Authored By Salleh Kodri, Regional Director, Solutions Engineering, ASEAN, Cyble
For the last decade, cybersecurity has spent a lot of energy trying to solve a visibility problem. We wanted more logs. More telemetry. More threat intelligence. More detection rules. More dashboards. And to be fair, we got them.
Today, many organisations have SIEM, EDR, NDR, attack surface management, identity security, vulnerability management, cloud security and multiple threat intelligence sources. The average SOC can probably see more of its environment than at any point in the past.
Yet incidents still happen where, afterwards, somebody inevitably asks: “Did we already have the indicators?”
Quite often, the answer is yes.
That tells me the next cybersecurity problem is not simply visibility.
It is decision latency. Seeing something is one thing. Understanding what it means, deciding what matters and taking the right action before the situation changes is something else entirely. And Agentic AI is about to make that gap much more obvious.
We Are Crossing a Speed Threshold
There is a lot of discussion right now about AI-powered cyberattacks. I think we need to be careful with the hype. AI does not suddenly make every traditional attack technique obsolete, nor does it mean tomorrow’s attacker will be an entirely autonomous machine. The more immediate change is simpler.
AI compresses time.
Reconnaissance can become faster. Target discovery can become faster. Vulnerability analysis can become faster. Social engineering can become personalised at a scale that was previously difficult. Infrastructure can be analysed, changed and replaced faster. And increasingly, AI systems can help determine what to do next. Agentic systems take this one step further because they are designed around a loop:
Observe -> Reason -> Decide -> Execute -> Reassess
Potentially with less human involvement at every stage.
So when I think about Agentic AI in cybersecurity, I do not start with the question, “How intelligent will the AI become?” I start with another question: What happens when the attacker can make decisions faster than the defender? That, to me, is the more immediate challenge.
The SOC Does Not Have an Alert Problem. It Has a Decision Problem
In conversations with security teams across ASEAN, I rarely hear anyone asking for fewer sources of security data. They already have plenty. The problem is making sense of all of it quickly enough.
Imagine an incident where an organisation detects suspicious authentication activity. The identity platform sees one piece. The endpoint platform sees another. Threat intelligence knows something about the IP address. Attack surface management identifies an exposed service. The vulnerability platform knows there is a weakness on that asset. Digital risk monitoring may already have discovered credentials belonging to the same employee somewhere outside the organisation.
Every tool may technically be doing its job. But somebody still has to connect the dots.
Is this actually malicious? Is the account privileged? Is the asset internet-facing? Is the vulnerability exploitable? Are the credentials genuine? Has the infrastructure been associated with a known threat actor? Should we isolate the endpoint? Should we disable the account? What happens to the business if we do?
This is why I believe cybersecurity increasingly suffers from decision latency.
For years, security architecture has been optimised heavily around detection latency. How quickly can I see something?
Now the question has to become: How quickly can I understand enough of the situation to make the right decision?
If five security systems generate five different pieces of the same attack, but an analyst has to manually correlate them before anybody understands the risk, we are still operating at human speed. That becomes a bigger problem when the attacker is not.
Threat Intelligence Has to Move Closer to Action
I have spent a significant part of my career working around threat intelligence, and one thing I believe strongly is that intelligence has to change a decision. Otherwise, it risks becoming another source of information. Traditionally, threat intelligence has often followed a model like this:
Collect -> Analyse -> Report -> Distribute
There is still an important place for that, especially for strategic intelligence. But operational security requires something closer to:
Detect -> Enrich -> Correlate -> Understand -> Decide -> Act
Take something as simple as a leaked credential. A username and password belonging to an employee appears in an underground marketplace. On its own, that is intelligence. Useful, but incomplete.
Now imagine immediately correlating that information with the person’s identity, privilege level, external applications, exposed infrastructure, endpoint activity, known vulnerabilities, suspicious infrastructure and current adversary behaviour.
The question is no longer: “Did we find a leaked credential?” It becomes: “Does this credential create a credible path into something important, and do we need to act now?”
That is a very different security outcome.
And this is where I see the real potential of AI in the SOC.
Not another AI assistant creating another summary. Not another chatbot sitting on top of another dashboard.
AI should reduce the distance between intelligence and action.
ASEAN Has its Own Reality
This conversation becomes particularly interesting when viewed from ASEAN.
One thing I have learned working across the region is that there really is no single “ASEAN cybersecurity maturity level.”
Singapore is different from Malaysia. Malaysia is different from Indonesia. Indonesia is different from Thailand or the Philippines.
And even within each country, a major bank, a government agency, a telecommunications provider, a manufacturing company and a mid-sized enterprise can have completely different levels of cybersecurity maturity.
Some organisations have mature SOC operations with substantial automation. Others are still strengthening basic identity security, vulnerability management, endpoint visibility and incident response.
Yet they may ultimately face the same AI-assisted adversaries.
That creates an uncomfortable reality: ASEAN may face machine-speed threats while many organisations are still operating human-speed security processes.
We cannot solve that simply by telling everyone to hire more SOC analysts.
The talent challenge is already real.
Instead, I see AI becoming a force multiplier for analysts – handling repetitive enrichment, correlation, evidence collection and initial investigation so people can spend more time on the decisions where judgement actually matters.
But this does not mean automating everything. In fact, the more powerful our automation becomes, the more careful we need to be.
