Alright. Excellent. Welcome, everyone. Let’s start in just a second. Okay. So welcome to today’s session from from concept to containment, the genetic sock in practice. I’m your host, Vijay Viswanathan. I’m with the product team here at Ontinu, and I’m joined by a true cybersecurity veteran and expert who also happens to be our chief security officer, Craig Jones. So, Craig, can you say hi? Hey, everyone. Great to meet you all. Right. So for today’s webinar, we’re gonna take a slightly different approach. Rather than just go through a set of slides, what I’m gonna do together with Craig here is we’re gonna walk through three different incidents, and these are incidents of varying severity. And each time, we’ll look at the initial alert, the evidence that comes up. And then I’ll pause and I’ll ask Craig. Hey, Craig. As a security leader, as a security practitioner, an operator, and as a customer who has hired a managed security provider, what would you ideally like to see your provider do next? What does good look like? Walk us through that. And then we’ll contrast for each incident the difference between a traditional MDR approach, and traditional MDR can just be pure manual, or it could be MDR with a little bit of AI sprinkled on top, a little bit of enrichment, a little bit of summarization versus a true agentic SOC approach. And maybe to start things off, the I’ll show I’ll I’ll tee up what we mean with an agentic SOC approach. It really comes down to a different type of operating model. At Ontinue when we talk about an agentic SOC approach, we’re talking about an approach that is built to scale security decision making. It does this through automation, through agentic AI, but always under the governance of humans. Okay. Excellent. So let’s let’s get right into it as as promised. First incident. So and I can let me turn this off so we can yep. See ourselves in the big see the content in the big screen. So first incident, conveniently, this is happening at 2AM on a Saturday, and three things come up. So there’s an authentication event to a privileged account that looks a little bit unusual. At the same time, the credentials that were provided and the MFA, those are valid. So there’s a couple of contrasting things here. And the third piece of evidence, this is a device that is unmanaged and has never been seen before. Okay. Craig, so it’s Saturday, 2AM. You’re sleeping peacefully after a nice long week. What would you expect your provider to do next? That’s a good point. Honestly, I would expect for one, for it to have fairly quick decent deep investigation into this. One thing I would expect though is the provider provider to check all the context around the authentication and the activity around that and, you know, try to really understand what’s happened here from a from a kind of timeline perspective And and honestly, if it’s high if they have high confidence in this and they truly believe that this is something that’s, you know, credentials that have been stolen, I’d want them to take some sort of preapproved response. I you know, I want them to deal with this for me. Okay. Got it. So so you don’t want them calling you up right away and asking you what to do next? No. That that’s what I pay you for. Yep. Excellent. So so let’s look at what what that would look like. It sounds like there’s some key questions you want them to answer. Right? Really understand what is all and when we talk about context, it’s what are all the things that are happening around this activity that could either make it benign or malicious? So there’s an unfamiliar authentication. What does the location information look like? Is the device recognized? We said in this case, it’s actually an unmanaged device, never been seen before. Right? So the first time observed. That that looks a bit suspicious. How does that activity compare to compare to the typical activity for this kind of user? Are there any notes on some specific business context? So these are the kinds of questions that sounds like, Craig, you want your provider to be not just asking, but actively finding the answers to. Let’s look at how traditional m MDR goes through it. They can certainly gather this context. But the question is, can they do it in a hundred and eighty seconds? And can they do it for every low severity alert? The the kind of manual approach that traditional MDR takes. Right? Sits in the queue. The low, medium severity that really defines how quickly it’s picked up, and then there’s a lot of pivoting between tools to gather all that context. Ultimately, when a decision needs to be made, that has to go through a human. Let’s compare that to an agentic SOC approach. So here, first thing, right off the bat, you get immediate investigation. The moment the detection fires, there’s investigation happening. That context is something that the GentixSOC system has direct access to. So it’s all assembled at machine speed without any kind of manual handoffs, any kind of manual pivoting between tools. And then when there’s this level of confidence that’s reached, and, Craig, you mentioned this, that, you know, if if the if your provider is confident that this is malicious, you would want them to take action. What’s key is that Agentic Soc needs to have access to what actions can be taken and what what it’s preapproved to take. Right? So really granular pre authorizations of what’s okay to do for this specific customer environment versus what’s not okay. So in this case, looks like the the user is compromised Two preauthorized response actions that an agentic SOC can take right away because it’s explicitly preauthorized to be able to do that. And