This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Du Detection-as-Code au SOC agentique : la transformation structurelle du Managed Detection and Response

Download resources

About this session

Pierre Collard, who leads managed detection and response for Sopra Steria in North America, tests the marketing promise of the 'agentic SOC' against operational reality. He traces two decades of SOC modernisation, from SIEM correlation and EDR through CTI enrichment, early SOAR playbooks and detection-as-code, to the 2023 arrival of AI assistance, and argues that decision-making, not technology, is the real bottleneck to full autonomy. Using a maturity scale that runs from reactive to prescriptive to autonomous, he shows that an AI agent can only be trusted to decide (rather than merely investigate and recommend) once it has enough business context (asset criticality, identity, process, security policy), enough history of past decisions, and clearly defined authority limits; most organisations lack reliable, up-to-date sources for the first two. He proposes scoring use cases by business impact and reversibility, describes a 'decision contract' output that a policy gate checks before any autonomous action executes, and lists metrics (agreement rate, unsafe-action rate, evidence completeness, cost, latency) for governing agents once deployed. He closes with five questions organisations can use to test their own readiness for autonomous response, and a short audience Q&A on training junior analysts as the work shifts toward governance.

The SOC has always evolved in response to attacker speed. Detection-as-Code brought engineering discipline to threat
coverage. SOAR brought automation to response playbooks. But neither was designed for what defenders now face:
alert volumes that outpace analyst bandwidth, adversaries that use AI to iterate faster than rule-writers can respond,
and an industry-wide shortage of senior investigation talent.
The next structural shift is already underway: the Agentic SOC, where AI agents handle triage, investigation enrichment,
and initial response autonomously, allowing human analysts to focus exclusively on judgment-level decisions.
This session offers a practitioner-first account of what that transition actually looks like inside a managed security
practice, covering the architectural decisions, tooling trade-offs, and operational realities that vendor presentations
leave out. Attendees will leave with a clear mental model of how the agentic layer sits alongside existing SIEM and SOAR
infrastructure, where the human-machine handoff should actually happen, and what MDR providers and in-house SOC
teams alike need to do now to avoid being structurally behind within two years.
Takeaways for attendees:
-A practical framework for evaluating AI agent maturity in SOC workflows
-Decision criteria for the detection-as-code to agentic transition
-Honest assessment of what agentic SOC cannot yet do, and where human analysts remain irreplaceable
Target audience: SOC leads, CISO/security architects, MDR practitioners, and security engineers evaluating AI tooling
Level: Intermediate to Advanced

Key takeaways

  • Do not equate agentic SOC with full autonomy; classify each use case by business impact and reversibility before deciding whether an agent may act alone.
  • An agent can only decide reliably with three inputs in place: current business context (asset criticality, identity, process, policy), a documented history of past decisions, and explicit authority limits.
  • Insert a policy gate between an agent's 'decision contract' (confidence, evidence, proposed action) and execution, so a probabilistic model never acts directly against production.
  • Track agreement rate, unsafe-action rate and evidence completeness, not just cost and latency, to know whether an agent is actually deciding well.
  • Expect analyst work to shift toward governance and verification as routine tasks automate; plan explicit training and mentoring for junior analysts rather than assuming they will absorb it by osmosis.

Speakers

Pierre Collard
Pierre Collard
Responsable Détection et Réponse, Amerique du Nord · Sopra Steria
Pierre Collard est le responsable de la détection et de la réponse gérées chez Sopra Steria Amérique du Nord, où il dirige des équipes chargées de la détection des menaces, de la réponse aux incidents et des opérations de sécurité auprès de clients… Read moreRead less

Pierre Collard est le responsable de la détection et de la réponse gérées chez Sopra Steria Amérique du Nord, où il dirige des équipes chargées de la détection des menaces, de la réponse aux incidents et des opérations de sécurité auprès de clients des secteurs public et privé.

Resources

Photos

Tags

More from GoSec 2026

Also from Pierre Collard

On the same topic