How agentic AI is transforming South African security operations

How agentic AI is transforming South African security operations


South African organisations are facing increasingly complex cyber threats. As digital transformation accelerates, cloud adoption grows and regulatory obligations become more demanding, security teams are expected to manage more alerts, greater complexity and increased business risk, often without a corresponding increase in resources.

For managed security service providers (MSSPs), the challenge is amplified. Every new customer introduces different technologies, security controls, compliance requirements and threat profiles. While business growth is positive, it also places significant pressure on security operations centres (SOCs) to maintain speed, consistency and accuracy.

According to Tim Leehealey, vice-president of corporate strategy and operations at Strike48, this is where agentic AI is beginning to change how modern SOCs operate.

“Agentic AI isn’t about replacing analysts or reducing headcount,” says Leehealey. “The real opportunity is improving how much work a security team can realistically absorb before operational strain begins to affect decision quality. As organisations grow, the challenge isn’t simply processing more alerts, it’s maintaining consistent, high-quality decisions as complexity increases.”

The challenge isn’t more alerts, it’s managing complexity

Traditionally, scaling a SOC has followed a predictable pattern. More customers generate more alerts, leading organisations to hire more analysts, introduce additional operational processes and create new layers of management.

While this approach works initially, it eventually reaches a point where adding more people delivers diminishing returns.

Analysts spend increasing amounts of time switching between security tools, gathering context, correlating telemetry, validating information and determining whether an alert genuinely represents a threat. Although service levels may still be achieved, maintaining that performance requires significantly more effort behind the scenes.

For South African organisations already facing a shortage of experienced cybersecurity professionals, this operational pressure continues to grow.

Agentic AI improves workflows, it does not replace people

One of the biggest misconceptions surrounding artificial intelligence in cybersecurity is that it exists to replace SOC analysts. In reality, agentic AI is proving most valuable by enhancing how security professionals work.

Rather than simply automating isolated tasks or generating additional alerts, agentic AI continuously gathers evidence, correlates activity across multiple security platforms, enriches investigations with contextual intelligence and presents analysts with a far more complete understanding of an incident before human intervention is required.

Instead of spending valuable time collecting information, analysts begin investigations with much of the groundwork already completed.

“The workflow becomes less sensitive to volume because the effort required for each investigation becomes more consistent,” explains Leehealey. “Analysts spend less time rebuilding context and more time applying their expertise where it matters most.”

Addressing South Africa’s cybersecurity skills shortage

South Africa continues to experience a well-documented shortage of skilled cybersecurity professionals, making it difficult for organisations to expand security teams at the same pace as business growth.

Agentic AI provides an opportunity to maximise the effectiveness of existing security resources. By automating repetitive investigative tasks and accelerating contextual analysis, organisations enable experienced analysts to focus on higher-value activities such as threat hunting, incident response and proactive risk reduction.

“South African organisations are under pressure to strengthen their cyber resilience while managing constrained budgets and limited security skills,” says Timothy Whitaker, engineering team lead and lead developer at Maidar Secure. “Agentic AI allows organisations to increase the capacity and effectiveness of their existing SOC teams without compromising the quality of security decision-making. The goal isn’t fewer analysts, it’s empowering skilled professionals to spend their time solving real security problems instead of manually piecing together data.”

Consistency becomes the real advantage

As organisations grow, maintaining consistent security decisions becomes more difficult. Different analysts naturally investigate incidents differently, and as alert volumes increase, inconsistencies in prioritisation, escalation and response can begin to emerge.

Agentic AI helps create a more structured investigation process by automatically assembling telemetry, historical activity, threat intelligence, environmental context and supporting evidence before an analyst begins their assessment. This creates greater consistency across the SOC while reducing investigation times and improving governance.

For highly regulated South African industries, including financial services, healthcare, telecommunications, mining and the public sector, this consistency supports stronger compliance, improved auditability and more predictable security outcomes.

Rethinking how security operations scale

According to Leehealey, the most significant benefit of agentic AI is changing how organisations think about growth itself.

“As MSSPs scale, relying solely on individual expertise becomes increasingly difficult,” he says. “Agentic AI introduces greater consistency into investigations by ensuring analysts begin with a more complete understanding of every incident. Capacity grows not simply because there are more people, but because each analyst can operate more effectively within the same operational framework.”

Whitaker believes this evolution is particularly important for South African businesses embracing cloud services, hybrid work and AI-driven digital transformation.

“Cybersecurity can no longer rely solely on adding more people to keep pace with increasing demand,” he says. “The future lies in combining experienced security professionals with intelligent automation that strengthens investigations, improves response times, and allows organisations to scale securely as their digital environments continue to evolve.”

Building the next-generation SOC

Cybersecurity is no longer measured solely by how quickly organisations detect threats. Increasingly, success depends on whether security operations can continue to perform effectively as businesses expand and cyber risks become more sophisticated.

Agentic AI represents a significant evolution in how SOCs scale. Rather than continually increasing headcount to absorb additional demand, organisations can build intelligent security workflows that reduce operational friction while enabling analysts to make faster, more informed decisions.

For South African organisations navigating growing cyber threats, tightening regulatory expectations and an ongoing cybersecurity skills shortage, agentic AI offers a practical path towards building more resilient, scalable and effective security operations.

About Maidar Secure
Maidar Secure delivers modern cybersecurity and managed security services designed to help organisations strengthen cyber resilience and improve operational visibility. Its offerings include SOC services, compliance, cloud security, data protection, endpoint security, application security and network security solutions tailored to modern enterprise environments.

About Strike48
Strike48 is the agentic security operations platform that combines complete log visibility with AI agents that run investigations, automate detection engineering and orchestrate response at machine speed, 24/7. A product brand from Devo Technology, Strike48 is headquartered in Boston in the US.