Tech Talks Daily podcast

Inside the Agentic SOC Where Humans and AI Defend at Machine Speed With Barracuda

0:00
24:36
Manda indietro di 15 secondi
Manda avanti di 15 secondi

What does a security operations center need when attacks are arriving at a speed and volume that human analysts cannot manage alone?

I recorded this episode with Adam Khan, VP of Global Security Operations and AI Security at Barracuda, during the 20th anniversary of the Barracuda Tech Summit in Alpbach, Austria.

Adam has spent over 25 years in technology and security. When we last spoke at the event, he used Home Alone and soccer to make complex security topics easier to understand. This year, expectations were high, and he arrived with Formula One.

The comparison begins with what spectators see. Attention naturally falls on the car and driver. Behind them sits a much larger operation involving engineers, strategists, mechanics, simulations, telemetry, and rapid decisions. Adam believes modern security works in a similar way. Customers want to run their businesses, while a largely unseen combination of analysts, threat intelligence, automation, and AI works behind them.

That operating model has developed into what Barracuda calls the Agentic SOC. AI agents follow the same playbooks analysts use when examining endpoints, malware connections, artifacts, threat intelligence, identity behavior, and other signals. They can complete repeatable investigative work quickly and consistently across volumes that have grown from hundreds of alerts to thousands or millions.

Adam says Barracuda now has hundreds of agents with hundreds of individual skills. These agents can support the process from triage and intelligence gathering through correlation and response. When the system has high confidence that an ordinary user account has been compromised, it may disable that account. If the incident involves an administrative account capable of locking down an entire customer environment, a person must confirm the action.

This matters because an AI system can misclassify an event or reach a conclusion that requires additional context. Adam describes feedback mechanisms through which people review decisions, identify mistakes, and feed those findings back into the system. Barracuda also records an audit trail of the actions and queries performed by its agents.

One of the most surprising details concerns employment. While headlines frequently associate AI with reducing headcount, Adam says his team has doubled since adopting it. Analysts previously occupied with repetitive investigation have moved into threat hunting, model development, prompt engineering, and attack and defense exercises. The team is also attacking its own systems so that its agents can learn from emerging techniques before a genuine incident occurs.

The audience saw this operating model during Adam's keynote. Attendees used their phones to launch controlled business email compromise, QR-code phishing, and ransomware scenarios against Barracuda's attack and defense environment. The platform then analyzed and blocked the activity while the audience watched.

Adam says approximately 395 attacks were initiated during the demonstration and all were successfully blocked. That result comes from a controlled Barracuda demonstration rather than an independent test, but it gave attendees a rare view of the speed required during an active incident.

We also discuss how Barracuda Managed XDR uses behavior and telemetry across email, endpoints, cloud services, identities, networks, and other technology. An employee traveling with a familiar laptop and phone should not create the same response as an unknown device attempting an unusual login. Historical patterns, device identifiers, signatures, and location data can help reduce unnecessary alerts while highlighting activity that deserves attention.

For Adam, the purpose of AI is to increase the speed and reach of security experts rather than remove them. People determine strategy, examine high-consequence decisions, test systems, and remain accountable for customer outcomes.

Could the Agentic SOC give security teams the speed they need without surrendering the judgment and accountability customers expect? Listen to the episode and share your thoughts.

Altri episodi di "Tech Talks Daily"