Security

Agentic AI for SOC Alert Fatigue | Lauren Wilson, Splunk | TFiR

0

SOC analysts are fielding thousands of alerts per shift while threat actors use AI to automate reconnaissance, generate polymorphic payloads, and scale spearphishing with a precision that human-speed triage cannot match. The tuning trade-off inside most SIEMs has defaulted to surface everything rather than miss anything, which means the alert queue never shrinks. Meanwhile, the skills required to escalate from Level 1 triage to Level 3 forensic investigation take years to build, and most analysts never get there.

In this interview on TFiR, Lauren Wilson, Field CTO at Splunk, covers how agentic AI augments SOC analysts with capabilities they may never have reached in their careers, how Splunk governs those agents with least-privilege controls drawn directly from human HR policy, and what the incremental trust model looks like for enterprises moving from documented playbooks to autonomous incident response.

Guest: Lauren Wilson, Field CTO at Splunk
Show: TFiR

Here is what every SOC analyst, detection engineer, and security operations leader needs to know.

Technical Deep Dive

Q: Why are SOC teams still losing ground even with modern SIEM and detection tooling in place?

Lauren Wilson, Field CTO at Splunk, identifies the core tension as a two-front war: analysts must keep handling today’s alert volume while simultaneously preparing for an agentic threat landscape that is arriving faster than most transformation programs can move. Security teams have long defaulted to surfacing more alerts rather than fewer, accepting false-positive noise as the price of not missing a real incident. That tuning posture, combined with the expanding capability of threat actors who now include financially motivated enterprises running AI-assisted attack pipelines, means the gap between attacker speed and defender speed is widening structurally, not just operationally.

“The number of people that are conducting cyber incidents these days has kind of exploded. We are not just seeing the most sophisticated people anymore. That capability is in the hands of people that wouldn’t have dreamt of being able to do such attacks.”

Lauren Wilson, Field CTO, Splunk

Q: How are threat actors using AI to scale and sophisticate attacks in ways defenders have not seen before?

Wilson points to three compounding shifts: scale, speed, and sophistication, each advancing simultaneously. Threat actors are using AI to automate reconnaissance, generate targeted spearphishing with better return on investment, mount larger volumes of attacks, and produce polymorphic payloads that evade signature-based detection. Wilson draws a direct parallel to criminal enterprises optimizing for financial return: they will adopt every automation shortcut available, including agentic AI, because it is economically rational for them to do so. The UK National Cyber Security Centre’s annual report, which Wilson references from her time working there, shows a doubling of the most significant incidents, underscoring that the statistical evidence supports what practitioners are experiencing in the field.

“They are an enterprise, they’re a financially motivated enterprise and they are going to take the shortcuts they can with using agents and using AI to speed up spearfishing.”

Lauren Wilson, Field CTO, Splunk

Q: What specific agentic AI capabilities does Splunk provide for detection engineering and threat hunting?

Wilson describes Splunk’s agentic capabilities as giving Level 1 and Level 2 analysts access to Level 3 forensic skills they may never have developed otherwise. The analogy she uses is a virtual SOC teammate, available immediately, trained to handle complex investigative tasks that previously required years of specialist development. In the triage and detection space, agents optimize the human analyst’s workflow rather than replace it, operating under a human-in-the-loop model. Catching threats earlier in the kill chain, at reconnaissance rather than at deployment, directly reduces both operational impact and the financial and reputational costs of a successful incident.

“Some of the capabilities that we’re bringing, those agents are giving level one, level two analysts capabilities that they would may never have achieved in their careers.”

Lauren Wilson, Field CTO, Splunk

Q: How does Splunk use machine learning to cut through alert noise and surface real incidents?

Wilson traces Splunk’s approach to alert reduction back to its foundational competency in machine learning applied to disparate data sources, which predates the current generative and agentic AI cycle. The core capability is correlating context across fragmented telemetry to find the signal inside the noise, an evolution of what Splunk has always done with data. Agentic AI augments that machine learning core rather than replacing it. Wilson notes that the organization’s risk appetite and sector determine how aggressively they tune, and Splunk’s approach accommodates both high-sensitivity and high-specificity configurations.

“We know data, we know how to surface insights through that context from the disparate information. And that’s what we’ve always done and that’s what we’re really good at.”