most importantly, let’s compare the outcomes. With the traditional MDR, you have manual investigation and it’s ultimately escalated to a human for the final decision. With an agentic SOC, you get near real time. I’m not gonna say instantaneous, but near real time. Not just investigation, but also decision and response. This is really the difference between traditional MDR slash AI assisted MDR versus an agentic SOC. An agentic SOC is empowered to not only investigate deeply, but have the context to take an accurate decision and execute the response. Alright. Let’s flip to the next incident. So this one is Thursday. So hackers have been kind enough to strike on a working day, but it’s still pretty late at night. There’s some potentially suspicious looking activity going on here. There’s some sensitive resources that have been queried. There’s a bunch of admin tools that have been accessed. Given these signals, Craig, what would you expect your provider to do next? Yeah. I mean, that’s a good question, Vijay. I think this is the type of incident that’s pretty often found that’s benign, especially when it’s things like administrative tools. It’s something that often trips trips up analysts especially more junior ones, you know, but again, it’s often benign but if it’s malicious, it’s incredibly dangerous, you know, and I would expect the provider to really look at our history, understand a little bit about our environment, whether these things have been used before, if there’s some internal notes maybe on on on some of these aspects. And and, you know, that is as important really as taking prompt action. Really, we want to minimize the escalation of benign positives. You know, the last thing we want to do here, is is have a, you know, a provider just escalate to us, over something that might might be kind of bad but but with multiple signals like this is probably likely bad. You know? Yeah. I definitely, again, you know, wanna wanna see them take action. Yeah. Yeah. Absolutely. Yeah. As a a security professional, you felt the pain many times of, you know, providers needlessly escalating incidents. Right? And if there’s clear evidence that shows that it’s benign, you want them to be able to close it out. Of course, documenting why, right, the reasoning behind it, but it’s yeah. I think in many ways, an agentic focus, as much as it is about fast response actions, it’s also about being able to rule out benign positives in an effective way. So here again, I think it’s about asking these questions, being able to gather that context. Right? What does the behavior of this account look like? Does it does this kind of querying of sensitive resources, does it match any previous known pattern? So these are kind of all the pieces of evidence that ideally should be gathered by the provider to arrive at a decision and then, in in some cases, make a the action is to close out close out the incident. Here, I wanna contrast between AI assisted operations versus an adjective SOC. So, yes, almost every provider now uses AI to enrich alerts to summarize summarize an incident. But the real bottleneck that an agentic SOC helps unblock is the bottleneck around decision making, and that’s where AI assistant just falls short. Right? It can enrich. It can summarize, but, ultimately, it requires an escalation. It it it remains that a human is the bottleneck. With an agentic SOC, you want a system that has access to the context. And in this case, it’s actively coming up with hypotheses and then checking evidence, ruling them out. And when it when it’s able to rule out the possible malicious explanations, then it’s able to close it. Again, that’s within policy, and it provides reasoning for closing the incident as a benign positive. So let’s compare the final outcome. Escalation versus closing as a benign positive with all the reasoning recorded. And just one final point, deciding not to act is a decision as well. So the key thing is really the governance and the the documentation around that. Alright. Third incident, Craig. This time, it’s a public holiday at 4AM. So as usual, not sticking to to working hours. Here, this one is looking kinda serious. There’s there’s an authentication to a system. There’s some privilege escalation activity. Looks like looks like we’d want the provider to take action, but, yeah, my question to you is what would you expect the provider to do next? Okay. Great question again. Why did they always do it in a public holiday, Vijay? Alright. Honestly for this, I mean this is the high impact incident unless it’s contained. If it is a true positive, I mean it could be spectacularly bad. I I would really expect the provider to take immediate action, you know, where it can and also as well provide me as a customer context and evidence when approval is, is actually needed, you know. And again, it’s as you mentioned, it’s really about having that autonomy but also having governed decisions behind it too, you know. So I think for me, I I I’d wanna see this acted on quickly and I wanna see something done especially if it’s a true positive. So let let me ask you this, Craig. What would what would make you trust the system? I mean, ultimately, you’re responsible. Right? And you’re accountable for this. What would what would give you the confidence to delegate additional autonomy to your provider? I think it’s about control. I think it’s about me having that ability to decide what it’s autonomous on. You know? Yeah. I think that then that devolution of autonomy I think is useful. Yeah. But that’s the part I think that would give give me, I guess, the confidence to allow to do what I feel is right. Yeah. Okay. So