
Artificial intelligence is having a seismic impact on cybersecurity, but so far that impact has been mostly one-sided. Cybercriminals and other bad actors are happily taking advantage of large language models (LLMs) and AI agents to increase the speed, frequency and sophistication of attacks.
As Anthropic’s August 2025 Threat Intelligence Report points out, attackers are applying AI capabilities to practically the full menu of threats, from identity theft and data extortion to credit card fraud and romance scams. AI-powered tools enable criminals who lack technical skills to carry out sophisticated attacks (turbo-charging ransomware as a service, for instance) and enable the no-code generation of malware.
In November 2025, Anthropic observed a campaign against 30 organizations that it said was approximately 80% automated using Claude. Attackers were able to “jailbreak” the model and integrated it into their tooling for the campaign. The unspoken worry is what attackers are doing with local models that have no safety protections at all.
Defenders, meanwhile, are constrained by manpower and resource shortages, especially at organizations where cybersecurity is seen as a lower priority and not adequately staffed. These resource-constrained teams are often mired in reactive tasks such as alert triage and investigation, leaving them little time to pursue proactive tasks that improve security.
A 2024 report by Osterman Research found that SOC teams spend 75% on reactive tasks dealing with the onslaught of cyber activity, which 97.6% of respondents said is increasing every year. And, to date, those tasks have been performed manually, requiring a high degree of collaboration involving anywhere from two to nine employees (with an average of 4.6) to investigate reports. This increases costs in time and money and, ultimately, also increases the risk organizations face from possible attacks that aren’t resolved quickly (giving bad actors “dwell time” to carry out attacks) or that go unaddressed.
And over time, security debt from issues the team didn’t have time to address continues to build. To put it bluntly, defenders are losing the battle because of the asymmetry in skills and resources.
But this imbalance in capabilities between attackers and defenders is beginning to change with the emergence of AI agents that are being built to replicate human cybersecurity skills, taking over the reactive work by automating tasks and enhancing reports before they reach analysts, enabling them to spend more time on high-value proactive work.

AI Agents Make Security More Efficient and Effective
New technology like Dropzone AI combines the cognitive reasoning power of LLMs with the cybersecurity expertise of analysts to replicate expert techniques in investigating alerts. Instead of playing catch-up on reactive tasks like initial alert investigation, human analysts leave that work to AI. The system automates triage, sorting, scoring and de-duplicating alerts. While investigating alerts, the system works like an expert human analyst would. It draws data from every available source across the entire security stack, enhancing alerts with real-time data from relevant sources, covering factors such as asset inventory, user activity, threat intelligence and past incident context. Only then does it flag an alert as a genuine alert or a false positive.
A 24/7 AI agent that works like a human would and adapts to individual environments can perform initial investigations on every alert. SOCs can operate as if they had an army of tier-1 analysts to take care of triage and other routine tasks. Humans only get pulled in when the system escalates potentially malicious activity.
While AI agents can do a lot to enhance security, organizations need to understand the proper use cases for AI. It can take a lot of the grunt work off analysts’ plates, but it can’t replace them. A higher level of thinking and human judgement is still necessary for strategic projects and collaboration with other teams. AI agents can simply allow analysts to do their jobs more effectively, without a lot of the routine, repetitive tasks that currently burden them.
A Long-overdue Lifeline for Overwhelmed SOCs
The emergence of AI agents that replicate human reasoning represents a new era for cybersecurity, offering analysts the tools they have needed for too long a time. Although previous generations of AI helped enable advanced detection capabilities, they were actually compounding the challenge that SOCs faced.
My eyes were opened to the problem during the early days at my previous job, where I led detection engineering for a network detection and response (NDR) vendor. The SOC manager of a prominent financial services provider told me that better detections weren’t as important as I thought. He gave a live demonstration of an alert investigation—from a security information and event management (SIEM) alert, to confirming network telemetry in NDR, then moving to endpoint detection and response (EDR), to file sharing and then cross-referencing with the HR system to look for an insider threat. It took more than 15 minutes.
His point was well taken. Putting an alert into context was complex, time-consuming—and mostly manual. As threat detection becomes more automated with the help of AI, SOCs are overwhelmed trying to keep up, often being able to investigate less than 10% of them.
The 2024 Osterman Research SOC Survey Report clearly outlines the problem. Although SOC teams are becoming more efficient at addressing and resolving alerts, a significant increase in the number of alerts—and a corresponding increase in false positives—combined with the complexity of investigations, outstrip the ability to keep pace.
At the time of that demonstration, the automation of alert investigations was largely out of reach. SOAR and robotic automation tools at the time couldn’t handle the variety of alerts and the organization-specific contexts required for them. Since then, the threat landscape has only gotten worse, with attackers making use of LLMs to accelerate the speed and frequency of attacks while the breadth of attack surfaces continues to grow.
Fortunately, however, SOCs can now harness AI agents to protect their enterprises. The same LLMs and AI agents that are used for attacks can now be used to level the playing field.
Conclusion
As AI increases the speed and sophistication of cyber threats, employing AI agents in the service of cybersecurity is no longer just an attractive idea. It’s a necessity. It’s the new defensive weapon that is going to be table stakes in the ongoing battle for digital security.