
Agentic SOC platforms promise machine-speed incident response. But a January 2026 adversarial evaluation — OpenSec, by researcher Jarrod Barnes — found that three of four frontier AI models, acting as autonomous incident response agents, executed containment with false positive rates between 82% and 97%. Only one model demonstrated partial calibration. The conclusion: the gap is not in detection. It is in restraint. This paper argues that calibration — knowing when not to act — is the defining engineering and governance challenge of the agentic SOC era. It covers the complete deployment lifecycle: a three-phase migration roadmap with hard exit criteria, a calibrated reference architecture, ownership-risk-entity access governance beyond product RBAC, MITRE ATT&CK and ATLAS integration, SOAR transition strategy with specific vendor guidance, cloud-native and OT/ICS environment considerations, inter-agent trust and the ASI07 failure mode, cost modelling and capacity planning, a KPI and SLA framework, and human factors including automation bias, skill atrophy, and the analyst career path. Thirteen prioritised recommendations for security engineers, CISOs, and AI leaders. 27 citations. Research and drafting assistance provided by Claude (Anthropic); all analysis and conclusions are the author's own.
agentic SOC, AI security, incident response, calibration, security operations, MITRE ATT&CK, MITRE ATLAS, SOAR, governance, non-human identity, OT security, cloud security
agentic SOC, AI security, incident response, calibration, security operations, MITRE ATT&CK, MITRE ATLAS, SOAR, governance, non-human identity, OT security, cloud security
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
