if ( !emtpy($headline_subheadline ) ) : ?>
Agent-run SOCs, machine-speed containment, and flatter security teams could transform how cyber defense is practiced as the AI era takes hold.
endif; ?>
The rapid emergence of AI has radically changed a host of professions, with software engineering and development perhaps the most transformed of all pursuits. The usual “solitary ritual” of a developer writing code for hours is giving way to collaboration with an army of chatbots.
In its 2025 report on the State of AI-Assisted Software Development, Google Cloud researchers found that even then, LLM usage was almost universal among coders, with 90% of developer respondents using AI as part of their work, and 80% believing it has increased their productivity. An earlier Microsoft study documented the effects AI had on productivity, with software developers who used AI completing 26% more tasks than developers who didn’t use AI.
The downside of the increased productivity is the impact on software developer jobs. Although data is hard to find, anecdotal evidence and some research show an impact on employment. For example, a March 2026 Federal Reserve Board working paper found that coder employment is slowing. “We find robust evidence that annual coder employment growth is about 3% lower now than it was pre-ChatGPT,” the authors concluded.
Not only has the number of developer jobs potentially dipped, but the organization around those jobs has also shifted. Gartner predicts that “80% of organizations will evolve large software engineering teams into smaller, AI-augmented teams by 2030,” with more midlevel and senior specialists; managers supervising a wider arena of activity; new roles emerging that include AI-governance specialists, context designers, and AI-augmented UX designers; and greater demand for systems-thinking.
Experts predict these kinds of changes will soon be felt across the cybersecurity sector with agent-run SOCs, continuous vulnerability triage, machine-speed containment, and humans directing fleets of defensive agents, posing the potential to make information security unrecognizable from its current state.
And yet, the analogy between the evolution of software and cybersecurity is imperfect.
“The hard part for us is, if we’re talking about where engineering is moving — to fully looped autonomous agents, feedback loops, all the things that they’re building now, and just having humans supervise the machines — security really requires reproducibility,” David Lindner, CISO at Contrast Security, tells CSO, meaning that a security control must produce consistent, repeatable results.
Moreover, any changes won’t be as rapid for cyber as they were for software development.
“I don’t think cybersecurity will be completely changed that quickly, but certainly we will see month-by-month big changes, and two years from now, it may be unrecognizable from what it is today,” Jim Reavis, CEO and co-founder of the Cloud Security Alliance, tells CSO.
The autonomous SOC is almost here
The transition to a new world of cybersecurity has already begun, and the most obvious area transforming is the security operations center (SOC). Most experts agree that AI agents can easily do the job that fully staffed SOCs do today, and do it faster and better.
“We had an incident come in through Jira, and the agent went and pulled all the information from GitHub, pulled all the information from Datadog, and then gave an initial triage,” Contrast Security’s Lindner says. “I don’t want to even call it a junior SOC analyst. It is a SOC analyst that does some initial triage.”
But there appears to be disagreement regarding how much authority SOC-replacing AI agents should be granted.
“We’re definitely leveraging AI tools, and maybe some of what would have been first-level triage is now being done by agents,” Lionel Litty, CISO at Menlo Security, tells CSO. “But at this point, at least for us, we’re not yet comfortable with just letting agents run wide in our SOC and make the ultimate decision of, ‘Hey, this is something that we can ignore, or this is something that definitely we should look at.’ We use them to help provide context and prioritize.”
Still, experts believe that much of the first-level work performed by SOC analysts will move to agents, leaving humans to handle escalation, oversight, and higher-level judgment.
“Basically all of cybersecurity is going to need to operate at machine speed,” Reavis says. “SOCs absolutely are going to have a layer of activity where it’s going to be all agents making the decisions and doing the triage. Then the human in the loop is going to be at a higher level, more senior.”
Vulnerability discovery becomes abundant, but absorption becomes scarce
It’s undeniable that the most immediate and ongoing changes from AI for cyber defenders are the rapid discovery of massive numbers of cybersecurity vulnerabilities, a shift the industry is already experiencing. But even this transformation comes with downsides because chasing down and fixing every flaw is an arduous task that consumes most defenders’ time.
“The problem absolutely is absorption,” CSA’s Reavis says. “How do I absorb this information? How do I triage it? How do I fix it?”
Menlo’s Litty has seen this problem before with static analysis systems that generated more findings than engineering organizations could address. “You can find hundreds of things, but if you send hundreds of things to engineering and most of them aren’t relevant, engineering will just ignore you,” he says.
AI can already find and test problems in source code, but autonomous validation against complicated production environments remains harder. Caleb Sima, chair of the CSA AI Safety Initiative and founding partner of White Rabbit, distinguishes between analyzing source code and autonomously testing complex production environments.