Where AI Should Not Act Matters Too
This is particularly important for critical infrastructure. ASEAN economies depend heavily on energy, manufacturing, transportation, telecommunications and other essential services.
Many of those environments include operational technology and legacy systems where the consequences of getting an automated decision wrong can be very different from traditional IT.
Automatically isolating an employee laptop suspected of compromise is one thing. Automatically interfering with a production environment, operational control system or critical service is another.
The cybersecurity decision may be technically correct and operationally disastrous. That is why I keep coming back to this principle: The faster AI can act, the more important it becomes to understand where it should not act.
Context matters. Business impact matters. Safety matters. Authority matters. That is also why I do not believe the future SOC is simply an autonomous SOC. It has to be a governed autonomous SOC.
Agentic AI Needs a Trust Architecture
It would be dangerous to interpret Agentic AI as simply giving an AI agent access to every security tool and saying, “Go and defend us.” Trust has to be engineered into the architecture. I think about this in three practical levels.
Observe. Let the AI collect information, correlate events, investigate and build context. Humans retain the decision authority. Assist. Let the AI recommend an action, prepare the workflow and present the evidence. Humans approve significant actions.
Act. Allow the AI to execute predefined actions automatically – but only within clearly established policies, authority boundaries and confidence thresholds.
Most organisations will probably use all three at the same time. A low-risk containment action might be automated. Disabling a privileged identity may require approval. Taking action against a production system should probably have an even higher threshold.
The technology is actually the easier part. The harder questions are governance questions.
What agent is acting? What authority does it have? What evidence informed the decision? What is it prohibited from doing? When must it stop? When must a human become involved? And afterwards, can we explain exactly what happened and why?
Autonomy without accountability is not resilience. It is another form of risk.
‘Human in the Loop’ is Not Enough
I also think we need to challenge one phrase that gets used constantly in AI discussions: Human in the loop. It sounds safe. But what does it actually mean? If an AI system generates 50 recommendations during an attack and every one of them requires an analyst to click “Approve,” technically we still have a human in the loop.
We have also recreated the bottleneck we were trying to remove. The better model may increasingly be human on the loop rather than human in every loop. Humans establish the rules. Humans define the authority. Humans establish thresholds, escalation conditions, prohibited actions and risk appetite.
Machines operate inside those boundaries. And when the uncertainty, context or consequence exceeds those boundaries, the system escalates to a person.
Machine-speed defence does not require removing humans from cybersecurity. It requires being far more precise about which decisions actually need a human.
The SOC Needs to Become a Decision System
This changes how I think about the future SOC. The traditional SOC workflow is roughly:
Alert -> Queue -> Analyst -> Investigation -> Response
The emerging model looks more like:
Signal -> Intelligence -> Context -> AI reasoning -> Decision -> Controlled action
That does not make the analyst less important. I think it makes good analysts more important.
They should spend less time copying indicators between systems and more time understanding adversary behaviour, investigating complex incidents, assessing business impact, making judgement calls and defining how autonomous systems should operate.
AI should automate the work around the analyst, not automate away the analyst’s judgement. Because ultimately cybersecurity decisions are rarely purely technical.
Blocking something can interrupt a business process. Disabling an identity affects a person. Taking a system offline can affect customers. Changing something in operational technology can create physical consequences.
That context is what separates security automation from responsible security automation.
ASEAN can Leapfrog
There is also an opportunity here for ASEAN. We do not necessarily have to replicate every generation of security architecture built elsewhere. Some organisations in the region may be able to move directly from fragmented security operations toward more integrated, intelligence-driven models.
But we cannot assume AI will compensate for weak foundations.
Identity still matters. Asset visibility still matters. Security hygiene still matters. Threat intelligence still matters. Incident response still matters. And regional collaboration increasingly matters.
As our economies become more connected, cyber risk does not respect national boundaries.
A compromised supplier in one ASEAN country can affect customers in another. A threat actor targeting financial institutions may operate across several markets simultaneously. Infrastructure, cloud platforms and digital ecosystems increasingly cross borders.
That means strengthening ASEAN’s cyber resilience will require more than technology. It will require information sharing, public-private cooperation, critical infrastructure resilience, cross-border incident coordination, talent development and sensible AI governance.
This is why the conversation taking place around Singapore International Cyber Week and GovWare is timely.
SICW’s discussion around shaping the new cyber order, and GovWare’s focus on cyber at agentic velocity, are ultimately asking variations of the same question: How do we move faster without losing control?
Trust Becomes the Control Plane
I do not think the next cybersecurity race is simply going to be: AI attacker versus AI defender. That is too simplistic. The real advantage will belong to whichever side can understand what is happening, make the right decision and act faster.
But for defenders, there is an additional requirement. We must do it without losing control of the decision itself. Speed will become a security capability. Intelligence will provide context. AI will provide scale. But trust must determine what happens next.
As cybersecurity moves closer to machine speed, our security architecture will have to move with it.
That does not mean every decision should become autonomous. And faster certainly does not automatically mean safer.
The organisations that get this right will be the ones that combine machine-speed intelligence, machine-assisted decision-making and human accountability. For me, the formula is relatively straightforward:
INTELLIGENCE + CONTEXT + AI + GOVERNANCE -> TRUSTED ACTION
Everything before the arrow helps us move faster. Everything around it determines whether we should trust the outcome. And that is ultimately what trust at machine speed has to mean.






































