Arctic Wolf has expanded its
Aurora Agentic SOC and launched a
cyber resilience bundle that combines managed security operations, exposure management, endpoint protection, incident response, and up to $3 million in warranty coverage.
Arctic Wolf is broadening its role across the security lifecycle with its Agentic SOC, designed to automate more investigative work, while the resilience bundle extends the company’s reach into remediation, recovery, and financial protection. For customers, the company is trying to reduce the operational burden of running security tools and AI systems internally.
Pushing AI deeper into SOC operations
The Aurora Agentic SOC runs on the company’s Aurora Superintelligence Platform, which Arctic Wolf said now processes more than 10 trillion security events each week. The Aurora Agentic SOC, on the other hand, has resolved more than three million security cases and conducts more than 200,000 investigations weekly.
At the center of the platform is Arctic Wolf’s Swarm of Experts architecture, which coordinates specialized AI agents across different stages of an investigation. Those agents gather evidence, analyze activity, validate findings, and determine whether a case can be closed or needs additional review.
Will May, chief revenue officer at Arctic Wolf, told MSSP Alert that the company built Aurora as an operating model rather than a layer of AI features added to an existing SOC platform.
“Most solutions either add AI features to legacy SOC workflows or provide tools that require customers to build, operate, and govern their own agentic environment,” May said. “The Aurora Agentic SOC is a complete operating model built on the Aurora Superintelligence Platform, where AI acts as the primary engine of investigation and response through the Swarm of Experts, while human experts remain in the loop for judgment, validation, and accountability.”
Arctic Wolf said three components support that model. The Swarm of Experts coordinates agents across SOC functions. The Security Operations Graph draws on more than 14 years of security operations experience and data from more than 10,000 customer environments. The AI Trust Engine applies validation, guardrails, and human oversight.
“The result is a turnkey, agent-led SOC that delivers machine-speed operations without asking customers to become AI operators themselves,” May said.
Arctic Wolf said the system now resolves more than 60% of case volume as high-confidence closures. More complex cases are escalated to human analysts, with roughly one-third of those cases receiving final human verification. Some investigations are completed in as little as 12 seconds, according to the company. Arctic Wolf also said customers are resolving cases 26% faster year over year.
Mean Time to Trusted Action focuses on usable guidance
Arctic Wolf is also introducing Mean Time to Trusted Action, or MTTA, a metric designed to measure how quickly a customer receives guidance that has been investigated, validated, and turned into a recommended action.
Security teams commonly track Mean Time to Detect and Mean Time to Respond. Those metrics measure speed at specific stages of an incident, but they do not always capture the time analysts spend verifying an alert, gathering context and deciding what to do next.
“The intent behind Mean Time to Trusted Action is to measure not simply how quickly an event is processed but how quickly organizations receive guidance they can trust and act on,” May said.
He said the goal is to provide customers with the context and recommended response in one alert rather than leaving teams to piece together information from multiple notifications.
“In security operations, speed only matters if teams can act on the information with confidence,” May said.
Cost claims show infrastructure and staffing requirements
Arctic Wolf is also positioning predictable cost as part of its Agentic SOC strategy. Building an internal agentic SOC can require additional spending on security data infrastructure, integrations, cloud compute, storage, software, and personnel. Organizations also need staff capable of validating AI outputs, setting governance rules, and maintaining the environment over time.
Arctic Wolf said its service includes unlimited data ingestion and investigations under a predictable pricing model. The company also said the platform can be deployed in about 10 days and is roughly 12 times more cost-effective than building and maintaining an agentic SOC internally.
May said that the estimate is based on the costs organizations typically face when they try to operationalize agentic AI on their own.
“Those costs include deploying and maintaining security data infrastructure, integrating multiple tools, managing compute and storage requirements, operating AI systems at scale, and hiring or retraining personnel to build, validate, and govern those environments,” he said.
Cyber resilience bundle combines prevention and recovery
Alongside the Agentic SOC updates, Arctic Wolf has also launched a cyber resilience bundle that brings several of its existing products and services under one offering.
The bundle includes Aurora Managed Detection and Response, Attack Surface Management, Vulnerability Management, patch management, Managed Endpoint Defense, and Managed Security Awareness. It also includes Aurora Incident Response 360 for containment and recovery.
The offering is intended to help customers identify exposed assets, prioritize vulnerabilities, detect threats, and manage the response when an incident occurs.
Eligible customers may also receive up to $3 million through Arctic Wolf’s Security Operations Warranty. The warranty adds a financial component to the company’s managed security model, but access to the full amount will depend on the program’s terms and coverage requirements.
“Like any warranty program, the Security Operations Warranty includes specific terms, conditions, and coverage requirements,” May said.
Warranty is designed to complement cyber insurance
Arctic Wolf said the warranty is intended to work alongside cyber insurance rather than replace it.
“The Security Operations Warranty is intended to complement, not replace, cyber insurance,” May said.
Depending on the incident and the terms of each agreement, the warranty and the insurance policy may cover different portions of response, recovery, or financial loss.
“Depending on the circumstances of an incident and the applicable policy and warranty terms, cyber insurance and the Security Operations Warranty may address different aspects of loss or recovery,” May said.
Customers will need to understand how claims are coordinated, which provider pays first, and whether receiving warranty funds affects an insurance payout. Those questions are likely to involve the customer, Arctic Wolf, the insurance carrier, and, in some cases, the broker or incident response provider.
The updates show that managed security services are expanding beyond alert monitoring. AI agents can handle more routine investigations, helping MSSPs work through cases faster. Providers still need to know how decisions are made, when humans step in, and whether the results can be reviewed or audited.