Sep 08 2026
Security

CrowdStrike Fal.Con 2026: Is Your SOC Ready for AI Agents?

As attackers continue to evolve techniques and strategies, defenders must be able to respond at machine speed. The agentic security operations center might be the answer.

Artificial intelligence is dramatically reducing the amount of time it takes an attacker to compromise an organization’s security. And cybersecurity leaders recognize the need to match that speed by appropriately arming their security operations centers (SOCs).

According to CrowdStrike’s 2026 Global Threat Report, “The average eCrime breakout time” — the period between initial access and lateral movement onto another system — “dropped to 29 minutes, a 65% increase in speed from 2024.”

At last week’s CrowdStrike Fal.Con, CrowdStrike President Michael Sentonas told attendees at a keynote session, “I will argue that the breakout time is over. Think about what that means. We now live in a world where a model finds a vulnerability and weaponizes it at the same time.”

“You’re not going to be scanning vulnerabilities and spending weeks to think about where to deal with an issue,” he continued. “There’s no gap left to measure. There’s no window. We’re living in a world where the breakout time is zero.”

Click the banner below to read the recent CDW Cybersecurity Research Report. 

 

Reduced Breakout Time Demands an Agentic SOC

For security teams to keep up with their adversaries, it’s becoming clear they must enable AI agents within the SOC. “We need to start to move to investigations at machine speed,” Sentonas said. “This is why the old SOC model is broken in many ways.”

Current models frequently involve separate human agents tackling endpoint security, identity security and cloud security. When an attacker has the capability to move in minutes or less, organizations can’t afford to spend hours on an investigation. That’s where the agentic SOC comes in.

With an agentic SOC, there would still be agents working on endpoint, identity and cloud security. But they would work simultaneously and collaboratively, speeding up the process because they’re sharing memory and information.

“No handoffs, no waiting, no starting over,” Sentonas said. “That’s the difference between a collection of agents and an agentic SOC. Not working independently, but working together in that shared space, giving you the ability to stay in control.”

DISCOVER: Find out how mature your security posture is with a self-assessment.

CrowdStrike Is Already Helping Organizations Create Agentic SOCs

According to Austin Murphy, vice president of managed services at CrowdStrike, “We started working on our agentic workflows over a year ago.”

“The agents that are powering the agentic SOC are created by Falcon Complete because it’s what we’ve been using behind the scenes for us, and now there’s an opportunity to expand the number of customers that can benefit from what we’ve built to help ourselves become more efficient, more consistent,” Murphy said.

Murphy anticipates that the agentic SOC will change the roles of defenders and the ways they interact with agents. He referenced the often-repeated phrase “human in the loop,” which he said means that “agents can only take you so far, and then it escalates to a human to finish up if it ever gets stuck.”

But he also mentioned “human on the loop,” which is a concept he said CrowdStrike is working on internally. He noted that the current state of AI was trained on data produced when humans were performing the work. “Well, if they stop performing the work, we’re going to lose the data to train the next version. So, when we refer to human on the loop, we have a human analyst parallel working the same detection that an agent does.” This approach allows CrowdStrike to perform data comparisons between the human and the agent and continually maintain and improve the agents.

Michael Sentonas headshot
There’s no gap left to measure. There’s no window. We’re living in a world where the breakout time is zero.”

Michael Sentonas President, CrowdStrike

How Can the Agentic SOC Benefit a Security Team?

Murphy said he envisions agents allowing human analysts to delegate some of their normal tasks to an investigative harness, transforming the analyst role into more of a managerial position. “Instead of actually doing log analysis, you’re directing the log analysis,” he explained. “You’re directing the work instead of running the actual work. It’s still the same discipline, it’s just more of a supervisory role.”

Murphy added that agents will also allow analysts to work at the next level up, addressing some of the skills gaps that have persisted in the cybersecurity workforce for years. Analysts who are skilled at writing a particular type of query or working in one language can rely on agents to elevate their abilities.

He admitted that some traditional analysts are responding to the use of agents differently. “There’s a lot of apprehension, but what we find is that kind of melts away when the analysts start in good faith interacting with some of the technology. That quickly turns into excitement.”

Despite some initial reservations about AI potentially eliminating jobs, familiarity with the technology can ease those concerns. Once analysts start working with agents, they frequently discover “it just means that I can do my job faster,” Murphy said. “I don’t have to be doing seven tasks one after another. I can have these seven tasks be done at the same time, and I’m working at a higher level.”

Photography by Joe Kuehne
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.