Back Spiceworks How AI agents can string together a fragmented cybersecurity stack
The growing threat of AI-powered attacks has exposed many of the limitations of the existing cybersecurity landscape. While awareness AI-enabled threats and the need for more proactive defense is growing, enterprises are still constrained by a fragmented tools ecosystem.
A CDW survey Opens a new window of 950 security professionals in the U.S. found that 68% of organizations use between 10 and 49 security tools or platforms. This tool sprawl is partly a result of layered security strategies, which require multiple tools to protect different parts of an organization’s digital infrastructure.
For example, EDRs (endpoint detection and response) keep an eye on devices for ongoing threats, IAMs (identity and access management) manage user access and permissions, and firewalls prevent unauthorized network traffic. Each tool produces logs in various formats along with its own set of alerts and severity levels. Analysts frequently need to manually compare data from several dashboards to gain a comprehensive view.
Cybersecurity firm Fortinet concurs Opens a new window that security fragmentation leads to blind spots and inconsistent policy enforcement. This makes it difficult for security teams to correlate signals across systems, resulting in slow detection and response to cyber incidents.
Unified architectures that prioritize tool consolidation and interoperability have tried to address this gap. SIEM (security information and event management) solutions can analyze data across the network to detect suspicious activity, while XDR (extended detection and response) solutions collect and connect data from different layers.
However, they have limitations too. For instance, XDR is most effective within a single vendor ecosystem, while SIEM platforms heavily rely on APIs (application programming interface), which face frequent maintenance issues and broken integrations.
Agentic AI can serve as a centralized orchestration layer, bringing together disparate security tools to improve incident response. While organizations are embracing these autonomous systems, they need to stay focused on comprehending their potential risks and limitations. Addressing the challenges posed by these systems is essential for effective integration
How agentic AI can fix this gap
According to IBM’s 2026 Cost of Data Breach Report Opens a new window , organizations that used AI and automation extensively had an average breach cost of $4 million, compared with $5.93 million for those that didn’t.
The advanced reasoning and coding capabilities of newer GenAI models such as Claude Mythos 5 for finding high-severity vulnerabilities have been in the news recently. Anthropic said in a July blog post Opens a new window that three of its new Claude models hacked into real-world applications of three organizations during a test run. OpenAI Opens a new window made similar claims its models breaking into Hugging Face .
The same AI capabilities used offensively can also be used defensively. AI agents can act as an orchestration layer across a fragmented security environment, connecting signals and automating parts of the investigation.
Lucia Stanham, senior manager, AI at CrowdStrike, explains in a blog post Opens a new window that agents can help with complex, error-prone tasks such as data onboarding in the SOC (security operations center).
“AI agents allow security teams to use natural language to build end-to-end data pipelines, from configuring ingestion to real-time validation to resolving errors as they occur. The result is faster and more efficient data onboarding into SIEM, simpler integration across data sources, and consistent visibility across the environment,” she adds.
According to Microsoft, AI agents Opens a new window can identify and highlight genuine threat alerts, allowing security analysts to focus on high-risk incidents faster. Security analyst agents can be deployed to investigate incidents, correlate signals, and suggest responsive measures. Threat intelligence summarization agents can also summarize threat intelligence into actionable insights.
Together, these agents help reduce manual investigation and speed up incident response across endpoints, identities, email, and cloud workloads.
NVIDIA in its developer blog also reiterates that agentic AI Opens a new window can streamline alert management by automating triage at scale, reduce over-dependence on analyst expertise by standardizing it into repeatable workflows, and fetch investigation context using data-querying tools.
In a recent blog post Opens a new window , cybersecurity firm Stellar Cyber details how agents can investigate credential theft by selecting the data sources to query, identifying relevant MITRE ATT&CK Opens a new window (knowledge base of adversarial behaviors) techniques, and choosing responses that match the policy and risk appetite.
Enterprises should be mindful of the reliability of underlying models and the risk of manipulation. These concerns largely stem from the models’ capacity to operate autonomously, in contrast to GenAI chatbots or conventional automation tools that perform a series of actions via SOAR (security orchestration, automation, and response) platforms.
For instance, when malware is identified, a SOAR platform would run a script to either isolate the endpoint or deactivate an account.
AI agents, on the other hand, can plan, act, and adapt across multi-step workflows autonomously. They can also call APIs, manage tickets, and orchestrate multi-agent chains. When multiple agents are deployed as part of an agentic AI framework, they can assign tasks to AI agents with specific skill sets.
That autonomy can also produce unintended behavior. A case in point is Replit AI’s coding agent, which deleted a company’s entire database during a code freeze last year. Jason M. Lemkin, CEO of the affected company SaaStr.AI, said in a post on X Opens a new window that his enterprise database was deleted without warning even though the agent was clearly instructed to not act without explicit permission. The agent admitted that it made bad decisions in response to empty queries and had run unauthorized commands.
CrowdStrike’s Stanham also warns that attackers can exploit vulnerabilities in agentic AI systems. For instance, adversarial attacks can trick AI into making incorrect decisions, which can have a catastrophic impact for enterprises.
According to a 2025 report Opens a new window by OpenAI and Apollo Research, the deceptive behavior can also be attributed to the way some of the underlying models have been designed. Several frontier models, including OpenAI o3, OpenAI o4-mini, Gemini-2.5 Pro, and Claude Opus-4, have shown deceptive behavior.
Navigating the future of agentic security
AI agents are still a work in progress. They face several limitations such as context length, latency due to GPU queues, and the rising costs associated with deploying LLM-based agents at scale.
Despite these limitations, they are already showing promise in cybersecurity. For instance, last year, a Google AI agent named Big Sleep detected Opens a new window a critical buffer overflow vulnerability in SQLite, an open-source database engine. The early detection allowed Google to patch it before it was exploited.
According to the IBM’s data breach report I referenced earlier, among the 50% of organizations that have deployed agents in their SOC, the use case is limited to threat hunting, response, and containment. Only 18% are using agents in the SOC for vulnerability scans and management. That said, organizations that are using AI extensively for security have cut their breach times by 80 days as compared to organizations that are not.
Stellar Cyber also cautions that AI agents can fail if they are rushed. Enterprises will need to integrate agents with existing SIEM tools rather than replace them. Human oversight will continue to be critical. While agents can triage alerts, correlate signals, and make recommendations, high-impact actions should still be validated by humans.
On June 22 , Toolbox will become Spiceworks News & Insights
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
