SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Zscaler launches Agentic SOC to fight AI-driven attacks

Zscaler launches Agentic SOC to fight AI-driven attacks

Wed, 9th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Zscaler has launched Zscaler Agentic SOC, now available globally.

The offering is aimed at security operations teams facing AI-driven attacks. It combines Zscaler's telemetry, threat intelligence and automated remediation with integrations into third-party security tools.

Built with an AI-first design, the system uses models from Anthropic and OpenAI alongside Zscaler's own data. It links exposure management with threat detection and response, allowing risks identified in one part of a customer's security environment to feed directly into incident workflows.

The launch comes as security teams face growing pressure from attacks that are faster and harder to trace. Zscaler's ThreatLabz research unit said it is seeing more evasive techniques, including the use of trusted websites to host attacks, misuse of legitimate remote management tools and browser-based attacks.

Central to the announcement is Zscaler's claim that it can unify network, identity, endpoint, cloud and AI-related signals from its Zero Trust environment. Its platform processes 750 billion daily Zero Trust transactions, which the company says gives analysts more context for detection and response.

AI in the SOC

The new product uses specialised AI agents to handle tasks including alert triage, root-cause investigation, verdict assignment and response workflows. According to Zscaler, the agents have been trained and tuned using more than a decade of security operations, managed detection and response, and threat-hunting experience.

Zscaler also said the product supports what it describes as closed-loop remediation. In practice, this means the system can isolate compromised users, block command-and-control communications and limit lateral movement, while also connecting to third-party tools for more tailored responses.

Deepen Desai, Executive Vice President of Cybersecurity at Zscaler, said the launch was intended as a direct response to the pace of attacks facing security operations teams.

"AI-driven attacks are moving faster than traditional SOC models were ever designed to handle," said Deepen Desai, Executive Vice President of Cybersecurity at Zscaler. "Agentic SOC is a fundamental rethinking of security operations, built with agentic capabilities at its core to reduce exposures proactively, extend human expertise with AI agents and contain threats at machine speed. With unmatched inline telemetry, specialized AI agents and closed-loop remediation, Zscaler is giving security teams the visibility and control they need to outpace modern attackers."

External view

The wider security industry has been debating how far automation and generative AI can help overstretched operations centres dealing with high alert volumes, staffing shortages and fragmented tooling. Analysts have also warned that the same technologies are giving attackers new ways to scale campaigns and adapt tactics more quickly.

Allie Mellen, Principal Analyst and author of Code War: How Nations Hack, Spy, and Shape the Digital Battlefield, said the changing nature of attacks was pushing organisations back to core security principles.

"The past year has made one thing clear: AI attacks are fundamentally changing the threat landscape, operating at a speed, scale, and level of adaptability that looks very different from traditional human-led activity," said Allie Mellen, Principal Analyst and Author of Code War: How Nations Hack, Spy, and Shape the Digital Battlefield. "To defend effectively, organizations must double down on the fundamentals - Zero Trust principles, preventing data exfiltration, limiting access, and making AI attacks as expensive as possible.."

Zscaler is positioning the product around that Zero Trust approach. The company said the platform's inline position allows it to observe activity across users, devices and applications in real time, with that telemetry feeding into both exposure management and active incident response.

Customer use

Zscaler also pointed to early customer experience to support the operational case for the product. One recurring problem for large security teams is that analysts can spend too much time triaging alerts rather than hunting threats or investigating the most serious incidents.

Andrea Liccardi, Senior Cybersecurity Manager at Maire Tecnimont, described that challenge in a customer quote released alongside the launch.

"Our team was drowning in alert noise, forcing top analysts into triage instead of proactive threat hunting," said Andrea Liccardi, Senior Cybersecurity Manager at Maire Tecnimont. "Zscaler Agentic SOC gives us full attack-path context using telemetry we already had in place, helping our team move from fragmented signals to faster, more informed decisions. Zscaler has proven to be one of our most valuable cybersecurity partners, continuously helping us improve operational efficiency, visibility, and our ability to focus our analysts on what really matters."

Zscaler said the product is part of an open platform approach, allowing third-party findings and controls to be pulled into the same workflow. That means vulnerability information and threat data from other vendors can add context to incidents and trigger automated actions within the operations process.

The company said the system's context graph correlates Zscaler telemetry with external data to map and prioritise incident chains, while continuous threat hunting is supported by human experts from Zscaler and Red Canary.