For the 2026 Security 100, CRN is recognizing 20 security operations, risk and threat intelligence vendors that have stood out over the past year through delivering a combination of technical advancements and expanded opportunities for solution and service provider partners. He started his career analyzing IT and professional services markets and GTM strategies, now helping translate complex technology benefits into stories that connect innovation, business, and people. The future of SOC operations lies not in processing more alerts faster, but in preventing the conditions that generate unnecessary alerts while developing laser-focused capabilities against the threats that matter most. With continuous exposure management integrated into the SecOps workflow, each incident becomes a learning opportunity that strengthens future detection and response capabilities. Continuous exposure management transforms this by providing real-time context about the systems, configurations, and vulnerabilities involved in each alert. Traditional detection tools generate alerts based on signatures and behavioral patterns, but lack environmental context.
- This allows teams to automatically correlate discovered exposures with specific MITRE ATT&CK techniques, creating actionable threat intelligence that’s immediately relevant to each organization’s unique attack surface.
- Top view of laptop, phone, glasses and pencil with card with inscription cybersecurity training.
- For CRN’s AI Security Week 2026, we’ve selected 10 agentic SOC tools that have been on our radar thanks to their combination of advanced AI-driven capabilities and expansive opportunities for solution providers.
- “What we’re seeing is that adversaries are logging in, not hacking in. This is a shift toward access, influence, and leverage that can be activated at moments of political or military tension, often below the threshold of traditional response.”
- IQSIGHT has launched the AUTODOME 7100s and AUTODOME 7100s IR outdoor PTZ cameras with 4MP video, 30x optical zoom, AI-powered analytics, long-range IR illumination, adaptive power management, and advanced cybersecurity for critical security applications.
These priorities reflect a growing desire to apply AI to the early stages of investigation and surfacing meaningful alerts while providing initial context, and offloading repetitive analysis. The sheer volume of telemetry, overlapping tools, and automated alerts has pushed traditional SOCs to the edge. It’s 2026, yet many SOCs are still operating the way they did years ago, using tools and processes designed for a very different threat landscape. This week’s SOF News update covers leadership changes in Ukraine security assistance, proposed protections for special operations personnel, international exercises, SOF history, conflicts in Iran and Ukraine, emerging technology, Afghanistan, veterans’ issues, and selected reports, commentary, podcasts, and videos from across the national security community. US Naval Special Warfare Command is assessing the feasibility of rapidly producing expendable mid-sized USVs in theatre to support SOF and maritime security missions. The platform can also power external loads such as a forward-operating tactical grid.
At SOF Week 2026, Pro-Shot Defense discusses the maintenance technologies and weapon support tools designed to keep special operations forces mission ready in the world’s harshest environments. When it comes to agentic security operations, Zscaler is delivering a highly disruptive offering built upon the acquisitions of security data fabric provider Avalor and managed detection and response trailblazer Red Canary, according to Zscaler founder and CEO Jay Chaudhry. ZeroEyes has announced executive leadership changes to support its continued growth as the company evolves into a comprehensive multi-analytics threat intelligence platform.
Critical Leadership Lessons from the FDNY’s Response to 9/11
Currently, 55% of security teams already deploy AI copilots and assistants in production to support alert triage and investigation workflows. This approach reduces immediate workload but potentially creates blind spots in security coverage. Teams designed to protect organizations are systematically unable to examine nearly half of the potential threats they detect. Even more troubling, 61% of security teams admitted to ignoring alerts that later proved to be critical security incidents. 40% of security alerts go completely uninvestigated due to volume and resource constraints. This overwhelming influx creates an impossible dilemma, forcing SOC teams to make difficult and often risky choices about which alerts receive attention and which are, by necessity, ignored.
EDR, cloud security, email security, identity, and SIEM platforms ship with built-in detection logic that pushes MTTD close to zero for known techniques. Anthropic restricted its Mythos Preview model last week after it autonomously found and exploited zero-day vulnerabilities in every major operating system and browser. A single click can turn into identity exposure, remote access, data access, or a wider investigation before the team has a clear picture. They’re the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. Organizations are rushing to implement AI without fully grasping where its legal protections begin and end.
