Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Monday, 15 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

From Playbooks to Adaptive Workflows: How MSSPs Are Evolving Security Operations with Agentic AI

by Lara Joseph
June 15, 2026
in Featured
Check Point Expands MSP Platform with AI Security Capabilities and Unified Bundles
Share on FacebookShare on Twitter

Tim Leehealey is the Co-founder and VP of Strategy at Strike48

Agentic AI is starting to show up in security operations in a very specific place, and it’s not in detection. It’s appearing in the part of the workflow where analysts are working out what an alert actually means, and deciding what to do next. That’s the part that doesn’t always follow a clean path, even in well-structured SOCs, and it’s also where most of the variation tends to sit.

If you look at how performance is usually measured, speed still dominates. Time to detect, time to triage, time to respond. Those metrics are easy to track, and they give a sense that the system is working as intended. What they don’t capture particularly well is how consistent those responses are. In practice, two alerts can move through the workflow at roughly the same speed and still be handled differently. One might be escalated earlier, another investigated more deeply, or handled with a different level of confidence depending on who is reviewing it.

None of those differences are necessarily wrong, but they introduce variation and are more noticeable as operations scale. That variation tends to sit in the same place every time. It shows up in the decision layer, where analysts are interpreting signals and applying judgement based on the context in front of them. Even with strong processes and playbooks, that step isn’t fully defined. It depends on experience, familiarity with the environment, and how closely a situation matches something that’s been seen before.

As environments grow and MSSPs take on more clients, the number of these decision points increases, and so does the challenge of keeping them aligned. Processes can guide what should happen, but they can’t fully standardise how decisions are made. This is where agentic AI begins to change how that layer operates. Instead of leaving context gathering and interpretation entirely to the analyst, agentic systems build that into the workflow itself. As alerts move through triage, the system is already correlating signals, pulling in relevant history, and structuring the context in a consistent way.

By the time a decision needs to be made, the starting point is much more aligned across the team. That doesn’t remove judgement, but it changes how that judgement is applied. Analysts are no longer approaching each alert from scratch. They are working from a shared foundation, where the key signals and relevant context have already been surfaced in a way that reflects how similar situations have been handled before. Over time, that reduces the variation between analysts and makes outcomes more predictable.

“Consistency in security operations is often treated as an operational objective, but in practice it has governance implications. When similar situations are handled in materially different ways, it becomes difficult to demonstrate control over risk, particularly at an executive level. What boards increasingly require is confidence that decisions will hold up under scrutiny, regardless of where they occur. Supporting that level of consistency is not simply about process, it is about ensuring that decision-making aligns with how risk is understood across the organization,” says Keven Knight, CEO of Talion Cyber Security.

You start to see the impact of this in how the workflow behaves over time. Decisions begin to follow more consistent patterns, not because the process has become rigid, but because the inputs to those decisions are more aligned. The need to revalidate or escalate simply to confirm interpretation reduces, and analysts are able to move through triage with greater confidence.

For MSSPs, that shift is particularly important. Operating across multiple clients introduces constant variation, and maintaining consistency across those environments is one of the harder parts of scaling. By supporting the decision layer directly, agentic AI allows that consistency to be built into how the workflow operates, rather than relying on individual experience to hold it together. That’s what begins to change how performance is measured.

This shift becomes harder to ignore. Consistency stops being something teams hope to maintain and becomes something that is actively built into how the workflow operates. That changes how performance is understood, and more importantly, how it holds up as environments become more complex. In that sense, agentic AI is not just improving decision-making, it is redefining how consistency is achieved in security operations.

ShareTweet
Previous Post

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

Recent News

Check Point Expands MSP Platform with AI Security Capabilities and Unified Bundles

From Playbooks to Adaptive Workflows: How MSSPs Are Evolving Security Operations with Agentic AI

June 15, 2026
Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol