IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand
ExtraHop launches Agentic SOC Alliance with 15 members

ExtraHop launches Agentic SOC Alliance with 15 members

Fri, 24th Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

ExtraHop has launched the Agentic SOC Alliance with 15 founding members to define a shared operating model for autonomous security operations.

The alliance brings together AuthMind, Armadin, Command Zero, CrowdStrike, Dropzone AI, Exaforce, ExtraHop, Fig, Intezer, Kindo, LangChain, Prophet Security, ReversingLabs, TENEX.AI and Torq.

Security operations centres have long relied on a workflow in which human analysts queue, enrich, triage, investigate and escalate alerts. ExtraHop argues that model is too slow against attackers that now automate reconnaissance, exploit development and lateral movement.

The initiative is built around three layers that members say should underpin an autonomous SOC: Context, Harness and Model. In this framework, Context is the real-time evidence an AI system uses, Harness covers orchestration and governance, and Model is the reasoning engine that can be swapped as systems evolve.

Common blueprint

The alliance aims to standardise architectural requirements, best practices and implementation blueprints across those three layers. Its goal is to help companies adopt AI-driven security operations without relying on a single vendor's design.

Greg Clark, Chief Executive Officer at ExtraHop, outlined the case for a new structure for security teams.

"Post-Mythos AI has fundamentally changed cyber defense. Adversaries now operate at machine speed, yet most security operations are still built on architectures designed for a human-paced world," Clark said.

"The industry needs a blueprint for how autonomous security should operate that combines real-time context, intelligent orchestration, and specialized AI agents into a new operating model. The Agentic SOC Alliance is bringing that blueprint together, giving organizations a foundation to detect, decide, and respond with the speed and accuracy that modern threats demand. This is a starting point, not a finished one. We invite the rest of the industry to join the Alliance and help us refine, validate, and perfect this operating model, because outpacing a machine-speed adversary is a challenge no single company can solve alone."

The launch comes as security suppliers race to position AI as a response to increasingly automated cyber attacks. A central debate, however, is whether AI tools reduce analyst workloads or simply generate more alerts and false positives.

ExtraHop argues that many current AI systems in the SOC still force analysts to verify questionable outputs and chase dead ends. The alliance's model is intended to reduce that by ensuring agents work from richer evidence and within clearer controls.

Context layer

A central part of the proposal is that AI agents should work from a continuously updated operational view of an organisation, rather than fragmented logs alone. That view would combine data from networks, endpoints, identities and threat intelligence into a structured representation that agents can query directly.

Under the alliance's architecture, the Harness layer would manage workflows, tool use, memory, permissions, human approval and audit trails. Supporters argue that separating those controls from the underlying models would let customers change models without rebuilding the governance around them.

Jason Dewez, Chief Information Security Officer at Fiserv, described that distinction as essential to how AI is likely to be used in live security operations.

"In the modern SOC, the turning point is recognizing that real-time ingest from network and endpoint telemetry has to become the primary substrate for how AI agents operate," Dewez said.

"Post-Mythos-level models can reason at remarkable speed, but only when they are fed live evidence from the environment instead of waiting on slower, batch-oriented pipelines. Our target state is machine speed detection, containment, response, and recovery. Our traditional SIEM model, while necessary, will not be able to keep up. Agentic assisted SOC is the only answer in our opinion."

The founding members span network monitoring, endpoint security, orchestration software, AI-native SOC platforms and agent frameworks. That mix reflects a broader shift in cybersecurity, where suppliers increasingly need to show their products can work within a larger automated workflow rather than in isolation.

Several members presented the alliance as an effort to define an open architecture before one vendor's approach becomes dominant. For customers, that could matter if they want to change models or tools without redesigning security operations from the ground up.

Industry backing

The effort has also drawn support from outside the founding group. Dr. Edward G. Amoroso, Chief Executive Officer at TAG Infosphere and Research Professor at NYU, said the market needed a practical framework for AI-led operations.

"Cybersecurity has reached the point where human-speed defense is no longer sufficient against machine-speed attacks. The Agentic SOC Alliance represents one of the industry's first serious efforts to define an open operational architecture for autonomous security operations, bringing together trusted context, governed AI, and coordinated response so enterprises can finally begin defending at the speed of their adversaries. I am excited to see the development."

ExtraHop's role in the model centres on network telemetry, which it says can provide real-time evidence for AI systems investigating threats. Other members contribute identity data, orchestration tools, agent runtime controls and AI-driven investigation systems.

LangChain, for example, focuses on the harness layer that governs what an agent can access and do. Kindo has highlighted governed runtimes and deployment choices, while CrowdStrike, Intezer, Torq and others have pointed to the need for richer network context to support automated triage and response.

The alliance enters a crowded market in which suppliers are trying to persuade buyers that AI can be trusted in high-stakes security work. Its success is likely to depend less on rhetoric than on whether the group can show that a shared architecture cuts errors, speeds investigations and preserves human oversight across tools from multiple vendors.

"Better models alone don't get an agent to production. The harness does. We built LangGraph to govern what an agent can do with its evidence, which context it reads, which actions it takes, when a human signs off, and LangSmith to test its trajectory before it goes live. Inside the Alliance, that becomes the layer every member agent runs in, so you can change the model underneath without re-earning trust in what the agent is allowed to do," said Karan Singh, Head of Partnerships at LangChain.