Agentic AI Is Forcing SOCs to Rethink How Security Work Actually Gets Done
Because Even the Most Mature SOCs Are Constrained by the Limits of Human Attention, Which Is a Challenge That Is Becoming More Acute Across Asia Pacific

Modern security operations centres (SOCs) in Asia Pacific are like control rooms overlooking a sprawling megacity—every alert, every data point, every device adds another layer to monitor. As cities grow vertically and digitally, so too does the complexity of enterprise systems, demanding security tools that can keep up with this growth.
Even the most mature SOCs are constrained by the limits of human attention—a challenge that is becoming more acute across Asia Pacific as digitalisation, AI adoption and regulatory complexity continue to accelerate.
Agentic AI continues to challenge those constraints. Not because it is simply “better automation,” but because it introduces a fundamentally different way of organising security work. As cybersecurity investment across Asia Pacific continues to grow, projected to rise at a CAGR of 10.6% and reaching USD $60.6 billion by 2028. At the same time, many SOCs are discovering that adding more tools or point AI features only compounds pressure, demanding a new and different operational approach.
Agentic systems offer that approach: one where autonomous agents operate at machine speed, while humans shift from task execution to system supervision.
Redefining the Role of the Human in Autonomous SOCs From Doing to Directing
The most significant shift is not technological but organisational. Traditional SOCs are built around task execution. Analysts investigate alerts step by step, following playbooks and escalating decisions as needed. Agentic systems invert this model. Agents execute workflows autonomously, while humans define guardrails, set policies, validate outcomes and intervene when judgement is required.
This elevates the analyst role rather than diminishing it. Instead of manually performing every investigative step, analysts begin orchestrating how agents collaborate.
This shift is happening at the executive level, where according to Splunk’s latest CISO Research, 47.1% of Singapore CISOs have become responsible for AI governance and risk management in the last one year. This is a clear signal that intelligent systems are becoming a core security mandate. As the CISO portfolio expands into including AI policy, governance committees, and cross-functional accountability, so will SOC teams evolve in tandem.
As execution becomes more automated, traditional signals of experience begin to shift. Entry-level analysts may appear more capable more quickly, not because they are more seasoned, but because agents accelerate execution across the board. In response, SOC leaders are beginning to rethink career paths—creating more strategic roles focused on supervising agents, tuning workflows and managing long-term security programmes.
This evolution naturally leads to a broader question: as security work changes, how should SOC performance itself be measured?

Why Legacy Metrics No Longer Tell the Full Story
As the nature of work changes, so too must the way SOCs measure success. For years, mean time to respond (MTTR) has been the dominant performance metric. But in an environment where agents can detect, investigate and neutralise issues before they escalate into incidents, time-based metrics start to lose meaning.
If an autonomous system prevents an incident altogether, what exactly is being “responded” to? In mature agentic environments, MTTR may even increase—not because performance is worsening, but because what remains requires deeper human judgement.
Forward-looking SOCs are shifting toward outcome-based measures: reductions in false positives, precision of autonomous triage, risk avoided rather than risk remediated, and alignment to business outcomes such as downtime prevented or financial loss avoided. These metrics better reflect what agentic systems actually deliver—continuous insight and resilience, rather than limiting to faster cleanup.
When performance is framed around avoided risk and operational resilience, security becomes easier to justify and integrate into broader enterprise priorities.
From Isolated Assistants to Multi-Agent Ecosystems
Early AI adoption in security often took the form of isolated assistants embedded within individual tools. While useful, these systems remained siloed. Agentic AI pushes SOCs toward coordinated, multi-agent ecosystems that can share context, reason together and act across platforms.
Instead of analysts switching between a SIEM, an endpoint console and a cloud dashboard — each with its own AI feature—networks of agents can move fluidly across environments. Open standards and shared context allow agents to sequence tasks, exchange insights and form a unified view of risk.
The benefits of these changes are already visible in Asia Pacific. According to Splunk’s 2025 State of Security report, SOCs in Singapore report faster incident response (62%) and when leveraging unified platforms. They are also less likely to experience significant challenges from dispersed tools (11%, compared to 24%).

AI Readiness and the Need for Accountability
As both attackers and defenders adopt autonomous systems, SOCs are also beginning to embrace continuous adversarial simulation. Autonomous red-team agents can probe defences, stress-test detection logic and surface weaknesses long before a real attack occurs. AI readiness both against AI-powered threats and AI-driven defence becomes a living discipline rather than a periodic exercise.
At the same time, increased autonomy raises important questions about accountability. As agents investigate, correlate and respond, SOCs must be able to explain not just what actions were taken, but why. Rich audit trails, transparent reasoning paths and clearly defined oversight boundaries become essential.
Agents effectively function as new digital identities, requiring the same governance applied to users and applications. With the right controls, auditability and autonomy can reinforce each other—building trust among analysts, leaders and regulators alike.
Redesigning SOCs for an Agentic Future
Agentic AI does not replace human judgement—it reshapes where and how that judgement is applied. The SOCs that succeed will not be those that simply “use AI,” but those that redesign how security work gets done: shifting from task execution to system supervision, from speed-based metrics to outcome-based ones, and from fragmented tools to connected ecosystems.
In this new model, humans set intent, context and boundaries. Agents handle scale, repetition and speed. Together, they form a security operation that is more resilient, more intelligible and ultimately more sustainable for the people who run it.



