike, нацелен на стандартизацию операций agentic по обеспечению безопасности. Созданная в преддверии Black Hat USA 2026, группа стремится определить общую операционную модель, тестируя трехуровневую архитектуру: контекст, систему управления и модель. Эта инициатива направлена на устранение существующей путаницы, из-за которой поставщики используют "Agentic SOC" для самых разных функций агентов искусственного интеллекта, от обобщения предупреждений до действий в реальной среде, без четких стандартов. Альянс считает, что общая архитектура и критерии оценки помогут CISO распознавать надежные системы, предотвращая "вымывание агентов" и обеспечивая реальную ценность агентов. Это имеет решающее значение, поскольку количество автоматизированных атак увеличивается, а искусственный интеллект дает небольшим организациям шанс преодолеть пробел в кибербезопасности, делая защиту более быстрой и рентабельной. Правительства также уделяют особое внимание контролю со стороны человека, подчеркивая необходимость четких методов оценки и подотчетности.
Альянс Agentic SOC пытается ответить на вопрос, который компании, занимающиеся кибербезопасностью, в основном упускают из виду в своем стремлении продавать искусственный интеллект: что на самом деле следует доверять агенту? Недавно объявленный Agentic SOC Alliance пытается навести порядок в одной из самых быстрорастущих категорий кибербезопасности. В преддверии Black Hat USA 2026 было объявлено о создании альянса из 15 членов-учредителей, включая ExtraHop, CrowdStrike и TENEX.AI, Torq, Dropzone AI и LangChain, группа хочет определить и протестировать общую операционную модель для операций агентной безопасности. Группа планирует протестировать общую операционную модель для операций агентной безопасности, построенную на трех уровнях, называемых Контекст, жгут и модель.
Поставщики систем безопасности уже просят компании доверять ИИ-агентам все более ответственную работу. Некоторые агенты обобщают предупреждения. Другие расследуют инциденты, запрашивают системы и рекомендуют меры предосторожности. Самые амбициозные могут действовать в реальных условиях. Без единых стандартов в отношении доказательств, разрешений и подотчетности покупатели могут с трудом отличить полезную автономию от рискованной автоматизации.
Главный вопрос заключается в том, сможет ли отрасль договориться о том, как должен выглядеть надежный агентский SOC, прежде чем этот термин станет просто еще одним маркетинговым обозначением. Альянс делает ставку на то, что общая архитектура, более четкие критерии и улучшенный контроль помогут руководителям CISO определить, какие системы заслуживают большего внимания, а какие - нет.
Что считается агентской SOC?Ричард Роджерс, директор по маркетингу TENEX.По словам Роджерса из Black Hat, самой большой проблемой может быть то, что производители используют одну и ту же этикетку для продуктов с очень разными возможностями.
"Реального определения агентного SOC не существует". По его словам, одной из целей альянса является установление того, "что является нормой для того, чтобы называть себя" агентурной операцией по обеспечению безопасности.
Продукт, который обобщает предупреждения, отличается от продукта, который расследует инцидент. Агент, который может отключить учетную запись или изолировать компьютер, создает совершенно другой уровень риска.
ExtraHop’s proposed architecture tries to separate those jobs. Context supplies information about identities, devices, workloads and network activity. The Harness controls what an agent can access and which tools it can use. The Model is focused on doing the reasoning.
Rogers said autonomous security needs "one good source of truth for identity," coupled with reliable information from the network and endpoints. The goal is to give agents an auditable factual base rather than asking a model to reconstruct attacks from disconnected evidence. The problem is familiar to anyone who has seen good quality security tools work with a broken dashboard. Better models and tools do not fix bad gauges.
Changes In Cybersecurity’s Speed Limit"We believe we’re in a new paradigm in cybersecurity," said Eric Foster, CEO and Founder of TENEX.AI. After 34 years in the industry, he still sees the old contest between attackers and defenders. What changed, he said, is "the exponential speed of change."
Foster pointed to a recent exercise with Armadin, the company founded by former Mandiant CEO Kevin Mandia. TENEX executives said the test deployed 20,000 agents and generated roughly 231 billion logs. Rogers said the broader exercise involved about 1.3 million attack attempts. Foster said the data from the exercise could have taken a typical organization months to work through manually.
While there haven’t yet been independent benchmarks or audits on this sort of activity, the underlying point is that automated attacks can create more activity than a human security team can investigate one alert at a time. Foster thinks that same automation could help smaller companies close part of the defensive gap with enterprises that spend tens or hundreds of millions of dollars on security.
"How does the 10 person credit union accomplish some of those things?" he asked. "Artificial intelligence is shrinking the gap."
That could become one of the more significant economic arguments for the agentic SOC. AI is not merely a way for a large bank to make a sophisticated security operation faster. It could give a manufacturer, regional business or credit union access to investigation capabilities it could never afford to staff around the clock.
Foster said emerging companies like theirs aim to make cyber defense "better, faster, and more cost effective," with all three conditions required.
The Alliance Is Entering A Crowded RaceThe AI markets are getting increasingly crowded and noisy. Gartner has explicitly warned about "agent washing," where vendors relabel assistants, chatbots or conventional automation as agentic AI. Gartner analyst Anushree Verma said, "Most agentic AI projects right now are early stage experiments or proof of concepts that are mostly driven by hype." Gartner predicts more than 40% of agentic AI projects will be canceled by the end of 2027, citing costs, unclear value or weak risk controls.
That problem is already showing up in analyst research. "It’s difficult to trust a technology that won’t always answer in the same way," Forrester principal analyst Allie Mellen wrote. She argues that buyers should scrutinize accuracy, repeatability, explainability and how vendors validate their systems.
ExtraHop and TENEX are hardly alone in the objectives to put AI and agentic operations at the center of security operations. CrowdStrike launched its Charlotte AI AgentWorks ecosystem in March, letting customers build and manage security agents on the Falcon platform. CrowdStrike described the goal as an agentic SOC where humans are amplified by agents rather than replaced by them.
CrowdStrike and IBM announced a separate collaboration around Charlotte AI and IBM’s Autonomous Threat Operations Machine, aimed at coordinating machine speed investigation and containment. That still leaves substantial room for the Agentic SOC Alliance. Its members include companies that may eventually fight for the same security budgets.
Governments are reaching a similar conclusion. In May, CISA, the NSA and other Five Eyes cyber agencies issued joint agentic AI guidance calling for human control points around high-risk actions. The agencies acknowledged that methods for evaluating agentic systems are still developing.
Useful standards such as those proposed by the Agentic SOC Alliance fit this gap by telling buyers how often an agent reaches the right conclusion, how much evidence supports its decision, when a human intervenes and what happens after the machine makes a mistake. Cybersecurity vendors have spent the past year proving they can build agents, but now they need to prove those agents deserve authority and provide lasting business value.
>
