Report an Incident Become a Partner Careers Contact
Book a Demo
Managed service

Managed SOC,
run by AI agents.

A fully managed security operations centre where the analyst workload is carried by fourteen specialised AI agents — triage, investigation, hunting, exposure and containment — backed by a 24/7 manned SOC where named senior analysts sign off every customer-facing decision.

Your SOC roster14 agents
L1Triage & intakeFront line
WATCHEarly warningFront line
L2InvestigationInvestigate
FUSIONLinks signals & campaignsInvestigate
INTELAdversary contextInvestigate
HUNTProactive huntingProactive
DETDetection engineeringProactive
VULNExposure managementProactive
INSIDERInsider riskProactive
RESPContainmenton approval
COMMSKeeps you informedService ops
RPTReporting & insightService ops
MAINTKeeps the SOC seeingService ops
MGRRuns the shiftService ops
Runs on CYBERSHIELD AI

Your own
AI-driven SOC.

CYBERSHIELD AI is our own agentic security operations platform, built and run in-house by the SOC that uses it. 14 agent personas draw on 250+ agent skills and 300+ AI tools to work an incident all the way to a verdict, not just to a ticket.

Every one of those skills is a procedure our analysts wrote while running Microsoft Sentinel for customers since 2019. Nothing here is a model trained on public threat data.

14 Agent personas One per SOC function, from triage to containment
250+ Agent skills Named analyst procedures the agents execute
300+ AI tools Actions across identity, endpoint, cloud and email
Definition

What is a
managed AI SOC?

A managed security operations service where the analyst workload — triage, investigation, hunting, intelligence and detection — is carried by AI agents, with senior humans accountable. A traditional MSSP scales by hiring; a managed AI SOC scales by adding agents.

Traditional MSSP Managed AI SOC
Analysts manually process thousands of alerts a day
Every escalation is investigated end to end, at machine speed
Low-value alerts closed at speed to keep the queue moving
Noise is filtered with the reasoning recorded, not discarded
Investigation depth depends on who happens to be on shift
The same depth on every incident, at 3am as at 3pm
Generic playbooks applied across every customer
Triage procedures built around your sector, estate and adversaries
The investigation stops at the first plausible answer
A completeness gate audits for gaps and sends it back for more evidence
Threat hunting sold separately and rarely delivered
Continuous hypothesis-driven hunting built into the service
Escalations land back with you as a ticket to work
Containment planned and executed, held only for L3 approval
Costs rise in step with your alert volume
Capacity scales without a proportional increase in cost
On every incident

You do not get an alert.
You get the finished case.

Every investigation produces the same complete set of documents — not a summary line in a portal, and not only on the incidents someone had time for.

Full investigation report

The complete case on every incident: evidence gathered, hypotheses tested, scope, root cause, impact and confidence.

L2 escalation write-up

Produced whenever an incident is escalated, so your team inherits the reasoning rather than a ticket number.

Closing statement

A plain-English account of what happened and how it was resolved, written for the record.

Email communication draft

A ready-to-send notification for your stakeholders, drafted while the incident is still moving.

Average L1 triage 3m 30s Average time to triage, enrich and reach a decision on an incoming alert.
Average L2 investigation 7m 50s Average time to work an escalation to an evidenced verdict.
Guardrails

The agents work.
You keep control.

The honest answer to the question every buyer asks: no, it does not act on its own. Here is exactly where the line sits, and who draws it.

01

Every action reports into the Control Centre

One place where every agent reports, and where our analysts watch and approve what they do. Nothing runs unobserved.

02

Approvals are configurable per agent, per tenant

You decide which agents may act, on what, and where the line sits. Your configuration is yours — it is not a shared platform default.

03

Auto-approve only when your confidence threshold is met

Set the bar. Below it, the action waits for a human. Above it, the agent proceeds and the decision is still recorded.

04

Humans stay at L3 and incident response

Senior analysts and responders remain in the loop for the decisions that carry real consequence. That is deliberate, not a limitation.

05

The AI SOC Manager watches the rest

The orchestration agent tracks queue, confidence and service performance, and escalates to a human when the standard is not met.

Customer portal

Your incidents, verdicts, reports and service performance — live, not a monthly PDF.

Mobile app

Approve, review and stay across live incidents from anywhere, including out of hours.

Named contacts

A team you can reach by name, with defined escalation paths to human experts.

Every agent on the roster The nine stages, named

In every package

The baseline, regardless
of tier.

These aren’t upsells. They’re the conditions that make the service defensible — so they apply from the entry tier upwards.

24/7 manned SOC

Agents run continuously and our SOC is staffed by security professionals around the clock, every day of the year.

Mean Time to Verdict

We measure the whole chain — signal received to signed-off outcome — not just how fast a machine acknowledged an alert.

Senior analyst sign-off

Every customer-facing decision is reviewed and approved by an experienced human analyst before it reaches you.

A verdict, not a longer alert

Every incident closes with a structured outcome: malicious or benign, scope, root cause, impact, a confidence score and a recommended action.

Tenant isolation

Your data stays in your tenant. No cross-customer learning, enforced architecturally.

Named contacts

A named team you can reach, with defined escalation paths to human experts.

