Elastic Proposes 'Agentic SOC' to Shield Air-Gapped Defense Networks
Sean MacKirdy argues that disconnected national security environments must adopt AI agents to counter the rise of automated adversaries.
National security and defense agencies must overhaul their Security Operations Centers (SOCs) to integrate agentic AI or risk falling behind adversaries who are already using AI to accelerate attacks. Sean MacKirdy, AVP of National Security at Elastic, argues that traditional defense models are no longer sufficient for air-gapped environments.
MacKirdy proposes a transition to an "agentic SOC," a model where AI agents handle the burden of routine triage and context assembly. By automating these foundational tasks, the model allows human analysts to evolve into "threat engineers," shifting their focus from manual data gathering to high-level strategic judgment. This approach is designed to maintain strict model sovereignty and data control, ensuring that sensitive information remains secure within disconnected environments while leveraging the speed of artificial intelligence.
The Erosion of the Air Gap
Air-gapped environments were traditionally viewed as the gold standard for security because they are physically disconnected from the public internet. However, this isolation has become a double-edged sword. While it protects against some external threats, it also restricts defenders from using modern, cloud-based AI security tools. This creates a critical capability gap: adversaries use AI to automate complex campaigns, while defenders in disconnected environments remain tethered to manual processes and outdated tools.
The perceived safety of physical isolation is further undermined by a surge in supply-chain vulnerabilities. According to data cited by MacKirdy, supply-chain compromises have nearly quadrupled since 2020, providing new vectors for attackers to breach even the most isolated systems.
The Speed of Modern Warfare
The urgency for this shift stems from the shrinking window between the discovery of a vulnerability and its exploitation. As AI lowers the barrier for malicious actors to conduct automated attacks, the speed of defense must match the speed of the offense. MacKirdy emphasizes the necessity of this evolution, stating, "If you are not using AI to defend against AI, the adversary has already closed the gap."
For national security agencies, the consequence of inaction is a heightened vulnerability of their most sensitive missions. Without agentic AI, these organizations cannot match the operational tempo of modern threats, rendering physical isolation an insufficient defense.
The Path Forward
Moving toward an agentic SOC requires a fundamental rethink of the security workforce. The goal is to move away from a structure reliant on a large base of entry-level analysts and toward a leaner, more specialized team of engineers supported by AI agents.
As defense agencies evaluate these tools, the primary challenge remains implementing these capabilities without compromising the strict data sovereignty required for classified environments. The industry will be watching to see how these agentic frameworks are deployed in real-world, disconnected settings to prove they can stop AI-driven threats in real time.