Agentic AI in the SOC: How AI Is Automating L1 and L2 Security Operations

Agentic AI is fundamentally changing how Security Operations Centres (SOCs) in Malaysia detect and respond to cyber threats. AI-powered SOC platforms can automate up to 80% of L1 alert triage and substantially accelerate L2 investigation — compressing Mean Time to Detect (MTTD) from hours to minutes and Mean Time to Respond (MTTR) from days to hours. For Malaysian organisations facing a documented shortage of trained security analysts, this shift is not a future aspiration: it is an operational necessity that leading enterprises are deploying today.
The L1 and L2 bottleneck crippling Malaysian SOCs
Every SOC operates on a tiered analyst model. L1 analysts are the first line of response — they review incoming alerts, distinguish genuine threats from noise, and escalate what warrants deeper attention. L2 analysts then investigate escalated cases, correlate indicators of compromise, map activity to known adversary behaviours, and recommend containment actions.
The volume problem is severe. A mid-sized Malaysian enterprise monitored by a traditional SIEM-based SOC can generate between 10,000 and 100,000 alerts per day. With industry-standard false-positive rates hovering between 45% and 70% for rule-based detection engines, the majority of analyst time is consumed by events that turn out to be benign. This creates three compounding problems:
- Alert fatigue: Analysts become desensitised to high-alert volumes, increasing the risk of a genuine threat being missed or deprioritised.
- Escalation bottlenecks: When L1 queues overflow, escalation to L2 is delayed — extending dwell time for active threats.
- Talent attrition: Repetitive, high-volume triage work accelerates burnout and resignation among skilled analysts.
Malaysia’s cybersecurity talent shortage compounds every one of these pressures. According to NACSA (National Cyber Security Agency), the demand for cybersecurity professionals in Malaysia significantly outpaces the current supply — a gap that cannot be closed through recruitment alone. Automation is the only credible path to sustainable SOC operations at scale.
How agentic AI transforms alert triage
Agentic AI moves beyond static detection rules. Rather than firing an alert when a single condition is met, AI agents correlate dozens of data signals — endpoint telemetry, network flow records, identity and access logs, threat intelligence feeds, and user behaviour baselines — before making a classification decision. The result is a dramatically more accurate and contextually aware triage layer.
Automated L1 classification
At the L1 layer, AI agents perform the following autonomously and continuously:
- Ingest raw alerts from SIEM, EDR, NDR, and cloud security tools
- Score each alert against a probabilistic risk model trained on historical incident data
- Cross-reference indicators of compromise against MITRE ATT&CK tactics, techniques, and procedures (TTPs)
- Classify alerts as confirmed true positives, likely false positives, or requiring L2 escalation
- Auto-close false positives with a documented rationale — maintaining the audit trail regulators require
This automated L1 layer typically handles 70–80% of incoming alert volume without human intervention, freeing analysts entirely from the most repetitive tier of their work.
AI-assisted L2 investigation
For escalated alerts, AI agents do not merely pass the ticket upward — they arrive with work already done. An AI-assisted L2 investigation package includes:
- A timeline of all related events across every monitored system
- Entity enrichment — pulling context on the involved IP addresses, users, devices, and domains from internal history and external threat intelligence
- MITRE ATT&CK technique mapping — identifying where the observed behaviour sits within a known adversary kill chain
- Blast-radius estimation — which other systems may be affected based on lateral movement indicators
- A recommended containment action, presented for human approval before execution
The human L2 analyst reviews this package, validates the AI reasoning, and approves or modifies the recommended response. This is the human-in-the-loop model — AI does the investigative heavy lifting, humans retain decision authority over response actions.
Human-in-the-loop: why approval gates matter
A common concern among Malaysian CISOs and IT leaders is that AI-driven automation will take containment actions — blocking IPs, isolating endpoints, disabling accounts — without sufficient human oversight. The responsible AI SOC model addresses this directly through structured approval gates.
Every recommended response action above a defined severity threshold requires explicit human sign-off before execution. This architecture serves multiple purposes:
- Regulatory compliance: Bank Negara Malaysia RMiT guidelines and PDPA incident response obligations require documented, auditable decision chains. Approval gates produce this documentation automatically.
