The AppSec testing market split itself in two. Both halves are wrong.
Manual pentesting doesn't scale. Autonomous AI testing isn't ready for Tier 1 apps. UltraViolet Cyber's third option: senior practitioners augmented by Solstice AI.
Find flaws in AI Systems
Find flaws in web, mobile, and IoT applications.
Expose risks in AWS, Azure, and GCP environments.
Live-fire exercises to sharpen detection and response.
Time-boxed security assessments across networks, apps, and infrastructure.
Simulated attacks to test detection and incident response.
Named security experts integrated seamlessly into your team.
Real-time detection and automated threat response.
24x7 monitoring and response by expert analysts.
Detection-focused SIEM migration without visibility gaps.
UltraViolet's proprietary AI platform powering all application penetration testing.
Unified security platform powering all UV services.
Cross-platform toolkit for advanced red team ops.
UltraViolet Cyber provides security services across the AI lifecycle, combining strategy, threat modeling, adversarial testing, monitoring, and training to support secure AI adoption.
Learn how a major U.S. airport operator achieved 24/7 threat detection, improved security maturity, and ...
Secure your code, infrastructure, and deployment pipelines before attackers exploit them.
AI agents won't fix a broken SOC. UltraViolet CEO Ira Goldstein on why Detection-as-Code, unified telemetry, and adversary ...
AI Governance by DesignAn Architecture-Aware Approach for Embedding Governance into AI Systems
Feb 3-5, 2026
Mar 19, 2026
Feb 19, 2026
UltraViolet Cyber is a practitioner-led MSSP delivering offensive and defensive security to Global 2000 and Federal clients. Built by former intelligence operators, we unify application security, red teaming, detection, and engineering under one roof. Our UV Lens platform replaces silos with integrated, outcome-driven operations.
The positioning around AI in the security operations center has shifted from "when" to "now." While components of AI in the SOC have become much more common over the past year, widespread usage and wholesale platform shifts are extremely rare. Tier 1 agents can triage alerts, investigate incidents and draft response actions, all without a human in the loop. Vendors are racing to announce agentic SOC capabilities, and CISOs are under pressure to adopt them.
But here's what most of that conversation is missing: AI agents don't fix a broken SOC. They inherit it.
If your detections are noisy, your telemetry is siloed and your response workflows are ad hoc, an AI agent will execute all of that, faster and at scale. The promise of the AI-enabled SOC collapses under the weight of poor fundamentals, despite platform vendor claims.
Earlier this year, I outlined five strategic investments CISOs need to make for 2026: attack-informed defenses, Detection-as-Code, unified telemetry, response playbooks and adversary simulation. To recap briefly:
The AI-enabled SOC narrative reached early prominence at RSAC 2025. What's changed over a year later is the noise level. The vendor proliferation, and procurement pressure. The reasonable expectation that every SOC should have an AI strategy and have it now.
That pressure makes the fundamentals more important, not less. Gartner predicts that 70% of large SOCs will pilot AI agents to augment operations by 2028 — but only 15% will achieve measurable improvements without structured evaluations. Many organizations investing in agentic SOC capabilities won't see meaningful results. Not because the technology fails them. Because the foundation beneath it does.
Those five investments aren't just good hygiene for the modern SOC. They are the prerequisites for a successful AI SOC.
Agentic AI systems are only as effective as the inputs they operate on. Consider Detection-as-Code. When detection logic is version-controlled, tested and validated, an AI agent can be trusted to reason against it. When it isn't, when business logic inputs to detections are undocumented, and rules inconsistently tuned producing false positives, an agent will dutifully chase every bad signal, creating more noise, not less.
The same applies to telemetry. Unified, full-fidelity data lakes give AI agents the context they need to distinguish a genuine intrusion from a misconfigured endpoint. Fragmented, siloed data leaves agents operating blind in exactly the areas that matter most — lateral movement, privilege escalation, cross-environment threats.
And without adversary simulation baked into operations, agents have no way to validate their own detection gaps. A model trained on historical alerts will miss novel techniques. Consistent red team exercises and purple teaming, with a combination of automation and human ingenuity, ensure that what your agents are looking for actually reflects what adversaries are doing today.
At UltraViolet Cyber, we've deployed agentic runbooks across our SOC operations, and the results speak to what's possible when the foundation is right.
Take identity abuse investigations, one of the highest-volume, most time-sensitive alert categories any SOC handles. Privileged account brute force attempts and suspicious user activity reports used to require 45 minutes of analyst investigation time per alert. With the runbook deployed, that same investigation completes in 15 minutes — a 67% reduction. The AI handles the cognitive heavy lifting of enrichment, correlation and pivoting. The analyst reviews the output, validates priority and context, and retains full decision authority before any response action is taken.
Web activity investigations tell a similar story. Malicious URL detections and potentially unwanted application alerts previously consumed 25 minutes of analyst time. The runbook brings that down to 3 minutes — an 88% reduction. The speed matters, but so does the consistency. Every investigation follows the same structured logic, with an analyst in the loop at the point of decision.
Cloud environment investigations round out the picture. AWS-based alerts — snapshot deletions, configuration changes, activity that signals potential data exposure or infrastructure manipulation — previously took 30 minutes to work through. The runbook completes the same investigation in 10 minutes, a 67% time savings that compounds quickly across a high-volume cloud environment. In each case, no action is taken, no case closed, without an analyst's eyes on it first.
Across all three, the pattern is the same: the AI didn't create the investigative process. It operationalized one that already existed and was already sound. Which means the ROI of your AI SOC investment is directly proportional to the quality of the foundation beneath it.
None of this replaces the need for experienced operators. What it changes is how their time is spent. When agents handle Tier 1 volume, the repetitive, pattern-matched investigations, analysts are freed to focus on Tier 2 and Tier 3 work: threat hunting, adversary emulation, tuning detection logic and reviewing the outputs that agents escalate.
The human role in the AI SOC is elevated and realizing that potential requires building a SOC where humans and agents are working from the same playbook: one built on structured detection, validated data and offensive-informed context. AI handles the volume. Humans handle the judgment. That division only works when the underlying systems give both sides what they need to operate with confidence.
There's a version of the AI SOC conversation that treats agentic tools as a shortcut around investment in people, process and architecture. That version leads to a faster, more automated version of the same reactive posture security teams have struggled with for years.
The better path, and the one we're seeing work in practice, is to recognize that getting your house in order isn't preparation for the AI SOC. It is the AI SOC strategy.
Detection-as-Code, unified telemetry, continuous adversary validation, structured response automation: these aren't legacy concepts being replaced by AI. They are the conditions under which AI agents actually succeed.
As for the changing role of humans in the SOC? At UV, the human and the machine work in tandem. AI runbooks act as a force multiplier, automating the cognitive heavy lifting of enrichment, correlation, and pivoting, but decision authority stays with the analyst. An agentic AI can triage and work a runbook, but the case is always reassigned to a person before any response action is taken. No autonomous blocking. No auto-isolation. No case closure without an analyst's eyes on it. Tested guardrails to limit AI autonomy.
To deliver better security outcomes amidst the AI Hype Cycle, the strategy is clear: Build the foundation, an d the agents will follow.
We’re here to help. Get in touch for an initial conversation with one of our security experts and learn more about how UltraViolet Cyber can help you take cyber readiness and resilience to new levels.