Cybersecurity firm
Trend Micro is introducing
agentic AI capabilities that are aimed at helping organizations and MSSPs address ongoing issues with SIEM operations, from cost and complexity to manual operations and alert overload.
Executives added that combining the SIEM AI agents with Trend Micro’s cybersecurity digital twin technology creates more proactive and responsive security operations that are necessary for addressing the increasingly adaptive and AI-driven cyberthreats facing them.
Trend Micro announced the agentic SIEM capabilities this week, about two weeks after the digital twin technology was
introduced in late July.
Rachel Jin, Trend Micro’s chief enterprise platform officer, called the Irving, Texas, company’s Vision One Agentic SIEM “a major stepping stone to our long-term vision for full, AI-driven SecOps” and added that it hails “a future in which security teams will have more time to work on strategic tasks, safe in the knowledge that our agentic AI has their backs.”
The offering uses autonomous data analysis and anomaly detection and response rather than manual log and alert monitoring to reduce the time needed to detect and mitigate threats and combines extended retention of data – up to seven years of archival data and two years of analytic retention for detection, threat hunting, and compliance – with the ability to search archival logs to better help meeting audit and regulatory demands, according to the company.
When investigating an incident, the AI agents automatically correlate data from multiple sources to speed up the process and improve the accuracy of the results. Agentic SIEM supports more than 900 data sources, provides three-day onboarding for new log types – a number that will be reduced to three hours by next year, Trend Micro says – and pulls in third-party telemetry along with Trend Micro’s owns sensors that collect data from endpoints, email, networks, servers, identity systems, and the cloud.
AI Agents and Digital Twins
Using agentic SIEM with the digital twin technology means that organizations and MSSPs can use the virtual models to more proactively detect and mitigate security risks, particularly in highly sensitive environments like healthcare, supply chains, predictive maintenance, and smart buildings, according to Trend Micro.
In a
white paper about AI agent-enhanced digital twins, Trend Micro co-founder and CEO Eva Chen wrote about the challenges security teams face – not only AI-armed threat groups but also managing increasingly complex digital ecosystems and supply chains. Threat detection, risk assessments, and remediation are becoming more proactive and innovative, but there are still obstacles for security and IT teams that play from behind, Chen wrote.
“Enter the digital twin: the visibility needed to secure your environment becomes the foundation for building a powerful, real-time simulation layer,” she wrote. “This allows security and IT leaders to safely validate defenses without ever touching production systems.”
Demand for Agents is Growing
A broad array of cybersecurity vendors are promoting AI agents for
SIEM operations.
“Innovations like generative AI (GenAI) and agentic AI are offering new ways to manage risk and reduce noise,”
CrowdStrike wrote in April. “GenAI is already being used to help analysts summarize incident details, recommend responses, and even write correlation rules. Agentic AI introduces the potential for autonomous systems that can pursue investigative goals, simulate attacker behavior, and streamline response actions – all without constant human input.”
The Argument for AI in Security
Leaning on AI for SIEM makes sense, according to Krista Case, research director with
The Futurum Group, told MSSP Alert.
“Traditional SIEM systems struggle with the sheer volume of security data generated daily, leading to missed threats, slow time-to-detection, and lengthy investigation times,” Case said. “One of the biggest opportunities I see is using AI to quickly and automatically correlate vast data sets, and to add contextualization. The result is reduced alert fatigue through improved accuracy of threat detection, and an ability to identify subtle and sophisticated attack patterns that rule-based systems might miss.”
AI also can be used to accelerate vulnerability and incident response through recommended playbooks, as well as potentially automated and autonomous actions, she noted.
Interest in AI for Security is High
Cybersecurity pros see a crucial role for AI and agents in protecting organizations against cyberthreats. According to a
report by security firm Darktrace, 95% of those surveyed said that AI-powered cybersecurity solutions significantly improve the speed and efficiency of preventing, detecting, responding to, and recovery from cyberattacks and 88% said using AI in cybersecurity is freeing up time for security teams and allowing them to be more proactive.
Case said she is seeing a similar appetite for adopting AI for the cybersecurity stack “in order to scale and upskill security operations teams. We do see that security teams are proceeding with caution and a healthy amount of skepticism. The trick will be keeping the human in the loop, and ensuring that all AI-generated insights and recommended actions are clearly explainable.”