MSSP, Generative AI, SIEM

Trend Micro Targets MSSPs with Agentic AI and Digital Twin-Enhanced SIEM

AI with young man in the night

Cybersecurity firm Trend Micro is introducing agentic AI capabilities that are aimed at helping organizations and MSSPs address ongoing issues with SIEM operations, from cost and complexity to manual operations and alert overload.

Executives added that combining the SIEM AI agents with Trend Micro’s cybersecurity digital twin technology creates more proactive and responsive security operations that are necessary for addressing the increasingly adaptive and AI-driven cyberthreats facing them.

Trend Micro announced the agentic SIEM capabilities this week, about two weeks after the digital twin technology was introduced in late July.

Rachel Jin, Trend Micro’s chief enterprise platform officer, called the Irving, Texas, company’s Vision One Agentic SIEM “a major stepping stone to our long-term vision for full, AI-driven SecOps” and added that it hails “a future in which security teams will have more time to work on strategic tasks, safe in the knowledge that our agentic AI has their backs.”

The offering uses autonomous data analysis and anomaly detection and response rather than manual log and alert monitoring to reduce the time needed to detect and mitigate threats and combines extended retention of data – up to seven years of archival data and two years of analytic retention for detection, threat hunting, and compliance – with the ability to search archival logs to better help meeting audit and regulatory demands, according to the company.

When investigating an incident, the AI agents automatically correlate data from multiple sources to speed up the process and improve the accuracy of the results. Agentic SIEM supports more than 900 data sources, provides three-day onboarding for new log types – a number that will be reduced to three hours by next year, Trend Micro says – and pulls in third-party telemetry along with Trend Micro’s owns sensors that collect data from endpoints, email, networks, servers, identity systems, and the cloud.

AI Agents and Digital Twins

Using agentic SIEM with the digital twin technology means that organizations and MSSPs can use the virtual models to more proactively detect and mitigate security risks, particularly in highly sensitive environments like healthcare, supply chains, predictive maintenance, and smart buildings, according to Trend Micro.

In a white paper about AI agent-enhanced digital twins, Trend Micro co-founder and CEO Eva Chen wrote about the challenges security teams face – not only AI-armed threat groups but also managing increasingly complex digital ecosystems and supply chains. Threat detection, risk assessments, and remediation are becoming more proactive and innovative, but there are still obstacles for security and IT teams that play from behind, Chen wrote.

“Enter the digital twin: the visibility needed to secure your environment becomes the foundation for building a powerful, real-time simulation layer,” she wrote. “This allows security and IT leaders to safely validate defenses without ever touching production systems.”

Demand for Agents is Growing

A broad array of cybersecurity vendors are promoting AI agents for SIEM operations.

“Innovations like generative AI (GenAI) and agentic AI are offering new ways to manage risk and reduce noise,” CrowdStrike wrote in April. “GenAI is already being used to help analysts summarize incident details, recommend responses, and even write correlation rules. Agentic AI introduces the potential for autonomous systems that can pursue investigative goals, simulate attacker behavior, and streamline response actions – all without constant human input.”

The Argument for AI in Security

Leaning on AI for SIEM makes sense, according to Krista Case, research director with The Futurum Group, told MSSP Alert.

“Traditional SIEM systems struggle with the sheer volume of security data generated daily, leading to missed threats, slow time-to-detection, and lengthy investigation times,” Case said. “One of the biggest opportunities I see is using AI to quickly and automatically correlate vast data sets, and to add contextualization. The result is reduced alert fatigue through improved accuracy of threat detection, and an ability to identify subtle and sophisticated attack patterns that rule-based systems might miss.”

AI also can be used to accelerate vulnerability and incident response through recommended playbooks, as well as potentially automated and autonomous actions, she noted.

Interest in AI for Security is High

Cybersecurity pros see a crucial role for AI and agents in protecting organizations against cyberthreats. According to a report by security firm Darktrace, 95% of those surveyed said that AI-powered cybersecurity solutions significantly improve the speed and efficiency of preventing, detecting, responding to, and recovery from cyberattacks and 88% said using AI in cybersecurity is freeing up time for security teams and allowing them to be more proactive.

Case said she is seeing a similar appetite for adopting AI for the cybersecurity stack “in order to scale and upskill security operations teams. We do see that security teams are proceeding with caution and a healthy amount of skepticism. The trick will be keeping the human in the loop, and ensuring that all AI-generated insights and recommended actions are clearly explainable.”

Jeffrey Burt

Jeffrey Burt has been a journalist for almost 40 years, moving from general-circulation newspapers to IT news sites in 2000. He’s an expert analyst and writer on cybersecurity, data center infrastructure, AI, and a host of other subjects for a range of organizations, including CyberRisk Alliance, eWEEK, Techstrong Group, The Next Platform, and The Register.

You can skip this ad in 5 seconds