The Strategic Problem Is Bigger Than Automation Rate
Security leaders are being asked how much of the SOC can be automated. That is still the wrong first metric. Automation rate says little about whether signals were connected correctly, whether the right attack path was prioritized, or whether the response matched the evidence before a high-impact action occurred.
Mandiant's M-Trends 2026 report, based on more than 500,000 hours of frontline investigations conducted in 2025, describes adversary pacing as a key differentiator across cybercriminal, espionage, and insider activity. [1] The strategic implication is simple: the SOC cannot treat every alert as an isolated unit when the attacker is moving through a connected sequence.
Four Jobs Determine Whether Autonomous Defense Scales
-
Correlate the path. A reviewer should understand which signals, identities, assets, and behaviors belong to the same attack sequence without rebuilding the investigation manually.
-
Prioritize the branch. The decision record should show why one branch deserves action now, including impact, privilege, progression, and evidence strength.
-
Match action to confidence. When confirmation is required, the record should show who confirmed, rejected, changed, or overrode the proposed response and when.
-
Preserve the outcome. The organization should be able to compare the proposed action with the executed action and its observed result, including rollback or corrective steps.
Correlation Must Be Operational, Not Decorative
Vectra AI's January 2026 platform announcement describes a defense model built around connected visibility and attack behavior across the AI enterprise. [2] Those are vendor-published capability statements, not independent performance evidence. The useful design idea is that context should follow the attacker across domains rather than forcing analysts to stitch together isolated product views.
That distinction matters because a fast verdict can still be weak evidence. A useful correlation should point back to telemetry, identity, asset, behavior, and sequence so that an analyst can challenge the connection rather than simply trust the score.
Shared Data Becomes Part of the Response System
Fortinet's June 2026 FortiSOC description says its platform normalizes, enriches, and correlates telemetry from network, endpoint, cloud, and identity sources on a shared data pipeline before detections and workflows act on it. [3] That is vendor architecture, not a universal prescription, but it illustrates the operating principle: defense gets faster when investigation and response work from the same context.
Current Autonomous-Defense Models Combine Reasoning With Predictable Execution
Fortinet's September 2026 FortiSOAR 8.0 announcement combines agentic AI with automation playbooks, positioning dynamic reasoning alongside predictable orchestration and explicit controls. [4] Mandiant's March 2026 AI risk and resilience report likewise argues that AI is both an attacker accelerator and a defender force multiplier. [5] These are vendor and provider perspectives, but together they show why autonomous defense needs both flexible analysis and controlled execution.
CyberTech Intelligence Correlation and Action Matrix
Figure 1. CyberTech Intelligence Correlation and Action Matrix
|
Defense Job |
Executive Decision |
Operational Expression |
Evidence |
|---|---|---|---|
|
Correlate |
Can a reviewer see which signals belong to the same attack path? |
Cross-domain path linked to supporting telemetry and context. |
Signals, sequence, identity, asset context, uncertainty. |
|
Prioritize |
Which active branch creates the most material risk now? |
Impact, privilege, progression, confidence threshold. |
Priority record, confidence, evidence basis. |
|
Decide |
Can the action execute automatically or does it need confirmation? |
Consequence-tiered route with named decision owner. |
Proposed action, decision, timestamp, override. |
|
Execute |
What was actually changed? |
Bounded action, command, workflow, or control step. |
Executed action, target, result, rollback state. |
|
Review |
Can the organization learn from the outcome? |
Post-action review, exception handling, control adjustment. |
Outcome, lessons, next review. |
CyberTech Intelligence Perspective
The credibility of autonomous defense will depend less on how quickly it reacts and more on how well it connects evidence to action. Speed matters, but speed without shared context creates operational debt. The durable model links cross-domain evidence to prioritization, a confidence threshold, controlled execution, and post-action review.
Strategic Recommendations
-
Define the minimum evidence set required before each class of automated response.
-
Require correlation to remain traceable to underlying telemetry, identities, assets, and sequence.
-
Separate dynamic AI reasoning from the mechanism that executes high-impact changes where practical.
-
Protect action logs, correlation evidence, and overrides as part of the incident evidence chain.
-
Review automation after meaningful changes in data sources, tools, permissions, models, or response scope.
-
Measure correlation quality, evidence completeness, override quality, and rollback success alongside speed.
Use the Correlation and Action Review Matrix
Select three workflows that can change identities, endpoints, cloud controls, or external communications. Map each through correlation, prioritization, confidence, execution, and review. Identify where the organization cannot yet connect the attack path, justify the action, reconstruct execution, or evaluate the outcome.
About CyberTech Intelligence
CyberTech Intelligence provides research-led cybersecurity intelligence, executive content, and market engagement programs. This publication is vendor-neutral and intended for education, decision support, and claim-safe GTM planning.
Evidence and Citation Note
External research is used only within its stated scope. Incident-response research supports observations about adversary pacing; vendor material is used only for the vendor's stated architecture or capabilities, not as independent proof of universal performance. CyberTech Intelligence does not infer an incident, defense gap, buying project, or business outcome for any named organization without direct evidence.
References
- Google Cloud / Mandiant, “M-Trends 2026: Data, Insights, and Strategies From the Frontlines,” March 23, 2026. https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026 (Accessed September 24, 2026. Relevance: frontline incident-response research based on more than 500,000 hours of Mandiant investigations conducted globally in 2025.)
- Vectra AI, “Vectra AI Launches Next-Generation Platform to Secure the AI Enterprise with Preemptive and Proactive Defense,” January 21, 2026. https://www.vectra.ai/about/news/vectra-ai-launches-next-generation-platform (Accessed September 24, 2026. Relevance: vendor-published example of cross-domain AI-native security positioned against AI-powered attacks; capability and outcome language remains attributed to Vectra AI.)
- Fortinet, “Introducing FortiSOC: One Platform, Total Control,” June 16, 2026. https://www.fortinet.com/blog/security-operations/introducing-fortisoc-one-platform-total-control (Accessed September 24, 2026. Relevance: vendor-published shared-data architecture for correlating network, endpoint, cloud, identity, detection, and response workflows.)
- Fortinet, “FortiSOAR 8.0 Unites Agentic AI and Automation to Revolutionize Security Operations,” September 14, 2026. https://www.fortinet.com/uk/blog/security-operations/fortisoar-8-unites-agentic-ai-and-automation-to-revolutionize-security-operations (Accessed September 24, 2026. Relevance: vendor-published architecture combining agentic AI, playbooks, governance, autonomous investigation, and controlled orchestration.)
- Google Cloud / Mandiant, “AI risk and resilience: A Mandiant special report,” March 9, 2026. https://cloud.google.com/security/resources/ai-risk-and-resilience (Accessed September 24, 2026. Relevance: Mandiant analysis of operationalized adversarial AI use, AI-enabled attack speed, and AI as a defensive force multiplier.)