Lauren Wilson, Field CTO, Splunk

Q: How does the Splunk and Cisco integration improve detection of low-and-slow and living-off-the-land attacks?

Wilson explains that the most sophisticated modern attacks are designed to avoid the noisy indicators that legacy detection was built around. Living-off-the-land attacks require correlation across geography, network layer telemetry, user behavior, and endpoint data simultaneously. Because the network is the primary flow of information in any enterprise, deep integration with Cisco’s network visibility layer gives Splunk access to telemetry that no security-only vendor can replicate. The result is a more complete picture of the attack surface, enabling detection of the subtle, slow-moving patterns that indicate a sophisticated intrusion rather than a commodity attack.

“We have to maximize all the context, all the telemetry and events that the enterprise is creating. And if we have tight integration with the main flow of information around an organization that is the network, that’s just going to surface those alerts in even better, more streamlined way.”

Lauren Wilson, Field CTO, Splunk

Q: How does Splunk keep AI agent decisions transparent, auditable, and grounded rather than acting as a black box?

Wilson reframes the black-box concern by mapping agent governance directly onto the governance frameworks already applied to human SOC analysts. HR policies, training mandates, operational constraints, and least-privilege access controls all exist to ensure analysts operate within defined boundaries. The same logic applies to agents: scope their access to only what they need for a specific task, restrict the information they can act on, and audit their decisions the same way analyst actions are reviewed. Wilson argues that the discomfort around agent autonomy is not fundamentally different from the discomfort of granting a new SOC analyst elevated permissions, and the same risk management principles resolve both.

“We just need to treat the agents as we would the humans and make sure that they only have least privilege, they only have access to what they absolutely need to get their job done.”

Lauren Wilson, Field CTO, Splunk

Q: Should security operations be fully autonomous or human-led, and where do CISOs actually draw the line?

Wilson is direct that full autonomy is not where most enterprises are, or should be, today. The model she advocates is incremental: identify a well-documented, well-tested playbook, such as isolating a single compromised laptop, automate that one process, measure the outcome, and use that experience to calibrate trust in agents for progressively more complex tasks. She explicitly contrasts this with the cloud adoption rush, where organizations moved fast without sufficient assessment, noting that the security industry is showing more restraint with agentic adoption. Different use cases carry different risk tolerances: automating isolation of a standard user endpoint is a different risk calculus than automating action on a CEO’s device.

“It is probably less exciting and kind of just identifying the SOC overnight. But trust is the gap that we’re seeing between organizations being ready to kind of take that big step.”

Lauren Wilson, Field CTO, Splunk

Q: Is the skepticism toward AI in security operations a regional or cultural phenomenon, or do CISOs globally share the same caution?

Wilson distinguishes between anti-AI sentiment and what she calls cautious AI adoption, framing the latter as a healthy and rational response to delegating authority to an unfamiliar system. She notes that the discomfort in giving authority to an agent is not categorically different from the discomfort of delegating to a human in a high-stakes environment; the agent dimension simply makes it more visible. Regulatory conversations and government policy debates around AI responsibility are, in her view, a positive signal that the industry is processing the risk thoughtfully rather than rushing adoption. The global security community is broadly aligned on this caution regardless of regional political posture toward AI.

“I don’t think that’s necessarily anti AI, I think that’s just cautiously AI. And I think that’s healthy.”

Lauren Wilson, Field CTO, Splunk

Q: What does a successful agentic SOC look like in two to five years, and how is success measured?

Wilson anchors the answer in MTTX, the family of mean-time metrics covering detection, analysis, investigation, response, and recovery. The goal of the agentic SOC is to compress each stage of the incident response lifecycle so that incidents that cannot be prevented at least do not translate into operational downtime. She ties this directly to Cisco’s digital resilience strategy, which Splunk’s platform is built to enable. Success, in her framing, is not a single metric reduced to zero but rather SOC teams that are confident in the choices they have made about where agents operate and satisfied with the overall quality of their security operations. Industry risk tolerance varies, but the MTTX reduction trajectory is universal.

“It’s not just reducing a particular metric to zero, it’s the SoC being comfortable with the overall satisfaction of their operations.”

