Services

Exercise the AI-enabled SOC. Close the loop.

A closed-loop practice for the AI-enabled SOC.

Audience

Who we serve

Security leaders, SOC teams, executives, and boards at organizations running an AI-enabled SOC, adopting agentic security tools, or putting AI agents into production.

The work

Problems we solve

  1. 01

    Vendor use cases, untested

    An AI SOC or agentic security tool shipped with the vendor's use cases, and nobody has tested them against your own risks.

  2. 02

    Agents in production, no plan

    AI agents are in production, and the incident response plan does not say who notices, who can shut one off, or who tells the business.

  3. 03

    Findings that stay in the report

    Tabletop findings stay in a report. They never become detections, and nobody re-tests them.

  4. 04

    The board has not rehearsed

    Executives and the board have not rehearsed AI agent misuse, shadow AI, or an incident at an AI vendor.

In the room

Questions to ask

  1. 01

    When one of our SOC's AI agents fails or is manipulated, who notices?

  2. 02

    Which of our AI-related detections actually fire? How do we know?

  3. 03

    What are our autonomy limits and kill-switch rules for AI in the SOC?

  4. 04

    What does the board do in the first hour of an AI vendor incident?

  5. 05

    When did we last re-test what the last exercise found?

The method

One closed loop

  1. 01

    Exercise

    Run the SOC and the business through the incident, including failure or manipulation of the SOC's own AI agents.

  2. 02

    Derive

    Write the AI security use cases the exercise exposes.

  3. 03

    Validate

    Test them against your telemetry. Keep the ones that fire. Record the ones that do not.

  4. 04

    Decide

    Turn results into AI governance controls and AI SOC design decisions, including autonomy limits and kill-switch rules.

  5. 05

    Re-test

    Run it again and check that controls and detections hold.

Mapped to

Public MITRE knowledge bases. ATT&CK for adversary behavior, D3FEND for defensive countermeasures, ATLAS for attacks on AI and ML systems.

Services

Engagements

The practice

Our team

Our team has delivered tabletops and war games at Booz Allen Hamilton, EY and AT&T DFIR and built a SOC at Accenture.

We run the exercise, and we write and audit the detections.

Cyber Defense Tactics is a practice of CarbeneAI.

Request a scoping call

Free

Open material.

Three things sit outside the engagements: a tabletop kit, the public library, and the Brief.

  1. 01 · Free

    AI Agent Tabletop Kit

    One scenario for an AI-agent incident, tied to NIST AI RMF risks and MITRE ATT&CK techniques. Confirm an address and the file arrives by email. It is separate from the engagements.

  2. 02 · Public

    Reference library

    Public pages for adversary behavior, defensive countermeasures, and attacks on AI and ML systems. No account.

  3. 03 · Monthly

    The Cyber Defense & AI Brief

    A monthly note. The public record of the method, the reference library, and what exercises show about AI in the SOC.

GitHub

AI Governance Toolkit

The public maturity self-assessment and framework from CarbeneAI.

Not ready for a scoping call? Subscribe to the Brief.