Zscaler Launches Agentic SOC to Defend Against AI-Driven Threats
Zscaler launches Agentic SOC with specialized AI agents, zero trust telemetry, and automated threat containment to defend against AI-driven attacks.
Zscaler has launched Zscaler Agentic SOC, a new security operations approach designed to help organizations detect, investigate, and contain AI-driven cyber threats at machine speed. The platform combines specialized AI agents, zero trust telemetry, threat intelligence, and automated response capabilities to strengthen AI-powered threat defense and reduce the pressure on security operations teams.
Zscaler Introduces an AI-First Security Operations Model
AI-driven attacks are becoming faster and more adaptive, creating challenges for security teams that rely heavily on manual investigation and remediation. Zscaler says attackers are increasingly using evasive techniques, including trusted websites, legitimate remote management tools, and browser-based attacks.
Zscaler Agentic SOC addresses these challenges by combining security telemetry with specialized AI agents that can analyze threats, investigate incidents, and initiate response actions. The platform is designed to move security operations beyond alert detection toward more proactive exposure reduction and automated threat containment.
Rather than simply adding AI capabilities to existing security products, Zscaler has positioned Agentic SOC as an AI-first approach to security operations. The company aims to help security teams respond to threats at a speed that matches increasingly automated attacks.
Combining AI Agents With Zscaler Telemetry
A key component of Agentic SOC is the security data available through Zscaler's Zero Trust platform. Zscaler says its infrastructure processes more than 750 billion daily zero trust transactions, generating telemetry across network, identity, endpoint, cloud, and AI environments.
Agentic SOC uses this telemetry to provide security teams with additional context when investigating potential threats. The platform can combine Zscaler data with information from third-party security tools, helping organizations build a broader view of an attack and its potential impact.
This approach is designed to reduce the fragmentation that often forces analysts to move between multiple security tools during investigations.
Specialized AI Agents Handle SOC Tasks
Zscaler Agentic SOC uses specialized AI agents to perform different security operations tasks. These agents can assist with alert triage, root-cause investigation, threat verdicts, and response workflows.
The company says the agents have been trained and continuously refined using more than a decade of frontline SOC, managed detection and response, and threat-hunting experience. Their development also draws on threat intelligence collected across thousands of customer environments.
By assigning specific responsibilities to individual agents, Zscaler aims to reduce repetitive workloads for security analysts. Teams can then spend more time on complex investigations, threat hunting, and strategic security activities.
Anthropic and OpenAI Models Power Agentic SOC
Zscaler is also working with leading AI companies to support its Agentic SOC platform. The company has partnered with Anthropic and OpenAI, integrating their frontier AI models with Zscaler's proprietary threat intelligence and zero trust telemetry.
According to Zscaler, combining multiple advanced AI models with specialized security data can provide deeper reasoning, accuracy, and explainability than relying on a single model or approach.
The company's open platform approach also allows security teams to integrate frontier AI models and operationalize vulnerability findings within existing SOC workflows.
This strategy reflects the growing importance of specialized AI systems in cybersecurity, where general-purpose models need security-specific context to investigate complex incidents effectively.
Data-Rich Context Graph Connects Security Signals
Agentic SOC includes a data-rich context graph designed to correlate real-time Zscaler telemetry with third-party security information.
The graph helps map relationships between different signals and build a clearer picture of complex incident chains. Security teams can use this context to prioritize risks, investigate threats, and understand how different events may be connected.
For organizations dealing with large volumes of security alerts, stronger contextual analysis can help analysts distinguish meaningful attack activity from isolated or lower-priority events.
Automated Threat Containment at Machine Speed
Another major component of the platform is closed-loop remediation.
Zscaler says Agentic SOC can use native inline controls to automatically contain threats. These controls can isolate compromised users, block command-and-control communications, and restrict lateral movement.
The platform can also integrate with customers' third-party security tools to provide additional response options. This enables organizations to combine Zscaler's native controls with existing security infrastructure when responding to active threats.
Automating these actions can reduce the time between detecting a threat and taking defensive action. This is increasingly important as AI-assisted attacks can move faster than traditional human-led security processes.