Lauren Wilson, Field CTO, Splunk

Resources & Documentation

  • Splunk, security information and event management platform with agentic AI, machine learning-based detection, and SOAR capabilities
  • Cisco, network infrastructure and security telemetry partner providing deep network visibility integrated with Splunk
  • UK National Cyber Security Centre, annual threat landscape reporting referenced by Wilson for incident trend data

***

👇 Click to Read Full Raw Transcript

Swapnil Bhartiya: Now, in this age of AI, the security teams are kind of drowning in, of course, alert fatigue, burnout. And new attackers are using AI to move faster. And the attacks are also becoming more and more sophisticated. Trusting a black box to fight back, it looks like impossible. But the answer is, Splunk says, is not in less AI, it’s more in smarter and govern autonomy. And here at Splunk we have with us Lauren Wilson Field CTO at Splunk. Who knows what CISOs and SOCs go through day to day. First of all, Lauren, it’s great to have you on the show.

Lauren Wilson: Thank you for having me.

Swapnil Bhartiya: It’s my pleasure. Let’s talk about what are CISOs and SOC leaders are dealing with every day when it comes to whole burnout, alert fatigue, and also the whole skepticism around black box AI. And then we’ll talk about how Splunk is addressing that.

Lauren Wilson: I suppose the tension that operational leaders have today is that they still have a job to do right now. They’re still receiving however many alerts. It depends on the size of the organization. But they are drowning, like you say, in alerts, and that’s not going away. And I think something we struggle with in cybersecurity is what we kind of call keeping the lights on. The operational need to do business every single day and catch every single attack to keep the bad guys away. But also, we’re trying to navigate a huge landscape change where we’re trying to transform how we’ve done security operations and move that into an agentic reality where we have capability that’s going to keep up with what the future looks like. And that future is getting nearer as well. So organizations are battling the priorities of how do we continue to keep that fight up, but also how do we prioritize looking at technology and how it can help us do things better? Because that’s not just. It doesn’t happen overnight. These are transformation programs that organizations have got to go through, and operational leadership has got to be given the time and the space to be able to kind of push forward some of that advancement. But they need it and they want to do that. And we see that the real demand for how technology, and particularly we’re going to go into AI. We can’t avoid the use of agentic AI for the future solution, which, like you say, with the speed, the scale, and the sophistication of the threat actors, which we say threat actors, the number of people that are conducting cyber incidents these days has kind of exploded. We are not just seeing the most sophisticated people anymore. That capability is in the hands of people that wouldn’t have dreamt of being able to do such attacks. And we need to have that same principle in mind. When we think about SOC analysts today, how do we give them the best technology to keep up with what the threat is seeing? And I often reflect that when we think about cybercrime, I think it’s one of the way to kind of caricature what the threat that we’re against. They, of course they’re going to use technology to help them do their job. They are an enterprise, they’re a financially motivated enterprise and they are going to take the shortcuts they can with using agents and using AI to speed up spearfishing, targeting a spearfish to have the best return on investment. They’re going to be using automation to mount more attacks, to mount more sophisticated attacks. So why aren’t we doing the same for our defenders? The kind of security challenge that we’ve seen over the years now and obviously Splunk have the technology and the capability answering that need that we’ve seen that demand signal from the industry.

Swapnil Bhartiya: When it comes to cybersecurity, I always say that it’s not a product, it’s always a process. Right. It’s like cat and mouse number two, is that as good guys you have to be right 101% time, bad guys have to be right only once. So it’s not even an even playing field. Now the incentives are also different, right. Some are state sponsored for totally different also. Now the attacks are also becoming more sophisticated. Earlier it was low hanging fruits. Now it’s also because the way we are using, also because of agentic AI where agents can take actions. Now you can have an image, I can look at the image, it’s just an image. But when you put an AI agent to scan that image with OCR, suddenly that may be instructions for the agent to run a code. And since you are autonomously. So can you also talk about how this is. Not even three things are happening now. The scale at which you can operate and capability of putting in the hands of people who otherwise, you know, it was a billion dollar industry, you know, the whole, you know, but now anybody can do that. And third is the sophistication. So what are you seeing right now where you’re like, you know what? This is not what we saw two years ago.