You set the autonomy

Per agent: fully autonomous, held for your approval, or autonomous above a threshold you set. High-impact containment is held for a human either way.

Your estate connected

Microsoft Sentinel is the only hard requirement. Connectors, parsers, analytical rules and playbooks for what you already run are built during onboarding, as part of the service.

Packages

Three ways to buy
the managed AI SOC.

Start where you are and move up when the estate does. Every tier includes the 24/7 manned SOC, senior analyst sign-off and a structured verdict on every incident; the package decides how much of the agent roster is on duty for you.

Package 01
Core

For teams that need alert volume handled properly, with the option to grow into a full SOC.

Per incidentYou pay for what your estate actually produces.

  • SOC L1 Triage Agent
  • SOC L2 Investigation Agent, charged when an incident needs it
  • Full evidence-based investigation on every escalation
  • Triage procedures and escalation instructions set up with you
  • 24/7 manned SOC & senior analyst sign-off
  • Quarterly service review
  • The rest of the agent roster starts at Complete
  • No Threat Attack Profile
  • No threat hunting included
  • Human-led incident response not included
Talk to us
Package 03
Command

For regulated and high-risk organisations that need deeper hunting and responders already on standby.

Per userYour bill moves with headcount, never with incident volume.

  • Everything in Complete — all fourteen agents
  • Extended threat hunting allocation
  • Human incident response team on standby
  • Priority escalation to human responders
  • Operational threat intelligence & advisories
  • 24/7 manned SOC & senior analyst sign-off
  • Monthly service review
Talk to us

What each package includes, in full

Full comparison

Every agent,
every package.

The Response Agent handles automated containment within your agreed limits.

Which agents are included in the Core, Complete and Command packages
Agent Core01 Complete02 Command03
Front line
SOC L1 Triage Agent ✓Included ✓Included ✓Included
Watch Agent –Not included ✓Included ✓Included
Investigation
SOC L2 Investigation Agent ✓Included ✓Included ✓Included
Intel Analyst Agent –Not included ✓Included ✓Included
Fusion Agent –Not included ✓Included ✓Included
Proactive security
Threat Hunter Agent –Not included ✓Included Extended
Detection Engineering Agent –Not included ✓Included ✓Included
Vulnerability Management Agent –Not included ✓Included ✓Included
Response
Response Agent (automated containment) –Not included ✓Included ✓Included
Service operations
SOC Manager Agent –Not included ✓Included ✓Included
Communications Agent –Not included ✓Included ✓Included
Reporting Agent –Not included ✓Included ✓Included
Maintenance Agent –Not included ✓Included ✓Included
Questions

The managed AI SOC, answered.

What is a managed AI SOC?

A managed AI SOC is a managed security operations service where the analyst workload — triage, investigation, threat hunting, intelligence and detection engineering — is carried by AI agents, with senior human analysts accountable for the outcomes. A traditional MSSP scales by hiring more analysts; a managed AI SOC scales by adding agents, so capacity grows without a proportional increase in cost.

How is a managed AI SOC different from a traditional MSSP?

A managed AI SOC differs from a traditional MSSP in depth and consistency. A traditional MSSP triages thousands of alerts a day by hand, closing low-value alerts quickly to keep the queue moving, and investigation depth depends on who is on shift. an AI SOC investigates every escalation end to end at machine speed, applies the same depth at 3am as at 3pm, records the reasoning behind filtered noise rather than discarding it, and plans and executes containment instead of handing you back a ticket.

Does the service train on our data?

No. Your data stays in your own tenant and isolation is enforced architecturally rather than by policy. There is no cross-customer learning: nothing we run for another customer touches your detections, and your telemetry does not improve the service any other customer receives.

Is the service staffed 24/7 by real people?

Yes. Agents run continuously and the SOC is staffed by security professionals around the clock, every day of the year, with named contacts and defined escalation paths to human experts.

What does every package include, regardless of tier?

Every tier includes a 24/7 manned SOC, senior analyst sign-off on every customer-facing decision, a structured verdict on every incident, tenant isolation, named contacts, Mean Time to Verdict measured across the whole chain, the autonomy dial on whichever agents are on duty for you, and the connectors and tooling your estate needs, built during onboarding. Which agents are on duty — and whether you have a Threat Attack Profile — is what the package decides.

Is threat hunting included?

Continuous threat hunting is included in the Complete package and extended in Command, and additional allocation can be purchased on top of either. It is not included on Core, which is the front-line agents only — hunting arrives with the rest of the roster at Complete.

Can the service contain a threat automatically?

Yes, within limits you set. The Response Agent builds a containment plan for a confirmed incident and executes pre-authorised actions inside the containment matrix agreed at onboarding, then verifies the action landed and reports what changed. Anything beyond those pre-authorised limits is held for human approval.

How is Mean Time to Verdict measured?

Mean Time to Verdict measures the whole chain — from the moment a signal reaches CYBERSHIELD AI to a signed-off outcome — rather than how quickly a machine acknowledged an alert. The clock starts at the same point on every measure.

Get started

See the managed AI SOC running
on your estate.

Book a demo and we’ll walk you through the agents, the sign-off process and the package that fits.