Step into the Agentic SecOps Command Center

Part 3 of the Intellyx Agentic SecOps Series for Straiker, by Jason English

Agentic SOC - Straiker - Intellyx bb3In our previous installments, we scouted out the new LOTA (living off the agent) villager attack patterns that are evading conventional threat hunting and remediation approaches. Then my colleague Eric Newcomer discussed how red, blue, and purple teams and agents can work together to complete pentesting and remediation missions while gathering post-exercise learnings.

We understand the risks privileged agents can create within our application environments, and also how agents can be an essential part of exposing and resolving vulnerabilities. Now, we need to operationalize new agentic offensive and preventative security capabilities into the organization.

We shouldn’t just form another department, that’s boring, and further, there may be stakeholders from different business groups coming together for mission-critical agent security work. Come to think of it, maybe it could be like a mission control center from the movies, with a bunch of big screens everywhere, and smart people and agents talking into headsets.

Enter the Agentic SecOps Command Center. It’s not a physical place, so much as a practice hub for managing and observing security team and agent SecOps activity, not dissimilar to the concept of a DevOps practice hub for developers and coding agents working together to provide automation and observability within the software delivery lifecycle.

What makes organizing around agentic security difficult

Companies and institutions are already widely deploying AI agents to increase worker productivity, accelerate development, and automate infrastructure-level activity, despite state-level agency warnings from the NSA and other cyber command centers calling for caution and noting insufficient safeguards.

There’s no slowing down agentic AI adoption – it’s a business imperative, even if the technology is being developed faster than the compliance guardrails needed to control it. Anyone who stands in the way of agentic speed might get run over by it in their next performance review. Here are some of the challenges this creates.

Understaffed SecOps teams, low executive morale. Despite some contraction in the overall technology job market, as many as 26% of cybersecurity roles remain unfilled in the U.S., and more than 4.8 million cyber jobs remain open globally. Cyber teams are now expected to cover a vastly expanded attack surface thanks to AI, and even CISO-level executives are feeling the heat, with near 25 percent planning to quit and 54 percent open to new opportunities within the next 6 months due to stress and poor work-life balance.

Shadow agents are being deployed within enterprises, and even if there is an official AI vendor selected by the company, there is often no official oversight or change management board making day-to-day decisions on what agentic AI uses are acceptable. A company can mandate the use of Microsoft and Github Copilot, for instance, but that won’t stop some developers from personally expensing the latest Claude Code or Cursor IDE on a credit card, or a manager using a downloaded chatbot for support, or an OpenClaw-style agent to auto-answer emails and sort files on their laptop.

Citizen developers are non-engineers within the org who build work product and application-like functionality with low-code tools, ranging from LLM-based services that automagically produce websites and presentations to “vibecoding” automation atop enterprise SaaS systems with a few prompts. Security researchers have uncovered mass data breaches of code, API keys, chat history and personal information, as security is often an afterthought for this cohort of users, because they aren’t exposed to the effort of remediating exploits.

What should an Agentic SecOps team do?

“The best-in-class Agentic SecOps organization listens to three agent heartbeats: agent discovery, adversarial attack, and defensive protection measures – all bound together with one central nervous system, a fabric of organizational context that ties all agent telemetry data together.”

– Sai Modalavalasa, Chief Architect, Straiker

As humans, we naturally tend to personify our SecOps agents as additional employees that can help us with our red, blue, and purple team exercises, but that is an oversimplification. In reality, the Agentic SecOps team is responsible for establishing agent visibility and maintaining the agentic security posture of the organization, using both event-based ephemeral agents, and longer-running agents that assure the integrity of an organization’s entire IT application estate over time.