it’s not you don’t wanna just flip a switch and say, okay. You can do anything you want in my environment. It’s about being very, very granular and specific about what your provider is allowed to do. Exactly. And and it needs to prove its worth too. You know, we can’t just turn it on and expect it to work either. You know? We’ve gotta I’ve gotta make sure that this thing is that I’m comfortable with it with the way that it works and that it works well. You know? And how does it prove that to you and how does it give you that comfort that, yes, it is taking the right decisions and I guess that’s with training and with lots of tuning. And those are those are the aspects, I guess, that are are super difficult when it comes to GenTic. Yeah. Excellent. So, again, here, I wanna contrast what an AI assisted operational model looks like versus an AgenTic SOC model. You’re getting enrichment. You’re getting summarization. You’re getting a recommendation, but a recommendation isn’t the final action. Right? It still still requires a human to act on it. Whereas with an agentic SOC approach, it knows the boundaries within which it can act and operate. It takes those actions, and then it only escalates when something is when it’s an action that it can’t directly take. Right? So exactly as Craig was saying right now, it’s not that agentic SOC means handing delegating all authority. It’s being very granular, defining exactly the scenarios in which the agentic SOC is allowed to take response action and then only in exceptional scenarios escalating. And then there too, as Craig mentioned, it’s about providing the relevant context evidence to to guide that and guide and inform that decision. And then finally, recording recording all that, the reason behind the decision. So here, just to play out this scenario, two response actions preapproved. So executed in near real time. There’s one action that requires an approval just in time, so that is escalated and approved and executed once approved. And this is really where we can think about this governance layer that surrounds agentic SOC in terms of the response actions it can take. And it’s you know, all those chips, there are are factors that that feed into that governance layer. Right? It really depends on the policies of your specific organization. It depends on the reversibility of action. Right? There’s some like, an investigation, of course, is always reauthorized because there’s there’s no risk with doing an investigation right away. But certain response actions, you know, it might have some business impact, so that’s really where that layer of governance comes in. And then finally, decision transparency, all the supporting evidence that led up to that final decision and response. So one of the key takeaways, not every response action carries its same threshold. You know, it really depends on the specific asset, on the type of user, so being very specific about that. And I just wanna land this final point on autonomy without governance creates risk, but governance without autonomy creates delay. Right? And, really, that’s the world in which we operate. Delay really is something that we have to something that we can’t accommodate. Alright. So I now would like to contrast and summarize the difference between these two approaches for these three incidents. Right? So first incident turned out to be a true positive with the traditional or AI assisted approach. That would have been sitting in the queue with a low severity alert, and it would have taken a while before any kind of decision and response was taken. Whereas with an agentic SOC approach, given that it was all within policy, the account is right away secured, and all that investigation detection response happened in near real time. Second incident was a benign positive, and we avoided an escalation. Instead, we found evidence that clearly showed it was not malicious incident, and we recorded that, closed it out. Nothing for the customer today. And third incident, the GentixSOC was able to act within the boundaries it’s given and then has escalated only this specific response action that required the approval of the customer. So couple things to call out. Notice the difference in the waiting states between a traditional or AI assisted versus agentic SOC. Traditional has a lot of waiting states. It requires an analyst to pick up the incident to begin with, then put together the context, then involve the customer. So there’s a lot of handoffs, a lot of shifting of the incident. I covered this point on handoffs. Third point is on it’s not about removing humans from decision making. It’s using human decision making on the decisions that really matter. And so we saw that example in the third incident where for isolating the critical asset, we still have a human explicitly approve that. And finally, the importance of having all that reasoning recorded. As Craig said, you can’t just blindly trust an agentic SOC. You need to be able to see the see the the reasoning, see why specific decisions and response actions were taken. And that really requires an auditable record. Yeah. One of the key points, it’s really not about human versus AI. Sometimes that’s some of the discussion around Genentech SOC. It’s human speed operations, that’s traditional MDR, versus governed machine speed decisions. And finally, just wanna call out that these are really two fundamentally different operating models with the Genentech SOC being centered around scaling decision making. Alright. So three incidents, all done. In this last case, you know, we took the response actions. Thanks for the approval, Craig. My question to you