Your SOC Won’t Survive AI Attackers Without This Shift

Threat Talks infographic

Find Threat Talks on

Your SOC Won’t Survive AI Attackers Without This Shift

Running a SOC was always hard. With AI in attackers’ hands, hard becomes impossible, unless you change how you work. Open-source tools now find and exploit a flaw in about 15 minutes, with no trained pentester in the loop. Detection and response was built for a world where you had time to react. That world is gone.

Rob Maas, Field CTO at ON2IT, sits down with Lieuwe Jan Koning, Co-founder & CTO at ON2IT, for a direct conversation about what a SOC becomes when speed collapses. Lieuwe Jan has spent twenty years arguing that prevention beats reaction. This episode is his case for why that argument just became urgent, and what SOC managers should do about it now.

4. What you’ll learn

  • Patching is a last resort. Almost every piece of software ships flawed, so leaning on patch cadence means you have already lost.
  • The analyst moves up the stack. Triage and correlation go to software, freeing humans to be quality gates and orchestrators.
  • Preemptive means prevention plus automated response. Countermeasures fire in seconds, which only works if your IT estate can receive them.

Your cybersecurity experts

Lieuwe Jan Koning

Co-Founder and CTO
ON2IT

Rob Maas

Rob Maas

Field CTO ON2IT

Episode details

The through-line is a single reframe: the SOC’s job is no longer to watch events and solve them, it is to make sure those events never happen. Lieuwe Jan frames every alert as a symptom of a fixable problem somewhere upstream. In a world where an attacker can find and exploit a flaw in minutes, a SOC that only detects and responds is measuring the lack of security instead of improving it.

That reframe lands hardest on patching. Lieuwe Jan is blunt: keep patching, because you depend on it, but the fact that you depend on it is bad news. Known and unknown flaws mean software is flawed by default. Prevention controls, segmentation, multi-factor authentication everywhere, resilient container farms, are where the budget should go, roughly 90% of it by his estimate.

The second half is about automation and culture. Preemptive cybersecurity has two halves: prevent what you can, and when you do get hit, respond automatically instead of routing every decision through a human who phones the customer first. The technical piece is solved: APIs, MCP servers, agents. The hard part is organizational. IT departments and software owners have to build a receiving end for automated countermeasures, which ON2IT calls a zero trust culture.

For the analyst, this is a promotion, not a redundancy. The groundwork, triage, correlation, building a battle plan, hours of work, now runs in under a minute at consistent quality. Humans become the quality gate, codify new attacker playbooks, and handle escalation and strategy. Lieuwe Jan’s verdict for anyone running a reactive-only SOC is the line to take away: there is no future for it.

Threat Talks infographic

Get your Hacker T-shirt

Join the treasure hunt!

Find the code within this episode and receive your own hacker t-shirt for free.

1 + 15 =

Christmas Hacker