IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Zscaler launches Agentic SOC to fight AI-driven attacks

Zscaler launches Agentic SOC to fight AI-driven attacks

Wed, 9th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Zscaler has launched Agentic SOC, a security operations product designed to detect, investigate and contain AI-driven threats. The system combines Zscaler's telemetry with AI models from Anthropic and OpenAI.

The launch reflects growing pressure on security operations teams as attackers use artificial intelligence to increase the speed and scale of intrusions. Many conventional security operations centres still rely on manual correlation and analysis, leaving analysts struggling to respond quickly enough to more evasive attacks.

The product is intended to unify exposure management and threat response in a single workflow. It draws on data from network, identity, endpoint, cloud and AI activity across what Zscaler described as 750 billion daily zero trust transactions, then combines that information with third-party security data to identify and investigate incidents.

Alongside external AI models, Zscaler has built specialised AI agents using more than a decade of security operations, managed detection and response, and threat-hunting experience. The agents are meant to assist with triage, root-cause investigation, assigning verdicts and triggering response workflows.

AI pressure

Cybersecurity groups have warned that generative AI is lowering the barrier for attackers to produce convincing phishing campaigns, automate reconnaissance and adapt malicious activity more quickly. Zscaler's research team, ThreatLabz, has also highlighted the use of trusted websites to host attacks, the misuse of legitimate remote management tools and browser-based techniques that can be harder for defenders to detect.

Agentic SOC is meant to address that shift by linking threat detection with direct response measures. According to Zscaler, its native controls can isolate compromised users, block command-and-control traffic and restrict lateral movement, while integrations with third-party tools give customers additional response options.

Deepen Desai, Executive Vice President of Cybersecurity at Zscaler, said the launch reflects a change in the pace of attacks.

"AI-driven attacks are moving faster than traditional SOC models were ever designed to handle," said Desai.

He added: "Agentic SOC is a fundamental rethinking of security operations, built with agentic capabilities at its core to reduce exposures proactively, extend human expertise with AI agents and contain threats at machine speed. With unmatched inline telemetry, specialized AI agents and closed-loop remediation, Zscaler is giving security teams the visibility and control they need to outpace modern attackers."

Open model approach

Zscaler said it chose to work with frontier AI model developers rather than rely on a single model or a closed in-house approach. By combining those models with its own threat intelligence and zero trust data, the company said security teams can bring vulnerability findings and other operational data into the same security workflow.

The approach comes as cybersecurity vendors race to embed more AI into defensive tools, particularly products aimed at reducing alert fatigue and speeding up investigations. A central argument from suppliers is that analysts need help not only with detection, but also with prioritisation and containment.

Industry observers have said the quality of the underlying telemetry and the ability to automate action safely will determine whether such systems gain wider trust among customers. Security teams have often been cautious about handing response decisions to automated systems without clear context and auditability.

Allie Mellen, Principal Analyst and Author of Code War: How Nations Hack, Spy, and Shape the Digital Battlefield, said the spread of AI-enabled attacks was changing the threat environment.

"The past year has made one thing clear: AI attacks are fundamentally changing the threat landscape, operating at a speed, scale, and level of adaptability that looks very different from traditional human-led activity," said Mellen.

She added: "To defend effectively, organizations must double down on the fundamentals - Zero Trust principles, preventing data exfiltration, limiting access, and making AI attacks as expensive as possible."

Customer use

Zscaler also pointed to customer demand for tools that cut through large volumes of alerts. One user, Maire Tecnimont, said the product helped its analysts move away from fragmented signals toward a clearer view of attack paths by using data already available in its environment.

Andrea Liccardi, Senior Cybersecurity Manager at Maire Tecnimont, said: "Our team was drowning in alert noise, forcing top analysts into triage instead of proactive threat hunting. Zscaler Agentic SOC gives us full attack-path context using telemetry we already had in place, helping our team move from fragmented signals to faster, more informed decisions. Zscaler has proven to be one of our most valuable cybersecurity partners, continuously helping us improve operational efficiency, visibility, and our ability to focus our analysts on what really matters."