Lauren Wilson: Yeah. And I think it’s all three. I think we can’t, sophistication and speed and scale like I mentioned and I think it is that trifecta of all those three advancing so quickly that we are seeing organizations need for more sophisticated capability, their own requirements to scale. But like you say, we’re comparing criminal enterprises versus actual enterprises and the landscapes that they’re operating in is very different. So we’re tooling the defenders in a way that they need to keep up. And I think when we look at where the attack landscape has shifted, I think it is just the amount of attacks. I think, like you say, if there’s more capable threat actors trying to do our organizations harm, of course they’re going to get in more times than not. And I used to work for the National Cyber Security Centre in the UK and their annual report that they put out every year gives a real insight into what the threat landscape looks like from their perspective. And the statistics, the stats that they’ve pulled this year, the doubling of the most significant incidents they’re seeing just supports the fact that that scale and the sophistication of those attacks are on the rise and not going anywhere.

Swapnil Bhartiya: And also now attackers are using AI to automate reconnaissance and also launch polymorphic attack. So talk a bit about how, if you look at, now we have talked about the problem area, let’s talk about the solution area a bit. If you look at Splunk’s agentic skills in area like, of course, detection engineering as well as threat hunting, what kind of edge it gives to defenders so they can catch these threats before they happen. Because once it has happened, now you are in damage control mode, damage is done.

Lauren Wilson: Yeah, and we always say about shifting left in terms of security design, but also the more expensive the incident becomes, the later you catch it in the kill chain. Right. So if you can catch them at the reconnaissance stage, again, that’s both an operational impact will be less, but also the financial reputation costs of all the other hardships that come with a successful incident getting all the way to deployment. And I think thinking about some of those agents that we have introduced and thinking back to my days as operating as an analyst, I loved to have what I almost envisaged as kind of my SOC best friend, this teammate that sat with me virtually, of course. But I mean, back in the day, it used to be a colleague, a mentor, somebody that used to help you through those difficult tasks in the SOC, as you’re learning how to learn the full breadth of the skills that you need in a SOC. And I often have the thought around as an analyst, I was very much Level one, level two, I never had level three capability, skills. I’m not an expert in deep forensics, but some of the capabilities that we’re bringing, those agents are giving level one, level two analysts capabilities that they would may never have achieved in their careers. And it’s there, right there for them to use. And we’re very much about, human in the loop and augmenting the SOC analyst and that capability that we’re providing, be that in the triage space or detection, it’s just optimizing and augmenting the human in a way that we know the attackers are doing. So we need the capability in the hands of the defenders.

Swapnil Bhartiya: And now let’s talk about the cause of fatigue. The SOC team, they lose hours in triaging false positive across fragmented tools. Let’s talk about Splunk’s native AI agents and how they cut through all this noise and surface real incidents at machine speed.

Lauren Wilson: Yeah. So again, like the needle in the haystack, that’s what the SOC analysts are often hunting for. But also the risk appetite for different organizations, depending on the sector, depending on the industry, depending on the tuning of their SIEM and their apparatus that they have in cyber defence means that for many, many, many years, they’ve been surfacing more rather than less. They’d rather see everything and tune out than see nothing and potentially have the ramifications of a successful attack. So the capability again. And we often talk about AI as kind of new emerging thing and it is in the kind of generative and the agentic sense. But thinking back to kind of machine learning, which is something that Splunk’s been doing for many years, we know data, we know how to surface insights through that context from the disparate information. And that’s what we’ve always done and that’s what we’re really good at. So whilst we’re continuing to do that, we’re doing it in a better way with that augmentation of agentic. But the machine learning that we’ve been doing for many years, that’s still the heart of what we do.

Swapnil Bhartiya: And when you combine Splunk with the whole Observatory and Cisco, because networking is where no matter what you do, everything goes through the pipe. So you have that visibility that no one else has and companies would like to have. So can you also talk about how that puts you folks in a unique position to address some of these security challenges?

Lauren Wilson: You’re right. And I think that’s where we have started to see the attack landscape shift. Attacks often used to be seen as these very noisy things that of course you’re going to spot. But we’ve seen more sophisticated threat actors looking at the kind of low and slow, living off the land type attacks where you have to do that correlation. You have to look at all different parts of the network, not just user logs. Look at the geography, the network layer, all the different telemetry available. To be able to really see the more sophisticated attacks. We can’t just look at the traditional security apparatus that we used to have. We have to maximize all the context, all the telemetry and events that the enterprise is creating. And if we have tight integration with the main flow of information around an organization that is the network. So if we are deeply embedded and being able to consume that data better than anybody with that partnership with Cisco, that’s just going to surface those alerts in even better, more streamlined way.

