The award-winning WIRED UK Podcast with James Temperton and the rest of the team. Listen every week for the an informed and entertaining rundown of latest technology, science, business and culture news. New episodes every Friday.
…
continue reading
A tartalmat a Anton Chuvakin biztosítja. Az összes podcast-tartalmat, beleértve az epizódokat, grafikákat és podcast-leírásokat, közvetlenül a Anton Chuvakin vagy a podcast platform partnere tölti fel és biztosítja. Ha úgy gondolja, hogy valaki az Ön engedélye nélkül használja fel a szerzői joggal védett művét, kövesse az itt leírt folyamatot https://hu.player.fm/legal.
Player FM - Podcast alkalmazás
Lépjen offline állapotba az Player FM alkalmazással!
Lépjen offline állapotba az Player FM alkalmazással!
EP252 The Agentic SOC Reality: Governing AI Agents, Data Fidelity, and Measuring Success
MP3•Epizód kép
Manage episode 519897359 series 2892548
A tartalmat a Anton Chuvakin biztosítja. Az összes podcast-tartalmat, beleértve az epizódokat, grafikákat és podcast-leírásokat, közvetlenül a Anton Chuvakin vagy a podcast platform partnere tölti fel és biztosítja. Ha úgy gondolja, hogy valaki az Ön engedélye nélkül használja fel a szerzői joggal védett művét, kövesse az itt leírt folyamatot https://hu.player.fm/legal.
Guests:
- Alexander Pabst, Deputy Group CISO, Allianz
- Lars Koenig, Global Head of D&R, Allianz
Topics:
- Moving from traditional SIEM to an agentic SOC model, especially in a heavily regulated insurer, is a massive undertaking. What did the collaboration model with your vendor look like?
- Agentic AI introduces a new layer of risk - that of unconstrained or unintended autonomous action. In the context of Allianz, how did you establish the governance framework for the SOC alert triage agents?
- Where did you draw the line between fully automated action and the mandatory "human-in-the-loop" for investigation or response?
- Agentic triage is only as good as the data it analyzes. From your perspective, what were the biggest challenges - and wins - in ensuring the data fidelity, freshness, and completeness in your SIEM to fuel reliable agent decisions?
- We've been talking about SOC automation for years, but this agentic wave feels different. As a deputy CISO, what was your primary, non-negotiable goal for the agent? Was it purely Mean Time to Respond (MTTR) reduction, or was the bigger strategic prize to fundamentally re-skill and uplevel your Tier 2/3 analysts by removing the low-value alert noise?
- As you built this out, were there any surprises along the way that left you shaking your head or laughing at the unexpected AI behaviors?
- We felt a major lack of proof - Anton kept asking for pudding - that any of the agentic SOC vendors we saw at RSA had actually achieved anything beyond hype! When it comes to your org, how are you measuring agent success? What are the key metrics you are using right now?
Resources:
- EP238 Google Lessons for Using AI Agents for Securing Our Enterprise
- EP242 The AI SOC: Is This The Automation We've Been Waiting For?
- EP249 Data First: What Really Makes Your SOC 'AI Ready'?
- EP236 Accelerated SIEM Journey: A SOC Leader's Playbook for Modernization and AI
- "Simple to Ask: Is Your SOC AI Ready? Not Simple to Answer!" blog
- "How Google Does It: Building AI agents for cybersecurity and defense" blog
- Company annual report to look for risk
- "How to Win Friends and Influence People" by Dale Carnegie
- "Will It Make the Boat Go Faster?" book
254 epizódok
MP3•Epizód kép
Manage episode 519897359 series 2892548
A tartalmat a Anton Chuvakin biztosítja. Az összes podcast-tartalmat, beleértve az epizódokat, grafikákat és podcast-leírásokat, közvetlenül a Anton Chuvakin vagy a podcast platform partnere tölti fel és biztosítja. Ha úgy gondolja, hogy valaki az Ön engedélye nélkül használja fel a szerzői joggal védett művét, kövesse az itt leírt folyamatot https://hu.player.fm/legal.
Guests:
- Alexander Pabst, Deputy Group CISO, Allianz
- Lars Koenig, Global Head of D&R, Allianz
Topics:
- Moving from traditional SIEM to an agentic SOC model, especially in a heavily regulated insurer, is a massive undertaking. What did the collaboration model with your vendor look like?
- Agentic AI introduces a new layer of risk - that of unconstrained or unintended autonomous action. In the context of Allianz, how did you establish the governance framework for the SOC alert triage agents?
- Where did you draw the line between fully automated action and the mandatory "human-in-the-loop" for investigation or response?
- Agentic triage is only as good as the data it analyzes. From your perspective, what were the biggest challenges - and wins - in ensuring the data fidelity, freshness, and completeness in your SIEM to fuel reliable agent decisions?
- We've been talking about SOC automation for years, but this agentic wave feels different. As a deputy CISO, what was your primary, non-negotiable goal for the agent? Was it purely Mean Time to Respond (MTTR) reduction, or was the bigger strategic prize to fundamentally re-skill and uplevel your Tier 2/3 analysts by removing the low-value alert noise?
- As you built this out, were there any surprises along the way that left you shaking your head or laughing at the unexpected AI behaviors?
- We felt a major lack of proof - Anton kept asking for pudding - that any of the agentic SOC vendors we saw at RSA had actually achieved anything beyond hype! When it comes to your org, how are you measuring agent success? What are the key metrics you are using right now?
Resources:
- EP238 Google Lessons for Using AI Agents for Securing Our Enterprise
- EP242 The AI SOC: Is This The Automation We've Been Waiting For?
- EP249 Data First: What Really Makes Your SOC 'AI Ready'?
- EP236 Accelerated SIEM Journey: A SOC Leader's Playbook for Modernization and AI
- "Simple to Ask: Is Your SOC AI Ready? Not Simple to Answer!" blog
- "How Google Does It: Building AI agents for cybersecurity and defense" blog
- Company annual report to look for risk
- "How to Win Friends and Influence People" by Dale Carnegie
- "Will It Make the Boat Go Faster?" book
254 epizódok
Minden epizód
×Üdvözlünk a Player FM-nél!
A Player FM lejátszó az internetet böngészi a kiváló minőségű podcastok után, hogy ön élvezhesse azokat. Ez a legjobb podcast-alkalmazás, Androidon, iPhone-on és a weben is működik. Jelentkezzen be az feliratkozások szinkronizálásához az eszközök között.