From reactive to proactive

Mazen Adnan Dohaji, Vice President & General Manager, IMETA, Exabeam, shares his thoughts on achieving smarter, more scalable SOC strategies with agentic AI.

Organisations in the Middle East are rapidly exploring new space when it comes to AI in cybersecurity. As demand for greater efficiency and automation in the security operations centre (SOC) increases, business leaders are looking for solutions that ease workload burdens while proactively fighting threats. This is where agentic AI comes in.

As the region pushes forward with national initiatives including Saudi Vision 2030 and the UAE National Strategy for AI 2031, the conversation is shifting from assistive AI to agentic AI. With the AI agent market expected to reach $2.2 billion by 2030 across the Middle East and Africa, according to Grand View Research, there’s no doubt around the increasing appetite for and value in autonomous AI systems across the region.

The question is no longer whether AI belongs in the SOC, but can AI deliver results that matter? Security leaders need agentic AI solutions that can take their organisation’s security approach from reactive to proactive by pinpointing gaps, fine-tuning strategies, and justifying investments.

Overpromised capabilities, undelivered value

While there is massive promise and potential around agentic AI in cybersecurity, too many tools lack integration with security operations workflows and still require constant tuning and interfaces to learn. Most teams are still reactive, chasing false positives, and struggling to respond fast enough.

The challenge lies in deploying agentic AI that doesn’t just collect data but turns it into actionable strategies that Chief Information Security Officers (CISOs) and their teams can operationalise.

Currently, SOC teams across the Middle East are facing several critical challenges that impact their overall efficiency, including:

  1. Lengthy threat investigations. Analysts often lose valuable time manually correlating events and building timelines. Many teams still struggle to respond to incidents in less than an hour. For organisations in the Middle East, this is leading to increased mean time to detect (MTTD) and respond (MTTR).
  2. The security talent shortage. According to the ISC2 2024 Workforce Study, the global cybersecurity workforce gap has reached 4.8 million. Across the Middle East, this talent shortage is exacerbated by the region’s rapid digital transformation and the increasing sophistication of cyber threats. This leaves SOCs overextended and understaffed, increasing the risk of threats going unnoticed.
  1. AI-powered threats. Attackers are using AI to scale and accelerate attacks faster than traditional detection methods can manage. These AI-powered attacks allow threat actors to automate, customise and evolve their methods in real time. In turn, this increases pressure on analysts as they grapple with unfamiliar threat tactics.
  2. Static dashboards. Traditional cybersecurity tools don’t recommend next steps or guide SOC teams on vulnerabilities or areas to improve. As a result, CISOs are often left piecing together reports from disparate tools or manually chasing metrics from their teams.

At the same time, today’s CISOs are business leaders, responsible for more than just minimising risk. They’re expected to make smart investments, support strategic transformation, protect sensitive data and users, and clearly demonstrate how security operations support their organisation’s growth.

The combination of these factors introduces serious vulnerabilities that leave organisations exposed to breaches and increases the mounting pressure on CISOs. Agentic AI changes this by delivering business-ready insights from operational data in real time and presenting them in a way business leaders can understand and utilise.

Turning data intelligence into strategic insight

To keep pace with the Middle East’s ever-evolving threat landscape, organisations need agentic AI that goes beyond basic task automation and chatbot-style interactions. They need solutions that can interpret data, prioritise threats, streamline investigations and help security leaders continuously improve their security posture.

Agentic AI addresses this by perceiving problems, interpreting context and initiating or recommending next steps. It’s not limited by static rules or rigid playbooks. Instead, it can reason across datasets, adapt to new input and stay aligned with organisation’s policies.

In the SOC, where every second matters, AI-powered automation enables faster, more accurate decisions. CISOs in the Middle East capture new value through:

  • Increased advisory insights: With the right agentic AI that supports cybersecurity strategy, CISOs benefit from a proactive solution that turns security data into business-relevant terms, proving value of investments and leadership decisions. SOC teams are supported by measurable insights, recommended targeted improvements and automatically generated data-backed roadmaps.
  • Improved security maturity: Through agentic AI, CISOs can improve their organisation’s overall security maturity by uncovering issues like missing log sources, misconfigurations and ineffective threat detection content that weakens security posture. They gain the tools to simulate adjustments or additional security capabilities and benchmark security posture daily.
  • Enhanced threat detection, investigation and response (TDIR): Agentic AI is not only augmenting strategic planning and reporting processes, but it also acts as a barrier to stop cyberattacks from infiltrating sensitive data. Agentic AI uses behavioural analytics and adaptive learning to detect deviations from baselines, uncover stealthy techniques, and prioritise high-risk events with contextual risk scoring. This is especially helpful in fighting AI-powered threats.
  • Reduced analyst burnout: Agentic AI is capable of analysing every step of a cyberattack, from identifying a vulnerability, to solving the issue, and then producing logs and insights on how to protect SOC operations in the future. With this, security teams can streamline their workloads by offloading repetitive tasks like data parsing and case summarisation. This frees analysts to focus on higher-value work.

Strengthening SOCs for an AI-ready future

AI agents built into the foundation of security operations workflow offer a new way forward for CISOs in the Middle East. More than just copilots bolted on to outdated infrastructure, they can serve as force multipliers — extending SOC capacity while enhancing decision-making. Whether it’s a review of the organisation’s security posture, creating executive-level reports that show the SOC’s true value, or an analysis of detections, automation from AI agents can simplify both strategic and routine tasks helping security teams work smarter and faster.

The benefits that agentic AI brings to the region will be key to strengthening operations, protecting against cyberattacks, and guiding future-ready security strategies.

No Comments

Sorry, the comment form is closed at this time.

1