LIVE NEWS
  • Global economy must stop pandering to ‘frivolous desires of ultra-rich’, says UN expert | Environment
  • Some Middle East Flights Resume but Confusion Reigns From Iran Strikes
  • Clinton Deposition Videos Released in Epstein Investigation
  • Elevance stock tumbles as CMS may halt Medicare enrollment
  • Wild spaces for butterflies to be created in Glasgow
  • You can now adjust how your caller card looks for calls on Android phones
  • TRON DAO expands TRON Academy initiative with Dartmouth, Princeton, Oxford, and Cambridge
  • Alex Mitchell: England scrum-half ruled out of Six Nations
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»How Agentic AI Can Boost Cyber Defense
Cybersecurity

How Agentic AI Can Boost Cyber Defense

primereportsBy primereportsDecember 5, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
How Agentic AI Can Boost Cyber Defense
Share
Facebook Twitter LinkedIn Pinterest Email


Cyberattack activity has increased to the point where even the largest of security analyst teams can no longer effectively measure the accuracy and quality of their investigations without some form of automation. For some organizations, relying on agentic artificial intelligence models that triage alerts and score severity and work alongside security operations center (SOC) analysts could be a viable option.  

Global roadway operator Transurban is among the early adopters of virtual agents to address the common issue of SOC operators facing a growing volume of threats that have become more sophisticated. Muhammad Ali Paracha, Transurban’s head of cyber defense, discussed how his team implemented agentic AI models as part of the Transforming the Future of Cyber Defense with Agentic AI presentation at the Black Hat Middle East conference in Riyadh, Saudi Arabia, this week. Paracha explained the challenges he faced, the technology implemented, plans moving forward, and how AI improved efficiencies in the organization’s security governance process. 

Paracha tells Dark Reading that alert volumes had become so overwhelming that Transurban’s SOC analysts were triaging 8% of the tickets generated. Senior analysts would enter data into Excel spreadsheets at the end of the month and find that the information in some tickets was not accurate, “so they sent them back to the analysts, but tickets were closed by that time,” Paracha says.

Related:CrowdStrike to Acquire Onum, Boost Falcon Next-Gen SIEM

Hiring more security analysts wasn’t feasible due to the expense and difficulty of hiring and retaining them. Consequently, at the beginning of this year, Paracha and his security and development team developed and trained an agentic AI system based on large language models (LLMs) that enabled automated agents to assist with handling security tickets. The developers trained two agents to perform quality checks, ensuring improved real-time accuracy of all security events.

After evaluating various LLM modeling options, Transurban decided to use Anthropic’s Claude. Paracha says Transurban chose Claude because it integrated well with its Splunk SIEM, ServiceNow ticketing system and AWS Bedrock, the managed AI service for hosting foundation models like Claude. 

The agentic AI model was designed in-house to traverse all incident and resolution nodes, ensuring incidents are handled within the respective playbooks. The model consists of two agents: one for categorizing incidents and another for verifying the resolution notes before closing tickets. The first agent reviews the fields of incident tickets, ensuring they are all categorized correctly, while the second agent resolves an incident before it is closed, Paracha explains. However, the agent doesn’t close tickets; instead, it sends the summary back to the human security analyst to address the suggested issues. Then, the agent model verifies that the problem has been rectified before closing the incident. 

Related:Mideast, African Hackers Target Gov’ts, Banks, Small Retailers

Paracha says that the models, which were extensively tested before deployment, provide 100% coverage of all incidents while maintaining a false positive rate of less than 3%.  Since deploying it in September, alert triage times have been reduced by 60%, with an accuracy rate of 92%. 

Adhering to service-level agreements and cyber response playbooks is essential at Transurban, which manages the operations of 22 toll roads in its home country of Australia, as well as some in the United States and Canada. Cyber resilience is vital because it has deployed technology on the roadways it manages that can affect traffic flow. 

“Human safety is the most critical factor for us,” Paracha says. 

Paracha says his team has only scratched the surface of what agentic AI can do to automate the entire mean time to detect (MTTD) and mean time to respond (MTTR) process. Plans call for expanding the system to incorporate external threat intelligence and automating triage and response processes using Anthropic’s Model Context Protocol (MCP) server to integrate with other systems. 

Related:Commentary Section Launches New, More Opinionated Era

Transurban is adding external threat intelligence and building solutions that will be integrated with the MCP server, Paracha says.  He adds the next phase will be to automate the triage process, then add automated response, “so if we have to contain any impacted systems or networks, we can rely on agentic AI to make intelligent decisions and contain the systems as well.”

Paracha says that while these capabilities are relatively new, he believes they will quickly gain traction, which aligns with Omdia’s Cybersecurity Decision Maker Survey 2025. According to Omdia’s forecast, autonomous SOCs could reach full potential and become standard for CISOs within two years. 

“Agentic AI is a rapidly maturing technology that SecOps teams are embracing as SOCs quickly become laboratories for advanced AI implementation,” noted Andrew Braunberg. “This adoption is revolutionizing operations more dramatically than any innovation since Next gen-SIEM platforms emerged.”

 



Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAdvance Trustworthy AI and ML, and Identify Best Practices for Scaling AI 
Next Article Residents spend night away from Derby homes after major incident
primereports
  • Website

Related Posts

Cybersecurity

Samsung Unpacked 2026 live blog: Updates on Galaxy S26 Ultra, preorder deals, and pricing

February 25, 2026
Cybersecurity

Marquis sues SonicWall over backup breach that led to ransomware attack

February 25, 2026
Cybersecurity

Why ‘Call This Number’ TOAD Emails Beat Gateways

February 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20255 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20264 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Global economy must stop pandering to ‘frivolous desires of ultra-rich’, says UN expert | Environment
  • Some Middle East Flights Resume but Confusion Reigns From Iran Strikes
  • Clinton Deposition Videos Released in Epstein Investigation
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.