The Cybersecurity Defenders Podcast

#262 - Defender Fridays: What does "AI-ready SOC" actually mean? With Dr. Anton Chuvakin from CISO, Google Cloud

9 snips
Oct 31, 2025
Dr. Anton Chuvakin, a Security Advisor at Google Cloud and a leading expert in SIEM and log management, delves into the essentials of an AI-ready security operations center (SOC). He discusses the risks of adopting technology prematurely and highlights key pillars for effective AI integration, including data quality and process maturity. Anton stresses the importance of cultural readiness for balancing human roles with AI capabilities and shares insights on using AI to enhance threat detection and operational efficiency. A must-listen for cybersecurity enthusiasts!
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Buying A Ferrari You Can't Drive

  • Anton recalls organizations adopting tech far beyond their process maturity, like buying a Ferrari when they can barely drive.
  • He observed persistent 1990s-era practices in vulnerability management at some companies despite modern tooling.
INSIGHT

AI Augments, It Doesn't Replace

  • AI should augment SOCs, not replace them; 'AI in SOC' is realistic, 'AI SOC' is misleading.
  • Vendors pitching 'AI SOC' risk overselling if the SOC lacks data access and automation.
ADVICE

Make Data Machine-Accessible First

  • Ensure machines have automated, scalable access to high-quality data via APIs before adding AI.
  • Without reliable machine-accessible logs and structured data, AI integration will fail or underdeliver.
Get the Snipd Podcast app to discover more snips from this episode
Get the app