“I think vulnerability discovery today in source code is done,” he tells CSO. “But in terms of real vulnerability discovery in an autonomous way, in a real enterprise production network that produces valid vulnerability and exploitation, we still have a bit of ways to go.”
The so-called “vulnerability apocalypse” is less a fundamental cybersecurity change that will make the field unrecognizable and more a question of an increasing disconnect defenders know too well. As Lindner puts it: “We don’t have a problem finding problems. We have a problem triaging and remediating all the problems that we find.”
Machine-speed attacks force machine-speed containment
Another change that could leave traditional cybersecurity practices in the rearview mirror is what happens when autonomous attacks alter the threat environment, necessitating machine-speed response.
“It’s no longer about a single attacker rooting through your network, but it’s a landing of an agent that spawns 200 agents that rapidly move through your enterprise to identify and exploit its vulnerabilities,” Sima says. These agents can scope out the environment, locate valuable assets, and abscond with data before defenders can respond.
Cyber defenders should be positioned to respond in equal lightning-fast fashion. “The cloud, the application, and the endpoints should all be able to actively quarantine, move, and adjust controls at machine speed without breaking production,” Sima says.
Litty believes that defenders should assume any component could be breached and design the environment to limit the resulting damage. “This goes back to fundamentals: least privilege and separation of duties,” he says. “How do I make sure that I have separated components, defense in depth, so that one vulnerability being exploited doesn’t take my entire company down?”
Defender teams become flatter, more agent-heavy
Although it would be tempting to conclude that as SOC analyst jobs disappear, the AI-centric cybersecurity landscape would result in net job losses across the industry, experts say that likely won’t happen.
Instead, they anticipate a restructuring of roles and the emergence of smaller, agent-heavy teams. “I see a flattening of organizations between the leaders and the builders,” Reavis says. “The more senior people are going to have to go and build things.”
White Rabbit’s Sima sees a workforce model that is barbell-shaped, consisting of highly experienced professionals on one end and AI-native junior workers on the other end, with pressure on the workers in the middle who are devoted to coordination and project management. “I think you’ll see a barbell: top-tier, senior individual contributors and then juniors and interns,” he says. “The middle is going to struggle.”
Contrast Security’s Lindner agrees that workers with the highest knowledge and experience will fare well in the future.
“The things AI isn’t going to be able to replace are experience and judgment,” he says. “My team is uber-senior today, and I need that. I need them to fully understand and have the experience and the judgment to know how and when AI is going to work for us, and where we need to add different controls where AI isn’t going to work, because it’s not going to work everywhere.”
AI will likely never replace skilled cyber professionals, according to Litty. “I’m definitely not seeing the humans going away in those areas for now,” he says.
One beneficial restructuring of the cybersecurity market as AI takes hold fully is that LLMs may be the interface that connects, but does not reduce, today’s existing security tool sprawl.
Sima describes controlling firewalls, endpoint tools, and other systems conversationally without having to grapple with each product’s interface. “AI becomes the interface and the glue across all of these fragmented security products,” he says.
The ability to manage sprawl will surely be welcomed in a world with enormous agent proliferation and accelerated churn. “The technology footprint is exploding, and it’s so vast,” CSA’s Reavis says. “On the one hand, you see a lot of sprawl, and we’re going to have trillions of agents.”
Litty, on the other hand, thinks that existing tools will evolve instead of proliferating. “What we’re seeing so far is that it changes the tools,” he says. “It doesn’t necessarily mean more tools. So far, I’m not seeing an explosion of tools.”
What should CISOs do now?
CISOs don’t need to wait for these and other AI-related changes to occur before taking action. Experts recommend that security leaders identify bounded, high-volume tasks such as alert enrichment, initial triage, and vulnerability prioritization, where agents can be tested with restricted authority.
“What I would consider telling senior people is: Go build things,” Reavis says. “Building things doesn’t mean going to an entry-level position, but go build things that create a new way of doing your job.”
CISOs should also direct attention to creating a new governance discipline based on an inventory of every agent and AI-enabled security function.
“First, [have] a registry of where you are using AI, and then look at the quality of the output,” Menlo’s Litty says. “How do you do drift detection for what your AI tools are doing? Is this still working? If you take the SOC example, how do you evaluate how well your AI agent is doing at triaging your vulnerabilities?”
Finally, autonomous agents should not be considered anonymous agents. Every agent should have a named human or team that is accountable for it, with human review reserved for situations that are consequential or difficult to reproduce.
“There has to be a named owner,” Sima says. “Whether that named owner is a team or an individual is all dependent upon what that AI agent is responsible for, what its goal and objective are, and the job that it does.”
The task for CISOs, then, is not to automate everything. It is to learn where agents work, restrict what they can do, and establish who answers for them when they fail.










