...

Zscaler Unveils Agentic SOC to Contain AI-Driven Threats by Unifying Exposure Management and SOC Workflows

Zscaler

Zscaler, Inc. (NASDAQ: ZS), the cybersecurity platform for the AI era, announced Zscaler Agentic SOC. The new approach aims to reduce security exposures and strengthen modern security operations. It also helps security teams scale their expertise while stopping AI-driven attacks at machine speed.

Zscaler designed Agentic SOC specifically for today’s rapidly changing threat environment. Traditional security stacks cannot keep pace by simply adding more AI capabilities. Therefore, Zscaler built its security operations approach around an AI-first architecture.

The solution combines security operations center workflows with exposure management capabilities. It uses Zscaler telemetry and specialized AI agents to detect, investigate, and respond to threats. As a result, security teams can accelerate threat detection and automate critical response actions.

“The past year has made one thing clear: AI attacks are fundamentally changing the threat landscape, operating at a speed, scale, and level of adaptability that looks very different from traditional human-led activity,” said Allie Mellen, principal analyst and author of Code War: How Nations Hack, Spy, and Shape the Digital Battlefield. “To defend effectively, organizations must double down on the fundamentals Zero Trust principles, preventing data exfiltration, limiting access, and making AI attacks as expensive as possible.”

Addressing the Growing Speed of AI-Driven Attacks

Today’s attackers increasingly rely on speed, stealth, and evasive techniques. AI-driven threats can move faster than SOC teams can manually correlate and analyze security signals. Threatlabz, Zscaler’s global research team, continues to identify increasingly evasive attack methods. These methods include using trusted websites to host attacks. Attackers also abuse legitimate remote management tools and browser-based attack techniques.

Zscaler Agentic SOC addresses these challenges through several integrated capabilities. The platform combines Zscaler telemetry with the world’s largest decoy mesh network. It also uses expert-validated agents and integrated Zscaler Zero Trust controls. Additionally, the platform works with customers’ existing third-party security controls. This combination helps teams identify threats earlier. It also enables automated containment at machine speed.

Zscaler has partnered with leading frontier AI labs to strengthen Agentic SOC. These partners include Anthropic and OpenAI. Zscaler integrates their frontier models with its proprietary threat intelligence and zero trust telemetry. This approach allows Zscaler to deliver AI agents with deeper reasoning capabilities. It also supports improved accuracy and greater explainability. Furthermore, the combined approach goes beyond traditional threat detection.

Zscaler’s open platform enables direct integration with frontier models. Security teams can also bring vulnerability findings into their existing SOC workflows. They can then operationalize those findings through integrated security processes. This collaboration supports Zscaler’s focus on using advanced AI technologies. The company aims to combine speed, reliability, and transparency for security operations.

“AI-driven attacks are moving faster than traditional SOC models were ever designed to handle,” said Deepen Desai, Executive Vice President of Cybersecurity at Zscaler. “Agentic SOC is a fundamental rethinking of security operations, built with agentic capabilities at its core to reduce exposures proactively, extend human expertise with AI agents and contain threats at machine speed. With unmatched inline telemetry, specialized AI agents and closed-loop remediation, Zscaler is giving security teams the visibility and control they need to outpace modern attackers.”

Zscaler Differentiates Its SecOps Approach

Zscaler Agentic SOC brings exposure management and threat defense together. The platform connects proactive attack surface reduction with reactive threat protection. This unified approach provides additional context during security investigations. Consequently, teams can prioritize risks and accelerate protection.

Zscaler also provides extensive zero trust telemetry through its inline architecture. The company captures network, identity, endpoint, cloud, and AI insights. The platform processes 750 billion daily zero trust transactions. Security teams can use this telemetry for real-time detection and response.

Zscaler has also developed specialized AI agents using frontline security experience. These agents draw from more than 10 years of SOC experience. That experience includes managed detection and response and threat-hunting operations. Zscaler continuously tunes its agents using threat intelligence from thousands of customer environments worldwide. The platform also supports closed-loop inline remediation. Zscaler can automatically contain threats using native inline security controls.

For example, the platform can isolate compromised users. It can also block command-and-control communications and restrict lateral movement. Moreover, integrations with third-party tools give customers additional response options. These integrations support more nuanced actions against active threats.

“Our team was drowning in alert noise, forcing top analysts into triage instead of proactive threat hunting,” said Andrea Liccardi, Sr. Cybersecurity Manager, Maire Tecnimont. “Zscaler Agentic SOC gives us full attack-path context using telemetry we already had in place, helping our team move from fragmented signals to faster, more informed decisions. Zscaler has proven to be one of our most valuable cybersecurity partners, continuously helping us improve operational efficiency, visibility, and our ability to focus our analysts on what really matters.”

Open Platform Integration Strengthens Security Workflows

Zscaler Agentic SOC integrates with customers’ existing security ecosystems. The platform pulls third-party data into its workflows to provide broader risk and threat context. It can also trigger automated outbound actions across connected security tools. Therefore, organizations can proactively address exposures and contain active attacks.

The platform focuses on connecting security intelligence with automated response. This approach helps security teams reduce manual processes and improve operational efficiency.

Key Zscaler Agentic SOC Capabilities

Data-rich context graph: The platform correlates real-time zero trust telemetry against third-party data. Then it makes a map and prioritizes complex incident chains. This allows security teams to investigate threats with more operational context. It also enables faster analysis of interrelated security events.

Expert AI agents: Autonomous agents for dedicated security operations tasks These tasks include triage, root-cause analysis, assigning verdicts and starting response workflows. This alleviates the burden of analyst workloads for security teams. They can also speed up their defensiveness to new threats.

Advanced Detections Powered by Frontline Threat Intelligence Zscaler leverages rich telemetry and deep threat research to expose advanced attacks. The goal is to detect these threats earlier and more accurately.

Continuous threat hunting and expert assistance: Zscaler blends AI-driven speed with human security expertise. Zscaler and Red Canary security experts provide seasoned judgment on threat-hunting activities. Together, these factors enable organizations to strike a balance between automation of tasks and the preservation of human supervision. It aids security teams in investigating ever more sophisticated attacks. 

Global Availability of Zscaler Agentic SOC

Zscaler Agentic SOC is available worldwide today. Learn more in Zscaler’s global launch webinar and related resources. The company continues to build its cybersecurity capabilities with an AI focus. Its Agentic SOC approach integrates AI agents, threat intelligence, zero trust telemetry and automated remediation.

These capabilities are designed to help security teams respond to threats faster. They also give organizations additional tools to manage security risks driven by AI. 

For related updates on digital trust and cybersecurity, explore our SOC News.

News Source: GlobeNewswire