For state and local government agencies, the rise of AI-driven cyber threats has made a tough situation worse. Many security operations centers (SOCs) were already struggling with limited budgets and staffing shortages, forcing analysts into a constant state of triage and contributing to alert fatigue and burnout. Now, malicious actors are using AI to discover and exploit vulnerabilities faster and launch attacks that are more difficult to defend against.
To keep pace, agencies need AI-powered security. An agentic SOC can automate routine tasks, allowing analysts to focus on work that requires human judgment. Security analysts move up to become true threat engineers — experts who manage, tailor and validate the agents they support.
An agentic SOC is even more effective as part of a statewide cybersecurity strategy. Rather than operating in isolation, state and local agencies can share insights through a data mesh approach, giving security leaders greater visibility into threats while allowing agencies to retain control of their own data.
“We need to treat the entire state ecosystem as a shared defensive perimeter,” said John Harmon, Regional Vice President for Cyber Solutions for Global Public Sector at Elastic.
In this video interview, Harmon discusses how state and local agencies can build on an agentic SOC to shift from a fragmented defense to collective resilience. Topics include:
- Defining a clear human-on-the-loop strategy for an agentic SOC
- Improving the cost-effectiveness of managing cyber telemetry
- Aligning agentic SOC with whole-of-state requirements



Leave a Reply
You must be logged in to post a comment.