Swapnil Bhartiya: Now let’s talk about other problem areas. One is of course, hallucination. That is kind of part of what AI you cannot separate from that. And second is the whole black box decisions. Let’s talk about how does Splunk’s governance and policy agents know? They try to keep those kind of actions transparent, auditable and grounded in real SOPs.

Lauren Wilson: And I think we kind of expect agents to operate in this kind of almost perfect way, but I think we’re best actually extrapolating that thinking and thinking around what we’re expecting of our humans today. And that’s just what we need to apply to agents. So our SOC analysts have HR policies, they have training mandates, they have all the kind of policies that exist to make sure that they are well trained, they understand the constraints in which they can operate. And we just need to apply that same logic to agents. So it sometimes feels like it’s quite unwieldy. And they say the black box, but what decisions are they making? That’s no different than a human today. That’s no different to a SOC analyst that’s been given the keys to the kingdom, potentially in a SOC that could do and automate and do different actions, that’s just the same as the agent. So when we think about what user access for a human, it’s exactly the same as kind of the agentic access or the access the agent’s got. So I think sometimes we get caught up in almost this sci-fi nature of, the black box, this dark art, but actually if we strip it back to basic risk management and risk assessment principles, then we just need to treat the agents as we would the humans and make sure that they only have least privilege, they only have access to what they absolutely need to get their job done and only give them information they should know, like we would a brand new SOC analyst that walks through the door on their day one.

Swapnil Bhartiya: And since you have brought human in loop, let’s also talk about one of the big debate, which is fully autonomous security versus human led security. What you are seeing in a field where we are, of course we need trusted autonomy, where AI is doing all the heavy lifting, but then we also have humans in governance. So the big decisions are made by humans.

Lauren Wilson: Yeah. And again, I’m in the field, I spend a lot of my time talking to CISOs, CXOs, organizations who are trying to make this a reality. And it’s our job as vendors to be pushing the art of the possible. We’ve got the technology, we’ve got the capabilities and the brains in Splunk and Cisco to be able to bring these new features to bear. But actually making that a reality in complex organizations and in enterprises is a different conversation. So just because we’re pushing something today, there’s always going to be that lag with organizations being able to fully adopt this technology. And keeping human in the loop is a part of that. It’s how can we build trust over time. How can we take a small process in the SOC and automate it? And I run readiness workshops with CISOs and we’ll sit down and we’ll talk about, okay, so let’s take one of your processes because often we talk about the SOC like it is just this one entity that does a job. It’s not, it’s separate. Different personas, different people, different tasks, different specialisms. From triage to some of the specialist skills in forensics and malware. It’s the incident coordination, the ability to coordinate major incidents. That’s something that is potentially less ready for agentic operations. But there’s some stuff that we’ve been doing for years, like playbooks. So organizations have got really good at writing down SOPs and playbooks for how they run incidents. That’s something that’s documented and well optimized, that’s kind of almost ready for that lift and shift. Can we take maybe low hanging fruit? An isolated laptop incident where I got a single user with some malware. We know what the playbook should look like, we’ve been running that playbook. Our analysts have been using that successfully for some months, years now. Why don’t we try that as a test case? Let’s give an agent some level of automation to that particular use case. And that builds trust in the operation of using agents. But also it allows leaders and the analysts that are interacting with agents to have more trust in maybe thinking about moving some of the longer term, more complex tasks to agents. But as cliche as it is, it’s as much a trust journey as it is a technology journey. And how organizations are best placed to build that trust is incremental: taking well-trodden processes, automating them and being happy with the outcome. And it is probably less exciting than identifying the SOC overnight. But trust is the gap that we’re seeing between organizations being ready to take that big step. And I think that shows real maturity in our industry. I compare it back to the cloud transformation where we all rushed to go on the cloud because that was the new thing. And we’re not doing that with the agentic space. We’re not seeing organizations rushing to have an agentic SOC overnight because they’re showing that restraint. They’re showing that actually, what can we do with agents? What should we or shouldn’t do with agents? Just because we could. Is that what we want to do? And I think breaking it down by process, by parts of the business. A good example: a user’s laptop is very different to a CEO’s laptop. Would you want the agent overnight to be isolating that device? Maybe, maybe that’s your risk appetite internally. But taking specific use cases and then applying some automation is the only way organizations can test the internal organizational boundaries of where agents should or should not be part of their security workflows.

