The AI arms race in cybersecurity: why your SOC must evolve now
The threat landscape has radically transformed. Adversaries are no longer just nation-states and elite criminal groups with deep financial resources. Now, they are anyone with access to AI, and this changes everything.
The uncomfortable truth: the attackers arrived first
Exploitation speed is no longer measured in days or hours, but in minutes and seconds. According to the Microsoft Digital Defense Report 2025, adversaries are now using generative AI to scale social engineering and automate lateral movement with surprising efficiency. Phishing campaigns created by advanced language models are achieving click-through rates up to 4.5 times higher than traditional methods.
The speed of these attacks is equally alarming. The CrowdStrike 2025 Global Threat Report highlights that the average breakout time, the window between initial compromise and lateral movement, has dropped to just 29 minutes. The fastest breakout recorded occurred in just 27 seconds. This acceleration is driven by what many call "vibe coding," where attackers use AI to build exploits and scripts at machine speed. Sophisticated threats that were once the exclusive domain of nation-states have been democratized, putting every organization in the crosshairs. It is quickly becoming an axiom in computing: if you're not using AI to fight AI, you will lose.
The shift to threat engineering
This rapid acceleration of sophisticated attacks is fundamentally changing the role of the SOC analyst. We are experiencing the most significant transformation since the invention of the SIEM, shifting from detection to engineering.
1. Attacking the supply chain: During an attack on a third-party supplier, Elastic agents automatically analyze software dependencies, compare suspicious SSL certificates, and generate compliance reports before the security team receives the alert.
2. Credential compromises: When anomalous access is detected, agents automatically apply temporary access rules, notify business teams, and initiate forensic investigations without human intervention.
3. Ransomware: In a ransomware attack, agents automatically isolate infected devices, restore data from encrypted snapshots, and begin decryption before the attacker can complete data encryption.
The data sovereignty dilemma
The choice between cloud and on-premises models raises critical data sovereignty issues. A European pharmaceutical company faced a dilemma when it discovered that its cloud AI provider stored training data in a country with different regulations. The Elastic solution allows:
- Running large models on on-premises infrastructure
- Keeping sensitive data completely offline
- Securely sharing anonymized data with research partners
The human aspect of agentic SOC
Integrating AI does not reduce the human role but radically transforms it. A McKinsey analysis reveals that:
- 68% of security analysts now spend more time on strategy design activities
- 52% of senior analysts are involved in training and mentoring
- 40% of time is dedicated to managing vendor relationships
This change requires new skills, such as the ability to interpret AI results and understanding the ethical limits of automated systems.
Considerations for decision-makers
1. Adoption time: Organizations with legacy infrastructures may require up to 18 months for full migration, while new cloud operators can implement agentic solutions in 6-9 months.
2. Hidden costs: Assessments should include not only software costs but also:
- Staff retraining
- Security policy changes
- Infrastructure upgrades
3. Success metrics: Beyond incident reduction, metrics should include:
- Average incident response time
- Percentage of incidents resolved without human intervention
The future of agentic SOC
Experts predict that by 2027:
- 75% of SOCs will use conversational agents to query security data
- 60% of organizations will adopt hybrid cloud/on-premises models
- 50% of companies will implement specialized security agents for specific sectors
The direction is clear: agentic SOC is not just a technological trend, but a strategic necessity to address the evolution of cyber threats.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.