
CyberWire Daily The cloud that spies back.
Dec 17, 2025
Doron Davidson, the General Manager and Managing Director of Security Operations at CyberProof Israel, discusses the evolution of security operation capabilities. He highlights the concept of agentic SOCs, emphasizing their potential by 2027 for autonomous alert management. Doron also shares insights on which SOC functions stand to benefit the most from automation and how analysts' roles will transform into consultative and management positions. With a focus on safeguards and practical implementations, he offers valuable advice for organizations starting their agentic transformation.
AI Snips
Chapters
Transcript
Episode notes
Agentic SOC Vision And Timeline
- An agentic SOC aims to be a fully autonomous security operations center by 2027 that handles alerts end-to-end with AI agents.
- Doron Davidson says semi-autonomous SOCs are today's reality while full autonomy remains a future milestone.
Analyst Role Will Evolve To Consultant
- Analysts will shift from routine analytics to consultative roles, focusing on explaining agent outputs to customers.
- Davidson expects analysts to become SMEs who design and develop new agents and manage agent orchestration.
Enforce Least Privilege And Human Oversight
- Apply least-privilege for each agent and enforce strict data boundaries to avoid cross-customer or cross-team data leakage.
- Keep a human-in-the-loop for verification, placing them inline or as post-execution oversight depending on criticality.