- False-positive containment: Even highly accurate AI systems will occasionally misclassify. A human review step before a network isolation action prevents a production system from being incorrectly taken offline.
- Analyst skill preservation: Analysts who review and approve AI recommendations stay engaged with investigations — they are not reduced to passive monitors of a black box.
Simply Data Agentic AI SOC platform implements this approval gate architecture natively, with configurable thresholds that allow organisations to tune the balance between automation speed and human oversight based on their own risk appetite and regulatory context.
False-positive reduction: the operational and financial case
Every false positive costs analyst time and erodes trust in the detection system. Research consistently shows that SOC analysts who distrust their alert pipeline begin applying informal filters — mentally discounting certain alert types — which creates blind spots that sophisticated attackers deliberately exploit.
AI-driven triage reduces false-positive rates by 60–80% compared to legacy rule-based SIEM configurations in real-world deployments. The mechanism is correlation depth: where a SIEM fires on a single threshold condition, an AI agent evaluates the same event in the context of the preceding 30 days of behaviour for that entity, compares it to peer-group baselines, checks threat intelligence for matching IOC patterns, and only then decides whether the signal is actionable.
For a Malaysian enterprise generating 50,000 alerts per day at a 60% false-positive rate, reducing that rate to 15% frees approximately 22,500 analyst-hours per year — equivalent to adding 10 full-time analysts without increasing headcount.
MTTD and MTTR: what AI improvement looks like in practice
According to Gartner’s SOC research, the global average MTTD for a breach in a traditionally operated SOC is 197 days. MTTR — the time from detection to containment — adds weeks or months on top of that. In Malaysia, where ransomware attacks on financial services, healthcare, and government sectors have increased significantly, dwell times of this magnitude translate directly into catastrophic data loss and regulatory breach notification obligations under PDPA.
AI SOC deployments consistently demonstrate:
- MTTD reduction: From days or weeks to minutes — AI agents monitor continuously, without fatigue, across every log source simultaneously
- MTTR reduction: From weeks to hours — pre-packaged investigation packages and one-click response actions compress the response cycle
- 24/7 coverage without shift gaps: AI does not have shift handovers, holidays, or sick days — peak attack windows (Friday evenings, public holidays) are covered with the same capability as business hours
Organisations operating under BNM RMiT incident reporting requirements — which mandate notification within defined timeframes — benefit directly from MTTD compression. You cannot report what you have not detected.
Deploying AI SOC in a Malaysian regulatory context
Malaysian organisations face a layered regulatory landscape: PDPA data protection obligations, BNM RMiT for financial institutions, MCMC licensing requirements for telecommunications providers, and NACSA’s Critical National Information Infrastructure (CNII) protection framework for designated sectors. An AI SOC must be configured to operate within this landscape — not just technically, but in terms of data governance.
Key considerations for Malaysian deployments include:
- Data residency: Log data processed by AI engines should be stored within Malaysia or in approved jurisdictions consistent with PDPA requirements
- Audit trail completeness: Every AI decision — classification, escalation, recommended response — must be logged with sufficient detail to satisfy a regulatory audit
- Incident notification readiness: AI SOC platforms should produce structured incident reports that can be submitted to NACSA or BNM in the required format without additional manual compilation
The SD Platform (SDP) Portal provides a unified operations view across all monitored environments, with compliance reporting dashboards pre-configured for Malaysian regulatory requirements — enabling security teams to move from incident detection to regulatory notification without switching platforms.
From traditional SOC to AI-native: what the transition looks like
Organisations considering an AI SOC transition often ask whether this requires replacing their existing technology stack. In most cases, it does not. AI SOC platforms integrate with existing SIEM, EDR, NDR, and ticketing tools via standard APIs and log forwarding. The AI layer sits above the existing stack, ingesting its outputs and adding the intelligence and automation layer.
