Your SOC Won’t Survive AI Attackers Without This Shift
Find Threat Talks on
Your SOC Won’t Survive AI Attackers Without This Shift
Running a SOC was always hard. With AI in attackers’ hands, hard becomes impossible, unless you change how you work. Open-source tools now find and exploit a flaw in about 15 minutes, with no trained pentester in the loop. Detection and response was built for a world where you had time to react. That world is gone.
Rob Maas, Field CTO at ON2IT, sits down with Lieuwe Jan Koning, Co-founder & CTO at ON2IT, for a direct conversation about what a SOC becomes when speed collapses. Lieuwe Jan has spent twenty years arguing that prevention beats reaction. This episode is his case for why that argument just became urgent, and what SOC managers should do about it now.
4. What you’ll learn
- Patching is a last resort. Almost every piece of software ships flawed, so leaning on patch cadence means you have already lost.
- The analyst moves up the stack. Triage and correlation go to software, freeing humans to be quality gates and orchestrators.
- Preemptive means prevention plus automated response. Countermeasures fire in seconds, which only works if your IT estate can receive them.
Your cybersecurity experts
Lieuwe Jan Koning
Co-Founder and CTO
ON2IT
Episode details
The through-line is a single reframe: the SOC’s job is no longer to watch events and solve them, it is to make sure those events never happen. Lieuwe Jan frames every alert as a symptom of a fixable problem somewhere upstream. In a world where an attacker can find and exploit a flaw in minutes, a SOC that only detects and responds is measuring the lack of security instead of improving it.
That reframe lands hardest on patching. Lieuwe Jan is blunt: keep patching, because you depend on it, but the fact that you depend on it is bad news. Known and unknown flaws mean software is flawed by default. Prevention controls, segmentation, multi-factor authentication everywhere, resilient container farms, are where the budget should go, roughly 90% of it by his estimate.
The second half is about automation and culture. Preemptive cybersecurity has two halves: prevent what you can, and when you do get hit, respond automatically instead of routing every decision through a human who phones the customer first. The technical piece is solved: APIs, MCP servers, agents. The hard part is organizational. IT departments and software owners have to build a receiving end for automated countermeasures, which ON2IT calls a zero trust culture.
For the analyst, this is a promotion, not a redundancy. The groundwork, triage, correlation, building a battle plan, hours of work, now runs in under a minute at consistent quality. Humans become the quality gate, codify new attacker playbooks, and handle escalation and strategy. Lieuwe Jan’s verdict for anyone running a reactive-only SOC is the line to take away: there is no future for it.
Get your Hacker T-shirt
Join the treasure hunt!
Find the code within this episode and receive your own hacker t-shirt for free.





