Core Services
What an “Agentic SOC” Actually Means to SEP2
AI has become ubiquitous in cyber security, and is almost an abstract buzzword. Too many vendors simply “bolt on” a basic chatbot, declare themselves an AI-driven organisation, and call it a day.
At SEP2, we believe that security operations have been playing catch-up for far too long. Attackers are running a fast sprint using automated toolsets to discover vulnerabilities and chain them into exploits, shrinking the Mean Time-to-Exploit (TTE) to machine speed. To defeat automated offense, you need autonomous defence.
That is why SEP2 launched EMEA’s first Agentic Security Operations Centre (SOC). Built on Google SecOps and the Google Vertex AI platform, this is a fundamental, ground-up re-engineering of how we protect our customers.
Here is what an Agentic SOC actually means to SEP2 in practical, operational terms.
Re-Engineering the Process, Not Just Automating the Past
To understand what an Agentic SOC means, we have to look at the traditional SOC bottleneck. Traditionally, a security analyst could spend up to 20 or 30 minutes manually checking security logs, verifying endpoints, querying external threat feeds, and writing case notes for a single security alert. During activity spikes, this manual toil creates data backlogs, delaying response times for high-priority incidents.
Instead of trying to make analysts run faster, SEP2 re-engineered the process. By deploying an ecosystem of interconnected, specialised AI agents, we shifted security from passive visibility and reactive alert sorting to proactive engineering.
These digital specialists operate symmetrically within a unified case management ecosystem using Model Context Protocol (MCP) and direct API integrations, handling the data-gathering and documentation heavy lifting so that humans do not have to.
Meet the Digital Team: Specialised Multi-Agent Personas
In our Agentic SOC paradigm, we do not rely on a single, generic chatbot. Instead, we use highly targeted technical personas designed to handle specific stages of the threat lifecycle:
Casey (The Alert Powerhouse)
Operating inside our custom multi-tenant UI, Casey automatically intercepts incoming alerts. Within seconds, Casey performs instant SIEM searches, enriches alerts with Google Threat Intelligence and cross-platform telemetry, runs vector searches across past case histories, and drafts natural-language case summaries.
S.I.T.H. (Special Intelligence Threat Hunter)
S.I.T.H. operates passively in the background, continuously mapping Software Bills of Materials (SBOMs), learning threat vectors based on client footprints, and automatically running threat hunts to find adversaries before they strike.
CurTIS (CURated Threat Intelligence System)
CurTIS gathers threat intelligence from trusted sources, keeping the most relevant information from the past 24 hours. It filters the more severe and impactive events, providing summaries based on specific prompts tuned by SEP2. The results are reviewed by human analysts before being shared with customers.