Traditional security tooling and processes aren’t built for agentic risks
For many years, security operation centre (SOC) tools and processes were built on a reasonable assumption: the actors that generate telemetry are human (with the exception of DDoS attacks).
Security staff would spend their time looking for signs of suspicious behaviour that suggest a human is up to no good, things like:
- Multiple failed login attempts
- Logging on from unusual locations or at unusual times
- People trying to access folders they don’t usually open
- Large downloads
- Opening links to visit unusual websites.
Agentic AI undermines this approach. When organisations have tens, hundreds, or even thousands of agents autonomously carrying out tasks, monitoring for suspicious behaviour becomes much harder.
Take our simple example of an over-provisioned HR bot.
In the past, if a non-HR person was trying to find out what their colleagues earned, the telemetry would show up some obviously suspicious activity (trying to open SharePoint sites they don’t have permissions for, or – if they’d stolen a password – downloading files they don’t usually look at).
But with a poorly permissioned HR bot (as in our example above), the breach runs through the agent and would not be flagged as suspicious.
The second major challenge is that managed detection and response tools do not ingest agent-specific telemetry.
They collect endpoint signals, identity sign-in events, email threats, and cloud configuration data. What they are not collecting is the audit record of what an agent accessed, what it sent, what it modified, and what instruction it acted on.
Without that telemetry, an agent can be compromised, misdirected, or operate outside its defined scope and the security team will see nothing unusual because they are not looking at the right data source.