Agentic SecOps work happens in three cycles:

  1. Agent and Skill Discovery. More than 90 percent of organizations report some level of agent visibility gap, and that is probably an underestimation, given that it’s impossible to account for non-human agent identities that are not found. In this phase, discovery agents explore the enterprise’s extended network, uncovering agent sprawl, including development coding agents, libraries full of agentic platform skills, MCP servers, and agent services including active and dormant agents generated by management, sales and marketing teams using SaaS and “vibecoding” tools.
  2. Adversarial Attack. This activity employs red-teaming agents that conduct continuous pentesting attacks, prompt injections, and cognitive hijacking attempts on every discovered agent and application service, including API gateways and MCP servers, as well as local system agents that can be exploited by emails and Slack messages. For safety, this activity is often highly concentrated on pre-production environments as a certification step prior to any production release, patch, or update.
  3. Runtime Protection. Now the team puts the learning and telemetry gathered from discovery and agent attacks to work, as well as bringing in global threat research data from sources like OWASP, setting up blue-team or defensive agents as sentries that look for known malicious attack patterns and prompts, as well as the side effects of zero-day threats such as latency or outbound spam emails that can indicate an unknown exploit. The agents are closely aligned with behavioral and permission guardrails so they can either block data leakage and model poisoning attempts when they happen, or alert the team to take action.

Telemetry data – or ‘heartbeats’ from all of these activities powers analytics and actions as the central nervous system of the agentic SecOps control center. These empirical indicators help the team decide where to focus new discovery, attack, and defense agents to address vulnerabilities and gauge the overall agentic security health of the organization.

Figure 1. Example view of a defensive agentic security control center dashboard from Straiker.

Guiding principles for how the team operates

Humans aren’t just “in the loop” of agentic security, they need to drive visibility, continuously test and learn, and help their organizations get ahead of emerging agent threat patterns, which may not resemble traditional attack chains thanks to non-deterministic agent behaviors.

  1. Test continuously and thoroughly, but safely. We should add continuous security (CS) to the CI/CD/CS pipeline, and ensure that every release or change is being validated by agents in near-real-time, so agility is not reduced. Live production testing is still important, but obviously it needs to be judiciously applied, as you don’t want your own attack agents to exfiltrate keys or destroy your production database. Thankfully, we now have containerization and Kubernetes as  scalable cloud native substrates, as well as lots of good simulation and replication tools on the market to provide safe and realistic pre-flight environments.
  2. Leverage AI as a security teacher for non-security experts. A developer can just ask an agent to recommend an approved security architecture within their agentic IDE to accompany their application under development, and help fill in the vulnerabilities with recommended workarounds as they go, Obviously, it’s less embarrassing and costly to get a notification that something would break during agentic coding versus in prod. New developers and citizen developers will be coming on board with their own AI-driven tools, and a system that gets better over time at predicting problems and recommending better approaches will mitigate emerging threats.
  3. Keep security awareness closer to the agents. Here’s where agentic security is way different than conventional AppSec and network security. The team is not just looking at agent nodes and endpoints, because every endpoint is also a potential entry point when agents are involved.

Fellow employees may be using agents on their local machines or smartphones. In scenarios where an agent might communicate with a third party agent or service such as a credit card processor, security agents must maintain awareness of two-way traffic in order to flag potential exploits. By applying contextual understanding of the intent of threats, defense agents then predict the source or root cause of the problem, and quickly provide remediation recommendations to the team, so fixes can be made quickly both internally and externally to limit disruption.

The Intellyx Take

We’re living in a new world of fast agentic adoption and higher speed releases, which requires less trust, and more verification from the agentic security team. However, none of the novel concerns of agentic security replace the need for rigorous conventional security tools and practices.

“You’re not going to make it if you think you can get by with just AI and agents, if you don’t have strong traditional security practices in place. You cannot afford to relax your security posture,” Straiker’s Sai Modalavalasa said.

If you have millions of dollars to spend, you could go ahead and set up a killer control room facility with all the big screens and data scientists running around like it’s a global spy thriller movie, or a space launch. I would love to come visit that, if you’ll pay for my travel.

Or you can just keep it simple, and treat the Agentic SecOps Command Center as an essential collaboration practice, where every team in the organization that relies upon agents can also work side-by-side with other business stakeholders and agents with a unified security framework of observability and automation.

©2026 Intellyx B.V. Intellyx is editorially responsible for this article. At the time of writing, Straiker is an Intellyx customer. None of the other organizations mentioned here are Intellyx customers. Not a word of this content was generated by AI. Image Source: Straiker.

 

SHARE THIS:

Principal Analyst & CMO, Intellyx. Twitter: @bluefug