Connecting Exposure Management and Threat Response
Zscaler is positioning Agentic SOC as more than a conventional security information and event management or security orchestration platform.
The company is bringing proactive exposure management and reactive threat defense together within the same approach. This allows organizations to identify weaknesses before attackers exploit them while also investigating and containing active threats.
By connecting these processes, security teams can gain greater context around why a vulnerability matters and how it relates to active attack activity.
Continuous Threat Hunting With Human Expertise
Although Agentic SOC automates multiple security tasks, Zscaler is not removing human expertise from the process.
The platform combines AI-driven analysis with threat-hunting expertise from Zscaler and Red Canary security professionals. This model is designed to combine the speed of AI agents with the judgment and experience of cybersecurity specialists.
This combination can be particularly valuable for sophisticated attacks that require deeper investigation or decisions based on broader threat intelligence.
Reducing Alert Overload for Security Teams
Security analysts often face large volumes of alerts that require investigation and prioritization. Excessive alert noise can force experienced analysts to spend much of their time on initial triage rather than proactive threat hunting.
Zscaler says Agentic SOC is designed to address this challenge by providing broader attack-path context and automating parts of the investigation process.
Andrea Liccardi, Senior Cybersecurity Manager at Maire Tecnimont, said the platform helped the company's team move from fragmented security signals toward faster and more informed decisions.
The goal is to allow analysts to focus their expertise where it provides the most value while AI agents handle repetitive and time-sensitive tasks.
Open Integration With Existing Security Tools
Organizations rarely replace their entire security infrastructure when adopting a new security platform. Zscaler has therefore designed Agentic SOC to work with existing security ecosystems.
The platform can ingest third-party data and use that information to provide additional context for threats and vulnerabilities. It can also trigger automated outbound actions through integrated tools.
This open approach gives organizations greater flexibility when building their security operations strategy while reducing the need to operate isolated security systems.
Zscaler Builds on Its Agentic AI Strategy
The launch of Agentic SOC builds on Zscaler's broader efforts to extend zero trust security into the AI era.
Earlier in 2026, Zscaler introduced additional capabilities for securing AI agents, including Zscaler AI Broker, an Agent Registry, Endpoint AI Security, and AI Access Graph. These technologies are designed to help organizations understand agent identities, control access, and track relationships between AI agents, applications, identities, and data.
Zscaler has also introduced its ZAgent Framework to support agentic administration across its Zero Trust SASE platform. The framework is intended to automate security management tasks such as configuration, troubleshooting, root-cause analysis, and policy validation.
The latest Agentic SOC announcement expands that strategy from securing AI systems to using AI agents directly within security operations.
Preparing Security Operations for AI-Driven Attacks
The rapid development of AI is changing both sides of the cybersecurity equation. Organizations are using AI to improve productivity and automate business processes, while attackers can also use AI to increase the speed and scale of malicious activity.
This creates pressure on security teams to improve their ability to identify and contain threats without relying entirely on manual processes.
Zscaler Agentic SOC is designed around this requirement by combining specialized AI agents, large-scale telemetry, threat intelligence, zero trust controls, and automated response capabilities.
Zscaler Targets Faster and More Autonomous Cyber Defense
Zscaler's Agentic SOC represents a broader shift toward autonomous security operations. Instead of relying solely on analysts to correlate alerts, investigate incidents, and initiate containment, the platform assigns specialized AI agents to perform portions of those workflows.
The combination of Zscaler's telemetry, frontier AI models from Anthropic and OpenAI, threat intelligence, and native zero trust controls gives the company a foundation for automating more security operations.
As AI-driven attacks become more sophisticated, organizations will need security systems that can operate at comparable speed. Zscaler's latest platform is designed to address that challenge by helping security teams reduce exposures proactively, investigate threats more efficiently, and contain attacks through automated controls.
With Zscaler Agentic SOC now available globally, the company is positioning agentic technology as a central part of the next generation of security operations.
SOC News provides the latest updates, insights, and trends in cybersecurity and security operations.
Read related news - https://soc-news.com/ai-powered-fraud-prevention-mobileum-and-apate/
0 comments
Log in to leave a comment.
Be the first to comment.