Eric Foster, CEO of TENEX.ai, thinks there’s still way too much manual work happening inside the SOC. And the way he critiques legacy MDR is even sharper: it is, he says, “a people business dressed up as technology.” He says that he wants to challenge legacy MDR providers and an operating model that still depends heavily on people to deliver the service.
TENEX’s answer is to hand more of that work to AI agents, while keeping humans involved in the decisions that matter. The company says its
platform investigates 100% of alerts, with
Tier 1 triage completed in under a minute and
go-live in as little as seven days for customers already using Google SecOps or Microsoft Sentinel. TENEX has been running the platform with production customers for about 18 months and is now making its Turnkey offering generally available.
For MSSPs, the question gets pretty practical pretty quickly: if AI agents can do more of the repetitive SOC work, how many analysts do you actually need to deliver the service, and what does that do to the cost?
“The easy idea is just to make security operations 10x more efficient, more effective, faster, and more successful,” Foster told MSSP Alert.
He added, “And ultimately, the idea of our platform is to materially drive down the cost of security operations while improving the quality and the outcomes for the customer.”
TENEX targets faster SOC deployment
Deployment is one area where TENEX is trying to shorten the traditional SOC rollout process. The
turnkey offering is designed primarily for organizations already using Google SecOps or Microsoft Sentinel. TENEX sits on top of those environments rather than requiring customers to replace their underlying security operations platform.
“If an organization, whether it's an MSSP or a company already operating on Google SecOps or Sentinel, they can be live with our turnkey in seven days or less,” Foster said.
TENEX has completed deployments faster in cases where customers already had the required environment in place, according to Foster. Deploying a new Google SecOps or Sentinel environment can extend that timeline. For MSSPs, deployment time can become a practical constraint when rolling out services across multiple customers. A platform that works within existing Sentinel or Google SecOps environments gives service providers another way to introduce automation without rebuilding the customer’s security stack.
Agents handle investigation, humans remain accountable
The bigger question around agentic SOC technology is how far automation should be allowed to go. TENEX is positioning its agents to handle much of the alert lifecycle, including enrichment, investigation and triage. Foster said the company designed the platform around human accountability from the start.
“One of our fundamental bets that we made from the first day of the company was that the value in artificial intelligence wasn't replacing the human. It was augmenting it," Foster said. “One of the big differentiators in our approach is we have a human accountable for every single decision.”
TENEX says its agents have been trained and tested against the work traditionally performed by Tier 1 SOC analysts. The company is measuring those systems against human analyst performance rather than expecting AI to operate without errors.
“Perfect isn't the benchmark. The benchmark is, is it better than a human driver?” Foster said, comparing the model to autonomous vehicles.
"When we say we can process all of your alerts in under a minute and do it better than a human, we’re not saying the AI will never make a mistake. We’re saying we can demonstrate that it makes fewer mistakes than we’ve seen from human-driven operations while running some of the largest SOCs in the world at scale."
Foster says the company has extensively trained and fine-tuned AI agents that operate across a company’s security tooling over the past 18 months, and tested that extensively and collected evidence showing that those agents can be more reliable than a traditional Tier 1 analyst.
AI-native architecture as the differentiator
But TENEX is entering a market where MDR providers, security platforms and newer AI-native vendors are all adding agents to investigation and response workflows.
Foster separates those competitors into two groups: established security providers adding AI to existing platforms and companies that were built around AI from the beginning. "When you look at legacy MSSP and MDR companies, everyone is adding AI to their services. The difference, from our perspective, is between companies adding the technology after the fact and companies built natively around it."
TENEX also competes with AI-native security companies. Foster argues that its managed services background is an important part of the distinction.
“We are the only company in it that’s built and run by people who come from the managed services industry. We know what it's like and what it takes to build a service at scale.”
A different cost model for MDR
Foster has also been vocal about what he sees as the limitations of the traditional MDR model, describing legacy MDR as a people business supported by technology. His argument comes from his own experience building managed security companies.
"If you look back at the original MDR model, the idea was that we were going to bring much more technology and automation into managed detection and response. Ultimately, I don’t think the industry achieved that vision. MDR largely became a services business that used technology to make people somewhat more efficient. It did not become the software-driven, automation-driven outcome that many of us originally envisioned."
Foster sees generative and agentic AI as giving security providers another chance to automate more of the work that MDR originally set out to automate.
“I think this is what the amazing thing of this AI revolution has proven is that it is possible to achieve this vision that we all had of better, faster cybersecurity outcomes.”
TENEX is asserting that alert investigation and Tier 1 triage can move much further toward automation while service providers keep control of the customer relationship and focus their teams on higher-value security work. For MSSPs, the real shift will come down to the work that still requires people and where automation can take over repeatable SOC tasks.
TENEX’s pitch to MSSPs
TENEX partners with organizations through both resale and service-provider models. Foster says, "We’re here to help organizations modernize their existing relationships, scale more effectively and improve efficiency."
For organizations that don’t have an MSSP, or that have outgrown a co-managed model, TENEX also offers a fully managed service. MSSPs can use the platform to make their own SOC operations more efficient, or resell TENEX’s managed service instead of building out larger analyst teams.
But Foster sees AI changing how MSSPs allocate people inside the SOC. He asserts, "What changes with AI is some of the specific work MSSPs need to do. Does it still make sense for an MSSP to hire a room full of SOC analysts to provide the same service if technology can make each analyst 10 times more efficient? In many cases, the answer is no."
Foster argues that some MSSPs may be better off reselling TENEX’s fully managed service or using the platform to make their existing SOC more efficient, freeing their teams to provide other managed services they previously lacked the capacity to offer.
MSSPs can use automation for repetitive SOC work and shift staff toward services that require deeper customer knowledge, security expertise and direct engagement.
But this also raises an important channel question: who owns the customer?
Foster said TENEX sees MSSPs as maintaining that relationship when the service provider brings TENEX into an account.
"Whether it is an MSP or MSSP, that partner is delivering a broader set of managed services. What we provide is the security operations component, specifically around detecting, investigating and responding to alerts. The MSSP owns the customer relationship and continues to provide the broader value around it. We are making that specific security operations function more effective."
He made the point more directly: “The MSSP owns the customer, provides a tremendous amount of value around it. We're just taking the specifics of detecting and responding to alerts and making that dramatically more effective.”