Published: 28/09/26

Beyond the Hype: What an “Agentic SOC” Actually Means to SEP2

What an “Agentic SOC” Actually Means to SEP2

AI has become ubiquitous in cyber security, and is almost an abstract buzzword. Too many vendors simply “bolt on” a basic chatbot, declare themselves an AI-driven organisation, and call it a day.

At SEP2, we believe that security operations have been playing catch-up for far too long. Attackers are running a fast sprint using automated toolsets to discover vulnerabilities and chain them into exploits, shrinking the Mean Time-to-Exploit (TTE) to machine speed. To defeat automated offense, you need autonomous defence.

That is why SEP2 launched EMEA’s first Agentic Security Operations Centre (SOC). Built on Google SecOps and the Google Vertex AI platform, this is a fundamental, ground-up re-engineering of how we protect our customers.

Here is what an Agentic SOC actually means to SEP2 in practical, operational terms.

 

Re-Engineering the Process, Not Just Automating the Past

To understand what an Agentic SOC means, we have to look at the traditional SOC bottleneck. Traditionally, a security analyst could spend up to 20 or 30 minutes manually checking security logs, verifying endpoints, querying external threat feeds, and writing case notes for a single security alert. During activity spikes, this manual toil creates data backlogs, delaying response times for high-priority incidents.

Instead of trying to make analysts run faster, SEP2 re-engineered the process. By deploying an ecosystem of interconnected, specialised AI agents, we shifted security from passive visibility and reactive alert sorting to proactive engineering.

These digital specialists operate symmetrically within a unified case management ecosystem using Model Context Protocol (MCP) and direct API integrations, handling the data-gathering and documentation heavy lifting so that humans do not have to.

 

Meet the Digital Team: Specialised Multi-Agent Personas

In our Agentic SOC paradigm, we do not rely on a single, generic chatbot. Instead, we use highly targeted technical personas designed to handle specific stages of the threat lifecycle:

Casey (The Alert Powerhouse)

Operating inside our custom multi-tenant UI, Casey automatically intercepts incoming alerts. Within seconds, Casey performs instant SIEM searches, enriches alerts with Google Threat Intelligence and cross-platform telemetry, runs vector searches across past case histories, and drafts natural-language case summaries.

S.I.T.H. (Special Intelligence Threat Hunter)

S.I.T.H. operates passively in the background, continuously mapping Software Bills of Materials (SBOMs), learning threat vectors based on client footprints, and automatically running threat hunts to find adversaries before they strike.

CurTIS (CURated Threat Intelligence System)

CurTIS gathers threat intelligence from trusted sources, keeping the most relevant information from the past 24 hours. It filters the more severe and impactive events, providing summaries based on specific prompts tuned by SEP2. The results are reviewed by human analysts before being shared with customers.

The Ultimate Core Value: Human-in-the-Loop (HITL)

There is a common industry misconception that AI in the SOC is meant to replace human analysts. At SEP2, our philosophy is the exact opposite. We are Tech-Driven, People-Powered.

Our Agentic SOC enforces a strict Human-in-the-Loop (HITL) governance model. AI agents do not make autonomous isolation or blocking decisions on their own. Instead:

  • The agents perform the multi-step reasoning, data aggregation, and initial triage in seconds.
  • They present a highly structured, contextualised case file to our human specialists.
  • A certified human analyst reviews, validates, and approves every single AI-generated recommendation before any remediation or containment action (such as quarantining a host or disabling a user account) is executed.

This approach does not replace our analysts but elevates them. By removing the mundane, repetitive administration, such as sorting through thousands of benign link clicks, our analysts are given back their most valuable resource: uninterrupted time to focus on complex threat hunting, deep-dive investigations, and perimeter tuning.

Why Location and Ownership Still Matter

With the rise of automated security, many providers outsource or offshore their SOC operations to cut costs. SEP2 does not.

Our Agentic SOC is operated 100% in-house by direct SEP2 employees located at our HQ in Leeds, UK, with zero outsourcing, zero offshoring, and zero subcontracting.

Furthermore, we believe in complete transparency. We have pioneered an Open Book Approach where our live case-handling notes are fully visible to our customers for every single alert received. These notes combine the natural-language summaries generated by our security-grounded version of Google Gemini with granular, technical analysis from our expert analysts, letting our customers see exactly what is happening in real time.

Remember that AI cannot be held accountable for the actions that it takes. All response actions that are performed should be traceable back to an individual who can back up their actions with reasoning.

 

The Proof is in the Metrics

We do not ask our customers to rely on abstract promises. Our Agentic SOC and Wingman Managed Detection and Response (MDR) platform deliver quantified, enterprise-grade resilience:

  • 20x Faster Triage: What used to take an analyst 20 minutes of manual research is now gathered, summarised, and contextualised by AI agents in under a minute.
  • 6x Faster Detection Rule Creation: Writing complex custom detection rules is accelerated six-fold.
  • 66% Reduction in Coverage Gaps: The time required to deploy rapid response rules for novel threats has been cut by two-thirds.
  • Double the Rule Efficacy: We have doubled the number of custom detection rules deployed across our customer base with zero additional internal resource requirements.

 

Modern Security for Modern Ecosystems

Transitioning to an Agentic SOC is about solving a very practical, real-world industry challenge: cyber threats are moving too fast for traditional, manual analyst workflows to keep up, yet completely autonomous “black-box” AI systems are prone to false positives that can disrupt legitimate business operations.

For SEP2, this approach represents a balanced, highly practical middle ground. By delegating the repetitive, time-consuming tasks of data assembly and initial triage to specialised AI agents, we ensure our human analysts have the exact context they need to make quick, accurate decisions. This means faster threat detection, fewer false alarms, and a sustainable security posture that scales seamlessly with your business, all backed by a UK-based, human team you can trust and talk to at any hour of the day.

Want to see EMEA’s first Agentic SOC in action? Get in touch with our technical team today for a tailored demonstration or to learn more about how Wingman MDR can secure your organisation’s infrastructure at machine speed.

Contact our team

Get the Latest

Wingman Insights

Photo of Paul Starr

Get thoughtful, people-powered cyber insights in your inbox once a month with our Wingman Insights newsletter

Name(Required)

By submitting this form, you are agreeing to our privacy policy.