Other major moves to bolster the Splunk SecOps platform include enabling Splunk customers to ingest https://www.inrecognition.org/what-impact-does-cybersecurity-have-on-business-trust/ security data from Cisco firewall systems at no charge. The offering connects Splunk Enterprise Security 8.2 with SOAR, UEBA and the Splunk AI Assistant to provide accelerated threat response as well as simplification in the SOC, according to the vendor. The expansion helps with the currently available offerings in security operations, such as AI SIEM (security information and event management), while also helping to set the stage for a bigger shift into an agentic SOC going forward, according to the company. Key moves include the integration of technology from recently acquired Observo AI, which can optimize data pipelines for autonomous threat detection and response. SentinelOne is enabling the shift to a truly agentic SOC with recent enhancements to its Singularity AI SIEM platform—with the ultimate goal of being able to provide a stunning level of autonomy in security operations, according to SentinelOne co-founder and CEO Tomer Weingarten.
Investigations Remain Slow and Manual
“Too many security teams have good data, powerful tools and endless alerts, but no real confidence that they are actually protected,” Mumcuoglu said in the news release. The combination of Cribl’s AI Platform for Telemetry and CardinalOps’ agentic detection software provides an alternative for legacy SIEM architectures, helping clients improve threat coverage and strengthen SOCs, according to the companies. In iconic venues around the world, Cisco Wi-Fi, AI, and security support the most bandwidth-hungry, future-facing fan interactions.
How satisfied are security teams with AI and machine learning tools?
Introducing native support for leading frontier AI models, including Claude Sonnet 4.6, Claude Opus 4.8 and Gemini 3.5 https://www.motonlegalgroup.com/impact-of-technology-on-law/ Flash across the Cortex platform. Discover how Palo Alto Networks Cortex XSIAM integrates with NVIDIA DOCA Argus to deliver deep visibility and secure the AI Factory with zero performa… AWS Systems Manager extends its capabilities to on-premises environments through Hybrid Activations, allowing physical servers and local virtual machi…
- Additional updates include STid V3 mobile credential API support, 32-bit Wiegand compatibility, OSDP In/Out readers, improved performance and simplified Chinese language support, giving security teams a more streamlined platform for managing complex environments.
- Google Cloud debuted its Google Unified Security offering, which combines security operations and cloud security with threat intelligence and the company’s Chrome Enterprise browser.
- He started his career analyzing IT and professional services markets and GTM strategies, now helping translate complex technology benefits into stories that connect innovation, business, and people.
- About Recorded FutureRecorded Future is the world’s largest threat intelligence company, serving over 1,900 businesses and government organizations across 80 countries.
- This impossibility forces difficult choices about which alerts receive attention and which get ignored.
- This week’s SOF News update covers leadership changes in Ukraine security assistance, proposed protections for special operations personnel, international exercises, SOF history, conflicts in Iran and Ukraine, emerging technology, Afghanistan, veterans’ issues, and selected reports, commentary, podcasts, and videos from across the national security community.
What’s New in Cortex
Fortinet announced unified endpoint security enhancements though FortiEndpoint to consolidate multiple endpoint products, reduce agent sprawl, simplify licensing and management, and strengthen protection against emerging threats, including AI application misuse. Enhancements include a dedicated agent that automates alert triage, investigation, threat hunting, and Model Context Protocol (MCP) support to maintain shared context https://power-at-work.com/cybersecurity-risks-and-solutions-for-connected-construction-equipment/ and execution continuity across detection, investigation, and response workflows. The Fortinet Security Operations Platform unifies telemetry, analytics, threat intelligence, and response across the kill chain, reducing complexity and accelerating investigations without forcing operational rebuilds. The cyber threats and risks are too high not to be proactive in advancing the capabilities of security operations centers. The adage is that people, processes, and technologies are essential for holistic cybersecurity. CompTIA is another certification organization that offers excellent training for potential SOC analysts.

