Blog | October 5, 2026
How agentic AI turns SOC overload into stronger defense
By Michael Baker, Global Chief Information Security Officer, DXC Technology
Blog | October 5, 2026
By Michael Baker, Global Chief Information Security Officer, DXC Technology
Most security leaders don't lack ambition or budget. What they lack is time. Their teams face thousands of alerts every day, and many lead nowhere. In its 2025 Detection and Response Survey, SANS found that 73% of security teams name false positives as their single biggest detection challenge. When skilled analysts spend their shifts separating noise from signal, the threats that matter get less attention than they deserve.
That's the low-key crisis inside the modern security operations center (SOC). It rarely makes a breach headline, yet it shapes how well an organization can defend itself. For the C-suite, the real question isn't whether to add more people or buy more tools. It's how to give the people they already have room to do their best work.
For years, the industry framed its talent problem as a numbers game. That framing is shifting. In its 2025 Cybersecurity Workforce Study, ISC2 found that skills gaps now outweigh raw headcount as the top workforce concern, with 59% of organizations reporting critical or significant skills shortages, up from 44% a year earlier. Hiring more analysts helps, but it doesn't fix a model that burns out experienced people on repetitive work. SOC alert fatigue is real: team members can become overwhelmed and start to lose confidence in their ability to respond appropriately to them.
The AI security operations center is where AI earns its spurs. Attackers already use AI to automate reconnaissance, sharpen phishing and orchestrate campaigns. Defenders need to keep pace with capabilities such as automated alert investigation. Gartner now counts AI-driven security operations among its top cybersecurity trends for 2026. Its analysts expect more than 75% of enterprises to use AI-amplified cybersecurity products by 2028, up from less than 25% in 2025. The direction is set, and the advantage will go to leaders who deploy AI with discipline rather than bolt on another disconnected tool.
At DXC, we tested this in our own SOC before recommending it to clients. Protecting DXC's global estate of more than a million devices generates an unremitting stream of alerts, and our analysts were spending as much as 80% of their time reviewing false positives and routine cases. So we made operations the proving ground and became Customer Zero for the DXC Agentic SOC, powered by 7AI.
The results changed how our teams spend their days. With agentic AI security operations in place, agents now handle roughly 100% of alert triage; time to acknowledge a ticket has fallen by 68%; and triage and investigation time has dropped by 90%. Triage accuracy sits above 95%, documentation is consistent and audit-ready across every shift and the approach has returned more than 225,000 hours of analyst time to the business. Reliance on Tier 1 analysts for routine triage fell to zero, freeing them for threat hunting and higher-value analysis.
Those numbers matter, although outcomes matter more. No analyst wants to stare at a screen for 12 hours parsing false alarms. When agents carry that load around the clock, people move to work machines can't do, including creative problem solving and complex decisions under pressure. Running the service in production also sharpened it, because our teams reviewed investigations and fed what they learned back into how the agents reason. Across a wider set of customer environments, the platform has since processed more than 100,000 security alerts in production.
Speed alone isn't the point. Leaders need a repeatable way to bring AI into operations without gambling on an unproven, enterprise-wide rollout. Our answer is a simple discipline: start small, scale fast. We launch focused pilots, prove value, then expand what works.
That discipline is codified in DXC Xponential , our framework for orchestrating AI across people, processes and technology with governance built in from the start. It sits alongside DXC OASIS, our AI-native platform that gives leaders a real-time view across their IT estate and keeps every agent action traceable. In cybersecurity, the agents run in a dedicated layer and their findings flow into OASIS, so cyber and IT operations share one picture and the path from detection to remediation operates at machine speed.
The pattern travels well beyond security. At Textron, for example, DXC used AI-powered automation to cut service desk tickets by 20% and resolve matters proactively for 32,000 employees.
None of this works without the people it's meant to help. DXC research makes the tension plain: 77% of leaders call AI a board-level priority, yet 94% run into serious challenges scaling it. That gap is rarely about the technology; it's about trust, communication and change.
Human monitoring continues to be essential as agents take on more. Human in the loop cybersecurity ensures there is someone there to set the guardrails, review the edge cases and decide when a situation calls for judgment rather than automation. Leaders who get this right treat AI as a career accelerator rather than a threat to jobs. They redeploy people to increasingly meaningful work, invest in new skills and hold honest conversations about where careers go next. Our research points the same way, with 81% of leaders expecting AI to increase demand for cybersecurity and data talent by 2028.
The trait that separates teams that thrive from those that struggle with AI is curiosity. Technical depth still counts, though the analysts who experiment, ask questions and connect security to business value are the ones pulling ahead.
The execution gap is closing, and waiting has real costs because competitors and adversaries are moving faster. The practical path is to pick one high-volume, low-judgment workflow in your SOC, deploy agents against it, measure the outcome and scale what proves itself. Keep people in the loop, keep governance visible and let early wins build the case for more.
Security leaders who take this step gain more than faster response times. They build teams that are more resilient, more engaged and better placed to defend the business against rapidly escalating threats.
That's the real return on agentic AI, and it's within reach for any leader willing to get started.
Michael Baker is global chief information security officer at DXC Technology. He is an accomplished cyber security executive who brings more than two decades of experience in the field across cyber leadership, talent development, risk management, audit and compliance serving the aerospace and defense industry as CISO along with a variety of clients across industries as a seasoned consultant.