is, is your provider off the hook now? Is their work complete? Is the work complete? I I think top priority obviously is immediate containment. If I’m comfortable that it’s this thing is not not burning and and continuing to develop, it’s fine. But honestly I can expect my provider to kind of follow-up with some recommendations. You know, I’d want to know why it happened, how it happened and get some guidance I guess on how do I harden against similar incidents because if this is a an issue in my environment, what what’s gonna happen is this will just happen again unless I take proactive changes. So for us, I guess for any provider, we wanna make sure that the system is improving and, you know, put my customer hat on. I’d want to have that guidance of hey. You need to do x and change this in order to to prevent that, You know? And I think I think that that’s a really important point is closing that loop. You know? Yeah. Yeah. I I mean, ultimately, was a good outcome. The the threat was contained, but it still required various response actions, one of which, you know, needed your approval. So it’s not something you wanna be dealing with twice a week. So some of the some of the Some of the points points you mentioned, prevention measures, hardening measures. But maybe also, you know, looking at is this response action that you’re comfortable delegating in the future? In this case, it required your approval, but maybe as your trust grows over time, you decide that, yes, the the provider can execute even that final decision that final response action on my behalf. So I think that’s that’s kind of you know, you you mentioned continuous. It’s that is that is something that continuously should be reviewed, the decisions and policy thresholds because, yeah, we we always suggest start small and then expand from there as as your trust in the system grows. So key point, of course, contain the incident, but more importantly, make sure that the system is continuously improving. So we promised that we would also talk about some of the steps in making a transition to an agentic SOC. What are the switching cost to consider? So let me open that up. I think, ultimately, it comes down to what I mentioned earlier and what we were discussing. We don’t see this as the flip of a switch. Right? This is really about a controlled transition, a controlled expansion of delegated authority, and we see key three key steps in in that expansion. First and foremost, you can’t talk about decision making, good decision making, accurate decision making without the system having the context it needs. So that means security context, the business context, all that needs to be readily available to the system. Secondly, and this is where, you know, some some real work is required, explicit explicit definitions of what is authorized, what needs approval, what should never be done autonomously, all that needs to be needs to be explicitly defined as part of the transition and as part of delegating more authority. And then finally, you wanna be looking at what were the decisions that were taken. Do you you know, are those decisions that you agree with? So really continuously looking back at those decisions and assessing them for quality. You know, it’s it there are some costs to switching, and I I would say the biggest one is really being very explicit about the policies and the escalation paths. But we think that the even bigger cost is that of deferring change. Really, when decision making is the bottleneck, it it just can’t keep up with the speed of modern attacks, and you don’t want that to surface during a life during a live incident. So let me end with a couple of questions to consider when evaluating your next provider. So this first question has to do with investigation speed. Really, what you want to be looking for is a provider that can autonomously investigate. If their investigation speed is based on analyst manually picking up the incident, that’s simply too slow. Second one has to do with investigation quality and decision quality, and that has to do with do they have the context that they need. And if they say they do, then ask them challenge them to show it to you. How show me how your system or your analyst has the context that they need to take a decision that I can trust. Third is policies. Again, challenge them to show you where they capture that policies and how that’s readily available to their platform and analysts. Fourth is, ultimately, GeneticSOC is only truly empowered if it can take response actions. So can it take actions on your behalf instead of sending recommendations instead of escalations? And then the final question is really one around trust. How can you trust the service to take the right decisions, and how can you trust the service to delegate more over time? And, again, challenge them to show you show you where the decision making is recorded and how auditable it is. Excellent. And I think with that, we are right at time. I’d like to end with just this final statement. Ask what your MDR can decide and do, not just what it can detect. Two resources I’d love to point you to, we have an AgenTik SOC buyers guide where we really mapped out these evaluation criteria in a lot more detail. That’s available at ontini.com/agencticsock. And, of course, we’d be more than happy to discuss the transition to an agenctic sock with with any of you, and you can reach us at antini dot com slash contact. Excellent. Well, thank you very much, Craig, for playing the role of a for customer and walking us through what you would expect your provider to do at each step. Thanks a lot. Thanks. Thanks for having me, PJ. Yep.