CISO Roundtable to Weigh Risks and Rewards of Autonomous SOCs
Security leaders meet September 15 to discuss the shift from AI-assisted tools to autonomous agents capable of independent remediation.
The cybersecurity industry is approaching a critical inflection point as it moves from AI-assisted tools toward fully autonomous security operations centers (SOC). To address the implications of this shift, The New Stack is hosting a CISO roundtable on September 15, 2026, focusing on the balance between operational efficiency and the risks of automated disruption.
The event will bring together 20 to 25 security leaders to discuss the transition to autonomous SOCs. Confirmed participants include Jami Hughes, Deputy CISO at Zions Bancorporation, and Oren Saban, Co-founder and CPO of Mate Security and former product lead for Microsoft Defender XDR and Security Copilot. To encourage candid sharing of both successes and failures, the session will operate under the Chatham House Rule.
The Push for Autonomy
For years, SOCs have been plagued by "alert fatigue," where the sheer volume of security threats exceeds the capacity of human analysts to respond. While previous AI implementations focused on assisting humans, the current trend is toward autonomous agents that can independently investigate and remediate threats. This acceleration is largely a response to the evolving threat landscape, as attackers increasingly leverage AI to speed up their own operations, forcing defenders to operate at "AI speed" to remain effective.
The Trust Equation
This transition fundamentally alters the role of the security professional, shifting the SOC analyst from a primary investigator to an orchestrator of AI systems. However, granting AI agents the authority to take disruptive actions—such as isolating endpoints or disabling user accounts—introduces significant business risk. The industry must now solve the "trust equation," determining how to maintain business continuity while allowing AI to act. Key considerations include the necessity of human-in-the-loop overrides and the ability to rapidly undo automated decisions that may cause unintended outages.
Future Outlook
As the industry moves forward, the primary challenge will be integration. There is a growing concern that the current vendor race to add agent capabilities could leave organizations with a fragmented collection of AI-enabled products rather than a cohesive, continuous system. The goal for many leaders is a "continuous detection and response" model, where the traditional silos of detection, investigation, and response are merged into a single, automated workflow. Whether organizations can achieve this without sacrificing stability remains the central question for the upcoming roundtable.