Swapnil Bhartiya: You travel globally, you have also seen different regions. I used to live in Europe. They have different opinions about AI. The adoption of AI is also different. So when we look at this whole kind of anti-AI view, if you look at it globally, because security is a space where you cannot have one region fully prepared for AI attacks and one team not prepared at all. What are you seeing globally? Not the adoption of AI in general, but when it comes to security, when it comes to CISOs, when it comes to SOC teams, do you also see that their view, their opinion of AI in security is same as we see in the political landscape or is it a bit different where they all look at AI and security from the same lens?

Lauren Wilson: And I think it’s just what I mentioned there around that skepticism that we have and I think that’s healthy. I don’t think that’s necessarily anti AI, I think that’s just cautiously AI. And I think when you talk about giving that trust or that delegating authority to somebody else, that’s an uncomfortable conversation about a human to a human, never mind a human to an agent, something they are at the moment still learning about. And I think it’s healthy and I think we need to continue those conversations about risk and government powers and regulation. It’s a hot topic across the globe about where the responsibility lies. And I think the fact that we are having those conversations is healthy and it is a real positive step. And critical challenge is part and necessary of any kind of global transformation, which we welcome.

Swapnil Bhartiya: Last question. Looking ahead, what would success look like for SOCs that fully embraced trusted autonomy when it comes to AI, with human-led decision making? How do you envision that world?

Lauren Wilson: Yeah. I think for me, what the agentic SOC of the future will look like is that human augmentation. It’s the ability to pick and choose which parts of the SOC you want to automate and where they make the most sense. Because having agentic capability where it matters, where speed is really important, is key. I talk a lot about digital resilience and it’s a key Cisco strategy, but also it’s what Splunk, at its core, is trying to achieve, helping organizations be digitally resilient. And I talk a lot about MTTX. So the ability to reduce the time from incident happening to operational impact, to then recovering from that incident. We know that incidents happen all the time, they shouldn’t always have operational impact. There are steps that organizations can take to avoid operational impact. So how we can detect quicker, how we can analyze, investigate and respond quicker, really shorten that lifecycle of finding the bad thing and getting the business back to where it should be as it was pre-incident. So I think where I see the agentic SOC in the next two, three, maybe five years, it’s doing what we can to start really shortening those different elements of the incident response lifecycle and that’s helping organizations maintain that digital resilience which customers and stakeholders are demanding. There’s no tolerance now for downtime in most organizations operating in public-facing services. So the way that we can try and apply that identification to the SOC to shorten the downtime, extending to observability, how do we use agents to get there? That’s going to be different for different industries, different risk tolerances. But organizations being happy they’ve made the right choices around agents and trusting agents, I think that’s what success looks like. It’s not just reducing a particular metric to zero, it’s the SOC being comfortable with the overall satisfaction of their operations.

Swapnil Bhartiya: Anything else from your perspective that you feel like we should talk about that as well, or you feel that we touched on all the key points that you wanted to discuss today?

Lauren Wilson: No, I think we’ve covered everything. I think trust is at the centre of all this and when it comes to implementing the great technologies that we’re pushing out, we appreciate that organizations have to come on that trust journey with us. So doing that in a way that feels sensible to them, we’re here, we use our partners, we sit down with the CXOs and really help them understand what that agentic SOC looks like for them. Because I sometimes worry that they see the flashing lights and this kind of future and they look at their own internal security operations today and think, wow, we’re so far away from that today. So I really pride myself on helping CXOs make that a reality, building the roadmaps with them, starting slow and starting incrementally to get them to that point. Because yes, we need the agentic SOC today to keep up with the pace of innovation and change in the threat landscape. But it’s still a journey and we’re not ignorant to that fact.

Swapnil Bhartiya: Thank you so much for joining me and talking about the whole landscape. For those who are watching, if you want to learn more about Splunk’s agentic workflows, please go ahead and check out splunk.com. Lauren, thank you for your time and I look forward to talking with you again.

Lauren Wilson: Thanks so much.

Why AI Workloads Fail Without Data Service Orchestration | Julian Fischer, anynines | TFiR

Previous article