LIVE NEWS
  • At least six killed in Kyiv as gunman opens fire and takes hostages
  • What Is Q-Day? The Quantum Threat to Bitcoin Explained
  • Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
  • My Friend Was 40 Years Older Than Me. She Changed How I See Life.
  • ‘No regrets’: Venezuela’s Machado defends giving Nobel medal to Trump | Donald Trump News
  • Stocks Soar on Middle East Peace Prospects
  • Air Force unit executes test of Anduril’s semiautonomous combat drone
  • 700-year-old mummy from Bolivia contains earliest confirmed evidence of strep throat bacteria in the Americas
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»How Agentic AI Can Boost Cyber Defense
Cybersecurity

How Agentic AI Can Boost Cyber Defense

primereportsBy primereportsDecember 5, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
How Agentic AI Can Boost Cyber Defense
Share
Facebook Twitter LinkedIn Pinterest Email


Cyberattack activity has increased to the point where even the largest of security analyst teams can no longer effectively measure the accuracy and quality of their investigations without some form of automation. For some organizations, relying on agentic artificial intelligence models that triage alerts and score severity and work alongside security operations center (SOC) analysts could be a viable option.  

Global roadway operator Transurban is among the early adopters of virtual agents to address the common issue of SOC operators facing a growing volume of threats that have become more sophisticated. Muhammad Ali Paracha, Transurban’s head of cyber defense, discussed how his team implemented agentic AI models as part of the Transforming the Future of Cyber Defense with Agentic AI presentation at the Black Hat Middle East conference in Riyadh, Saudi Arabia, this week. Paracha explained the challenges he faced, the technology implemented, plans moving forward, and how AI improved efficiencies in the organization’s security governance process. 

Paracha tells Dark Reading that alert volumes had become so overwhelming that Transurban’s SOC analysts were triaging 8% of the tickets generated. Senior analysts would enter data into Excel spreadsheets at the end of the month and find that the information in some tickets was not accurate, “so they sent them back to the analysts, but tickets were closed by that time,” Paracha says.

Related:CrowdStrike to Acquire Onum, Boost Falcon Next-Gen SIEM

Hiring more security analysts wasn’t feasible due to the expense and difficulty of hiring and retaining them. Consequently, at the beginning of this year, Paracha and his security and development team developed and trained an agentic AI system based on large language models (LLMs) that enabled automated agents to assist with handling security tickets. The developers trained two agents to perform quality checks, ensuring improved real-time accuracy of all security events.

After evaluating various LLM modeling options, Transurban decided to use Anthropic’s Claude. Paracha says Transurban chose Claude because it integrated well with its Splunk SIEM, ServiceNow ticketing system and AWS Bedrock, the managed AI service for hosting foundation models like Claude. 

The agentic AI model was designed in-house to traverse all incident and resolution nodes, ensuring incidents are handled within the respective playbooks. The model consists of two agents: one for categorizing incidents and another for verifying the resolution notes before closing tickets. The first agent reviews the fields of incident tickets, ensuring they are all categorized correctly, while the second agent resolves an incident before it is closed, Paracha explains. However, the agent doesn’t close tickets; instead, it sends the summary back to the human security analyst to address the suggested issues. Then, the agent model verifies that the problem has been rectified before closing the incident. 

Related:Mideast, African Hackers Target Gov’ts, Banks, Small Retailers

Paracha says that the models, which were extensively tested before deployment, provide 100% coverage of all incidents while maintaining a false positive rate of less than 3%.  Since deploying it in September, alert triage times have been reduced by 60%, with an accuracy rate of 92%. 

Adhering to service-level agreements and cyber response playbooks is essential at Transurban, which manages the operations of 22 toll roads in its home country of Australia, as well as some in the United States and Canada. Cyber resilience is vital because it has deployed technology on the roadways it manages that can affect traffic flow. 

“Human safety is the most critical factor for us,” Paracha says. 

Paracha says his team has only scratched the surface of what agentic AI can do to automate the entire mean time to detect (MTTD) and mean time to respond (MTTR) process. Plans call for expanding the system to incorporate external threat intelligence and automating triage and response processes using Anthropic’s Model Context Protocol (MCP) server to integrate with other systems. 

Related:Commentary Section Launches New, More Opinionated Era

Transurban is adding external threat intelligence and building solutions that will be integrated with the MCP server, Paracha says.  He adds the next phase will be to automate the triage process, then add automated response, “so if we have to contain any impacted systems or networks, we can rely on agentic AI to make intelligent decisions and contain the systems as well.”

Paracha says that while these capabilities are relatively new, he believes they will quickly gain traction, which aligns with Omdia’s Cybersecurity Decision Maker Survey 2025. According to Omdia’s forecast, autonomous SOCs could reach full potential and become standard for CISOs within two years. 

“Agentic AI is a rapidly maturing technology that SecOps teams are embracing as SOCs quickly become laboratories for advanced AI implementation,” noted Andrew Braunberg. “This adoption is revolutionizing operations more dramatically than any innovation since Next gen-SIEM platforms emerged.”

 



Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAdvance Trustworthy AI and ML, and Identify Best Practices for Scaling AI 
Next Article Residents spend night away from Derby homes after major incident
primereports
  • Website

Related Posts

Cybersecurity

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

April 18, 2026
Cybersecurity

Google wipes out 602 million scam ads with Gemini on duty

April 18, 2026
Cybersecurity

The surveillance law Congress can’t quit — and can’t explain

April 17, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20258 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20264 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • At least six killed in Kyiv as gunman opens fire and takes hostages
  • What Is Q-Day? The Quantum Threat to Bitcoin Explained
  • Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.