A structured transition typically follows three phases:
- Integration and baselining (weeks 1–4): Connect data sources, establish entity baselines, configure alert routing and approval gate thresholds
- Supervised automation (weeks 5–12): AI recommendations run in parallel with existing human triage — analysts validate AI decisions to calibrate the model against the organisation’s specific environment
- Full autonomous L1 + AI-assisted L2 (month 4+): AI handles L1 independently; analysts focus exclusively on L2 investigation and approved response actions
Organisations with existing managed SOC services can integrate the AI layer without rebuilding their operational model — the AI augments and accelerates the existing analyst team rather than replacing it.
Protect your organisation with Simply Data
Simply Data operates Malaysia’s Agentic AI SOC — a purpose-built platform that combines AI-driven L1 triage, AI-assisted L2 investigation, human-in-the-loop approval gates, and full compliance reporting for Malaysian regulatory requirements. Whether you are operating an in-house SOC that needs to scale without proportionally growing headcount, or you are seeking a fully managed AI SOC service, Simply Data provides the platform, the expertise, and the Malaysian regulatory context to deploy it effectively.
Explore the Agentic AI SOC platform or access your security operations data through the SDP Portal. To speak with a Simply Data security consultant about your organisation’s SOC maturity and AI readiness, contact the team for a no-obligation assessment.
Frequently Asked Questions
What is an AI SOC and how does it work in Malaysia?
An AI SOC (AI-powered Security Operations Centre) uses machine learning and agentic AI to automate the detection, investigation, and triage of cybersecurity alerts. In Malaysia, AI SOCs are increasingly deployed to address the shortage of trained security analysts, allowing organisations to maintain 24/7 threat monitoring without proportionally scaling headcount. The AI handles repetitive L1 and L2 tasks while human analysts focus on complex decisions and incident response.
What is the difference between L1 and L2 SOC analysts, and can AI replace them?
L1 SOC analysts handle initial alert triage — classifying events as true or false positives and escalating where needed. L2 analysts conduct deeper investigation, correlate threat indicators, and determine impact scope. AI agents can automate 70–80% of L1 tasks and assist significantly with L2 investigation by cross-referencing threat intelligence frameworks like MITRE ATT&CK. AI does not replace analysts — it eliminates the manual toil so human analysts can focus on decision-making and response.
How does agentic AI reduce false positives in a SOC?
Agentic AI reduces false positives by correlating multiple data signals — endpoint telemetry, network logs, user behaviour analytics, and threat intelligence — before raising an alert. Traditional rule-based SIEMs generate alerts on single-condition matches, producing high noise volumes. AI agents apply probabilistic scoring, historical context, and adversary behaviour models (such as MITRE ATT&CK TTPs) to filter noise, typically reducing false-positive rates by 60–80% compared to legacy SIEM configurations.
What is MTTD and MTTR, and how does AI improve these metrics?
MTTD (Mean Time to Detect) measures how long it takes to identify a security incident after it begins. MTTR (Mean Time to Respond) measures how long remediation takes once an incident is detected. AI-powered SOCs compress both metrics by automating alert correlation and initial investigation steps — reducing MTTD from hours to minutes and MTTR from days to hours. Faster detection and response directly limits the blast radius of any breach.
Is an AI SOC compliant with Malaysian regulations such as PDPA and RMiT?
Yes, when properly configured. Malaysian regulations including PDPA, Bank Negara Malaysia RMiT, and NACSA guidelines require organisations to maintain audit trails, incident logs, and evidence of proactive threat monitoring — all of which an AI SOC provides natively. Human-in-the-loop approval gates ensure that automated response actions are documented and reviewable, satisfying audit requirements. Organisations should verify that their AI SOC vendor stores log data within approved jurisdictions consistent with PDPA data residency expectations.
How much does an AI SOC cost compared to a traditional SOC in Malaysia?
A traditional in-house SOC in Malaysia requires a minimum team of 6–10 analysts running 24/7 shifts, plus SIEM licensing, infrastructure, and management overhead — typically costing RM 1.5 million or more annually for mid-market organisations. An AI-powered managed SOC delivered as a service (MDR + AI layer) typically costs a fraction of that, with pricing based on monitored endpoints or data volume. The cost advantage compounds when factoring in analyst recruitment difficulty in Malaysia current market, where demand for certified security professionals significantly exceeds supply.


