What will a Mythos-resilient SOC look like? International Security Journal speaks with Edward Wu, Founder and CEO at Dropzone AI, to find out more.
Security operations teams are under pressure, with analysts expected to investigate high volumes of alerts while keeping pace with more sophisticated threats.
The emergence of AI models capable of discovering vulnerabilities and generating working exploits adds another layer of complexity…
In this exclusive interview with ISJ, Edward Wu, Founder and CEO at Dropzone AI, discusses how security operations centre (SOC) teams can think about AI agents, where they can take on the work directly – and where human judgement still needs to remain firmly in control.
How do models like Mythos change the situation for SOC analysts?
Models such as Mythos make it easier, and cheaper, for attackers to find zero-day vulnerabilities and turn them into working exploits.
Vulnerability management teams are likely to feel the first impact, as they face a sharper increase in the number of issues they need to assess, prioritise and patch.
But patching will not keep pace with every new vulnerability.
That makes detection and response even more important.
If attackers have a greater chance of getting through perimeter defences, the SOC becomes the line between an initial foothold and a much wider compromise.
This does not necessarily mean alert volumes will double overnight.
The bigger concern is that more of those alerts may point to genuine activity.
For already stretched analysts, the priority becomes finding more investigative capacity so they can assess more alerts, faster, with greater confidence.
When should security teams expect LLM-enabled attacks to reach the SOC?
Security teams are already having to think about what this means in practice.
Commercial large language models already show similar capabilities and comparable open-source models are likely to follow.
Once that happens, attackers will have greater freedom to experiment and put them to work.
The most immediate risk is vulnerability discovery and exploit development.
Researchers are also exploring how these models could support automated penetration testing and lateral movement, but the clearest shift is their ability to identify vulnerabilities that previous generations of models could not reliably find.
Security leaders should be assessing whether their SOC has the coverage, triage capacity and response maturity needed to deal with a higher rate of successful initial compromise before these attacks become commonplace.
Is the threat from Mythos-type LLMs being overblown?
The threat should not be dismissed, but it does require some context.
Mythos was not a sudden leap from limited capability to full autonomy.
It was more of a threshold moment that has been building for several years as the use of large language models become more prevalent in cybersecurity.
However, there are still a few limitations. LLMs are currently strongest when they have access to source code, which makes open-source software an area of concern.
Black-box vulnerability discovery, where the model does not have the underlying source code, remains much harder and still favours experienced human researchers.
Organisations must prepare to protect complex environments, with security operations needing to become more automated, scalable and resilient.
How should the role of the SOC change as attackers adopt AI?
The role of the SOC is unlikely to change dramatically.
Teams will still need to detect, investigate, prioritise and respond to threats.
But the intensity at which they do this will change dramatically.
If attackers use AI to move faster and at a greater scale, defenders need AI agents working at that same scale to increase their own capacity.
One of the clearest opportunities is using AI agents to automate alert investigation.
An AI SOC analyst can review alerts, form hypotheses, gather evidence from connected tools and assess whether an alert is likely to be a true or false positive.
That gives human analysts more time to focus on genuine incidents, complex judgement calls and higher-value projects.
For security leaders, the value comes from speed and the ability to cover more ground.
Many SOCs only have time to investigate a fraction of their alerts properly.
AI agents let teams investigate more alerts consistently, including those that might otherwise stay in the queue.
What should remain firmly in human hands?
AI agents can support investigation and, in some cases, initial containment.
However, there are still areas of security operations where human judgement must remain central.
End-to-end remediation is a good example of this. In complex organisations, remediation depends on context, accuracy and a clear understanding of the business impact if the wrong action is taken.
The same is true for work that relies on influence and organisational change. Improving security coverage may mean working with application teams to add telemetry, deploying additional sensors or encouraging other parts of the business to change established processes.
They may start with a technical requirement, but they still rely on trust, context and human ownership.
That makes the future SOC less about choosing between people and AI, and more about deciding which tasks each is best placed to handle.
AI agents can take on repetitive investigative work, while human analysts remain accountable for the judgement calls and decisions that carry operational risk.
Who has the advantage, AI-enabled attackers or AI-enabled defenders?
Attackers may gain an early advantage because they can move quickly, experiment aggressively and use large language models for vulnerability discovery, exploit development and more targeted social engineering.
Defenders will need to close that gap by putting AI agents to work across security operations at a comparable scale.
This is important because most organisations are not going to double or triple their cybersecurity budgets or SOC headcount in response.
For defenders, the opportunity is to reduce the pressure on human analyst capacity.
If AI agents can take on repetitive investigative work around the clock, human teams can focus on the areas where judgement, accountability and strategic decision-making are still essential.
What will the future SOC look like?
The future SOC is likely to look like a team of experienced practitioners directing multiple AI agents.
Human analysts will increasingly act as team leads, defining scope, reviewing outputs, validating conclusions and remaining accountable for final decisions.
That does not mean humans disappear from security operations.
Some tasks remain too complex and consequential for full automation, including end-to-end remediation, decisions that require deep organisational context and work that depends on influencing other teams to improve telemetry or change processes.
For senior security professionals, the priority is understanding where AI can safely increase scale and where human expertise must remain in control.
The strongest SOCs will be those that use AI to extend their teams’ reach, without handing over the judgement calls that still need human accountability.