Inside the Agentic SOC Where Humans and AI Defend at Machine Speed With Barracuda
Tech Talks DailySeptember 24, 2026
3733
24:3633.77 MB

Inside the Agentic SOC Where Humans and AI Defend at Machine Speed With Barracuda

What does a security operations center need when attacks are arriving at a speed and volume that human analysts cannot manage alone?

I recorded this episode with Adam Khan, VP of Global Security Operations and AI Security at Barracuda, during the 20th anniversary of the Barracuda Tech Summit in Alpbach, Austria.

Adam has spent over 25 years in technology and security. When we last spoke at the event, he used Home Alone and soccer to make complex security topics easier to understand. This year, expectations were high, and he arrived with Formula One.

The comparison begins with what spectators see. Attention naturally falls on the car and driver. Behind them sits a much larger operation involving engineers, strategists, mechanics, simulations, telemetry, and rapid decisions. Adam believes modern security works in a similar way. Customers want to run their businesses, while a largely unseen combination of analysts, threat intelligence, automation, and AI works behind them.

That operating model has developed into what Barracuda calls the Agentic SOC. AI agents follow the same playbooks analysts use when examining endpoints, malware connections, artifacts, threat intelligence, identity behavior, and other signals. They can complete repeatable investigative work quickly and consistently across volumes that have grown from hundreds of alerts to thousands or millions.

Adam says Barracuda now has hundreds of agents with hundreds of individual skills. These agents can support the process from triage and intelligence gathering through correlation and response. When the system has high confidence that an ordinary user account has been compromised, it may disable that account. If the incident involves an administrative account capable of locking down an entire customer environment, a person must confirm the action.

This matters because an AI system can misclassify an event or reach a conclusion that requires additional context. Adam describes feedback mechanisms through which people review decisions, identify mistakes, and feed those findings back into the system. Barracuda also records an audit trail of the actions and queries performed by its agents.

One of the most surprising details concerns employment. While headlines frequently associate AI with reducing headcount, Adam says his team has doubled since adopting it. Analysts previously occupied with repetitive investigation have moved into threat hunting, model development, prompt engineering, and attack and defense exercises. The team is also attacking its own systems so that its agents can learn from emerging techniques before a genuine incident occurs.

The audience saw this operating model during Adam's keynote. Attendees used their phones to launch controlled business email compromise, QR-code phishing, and ransomware scenarios against Barracuda's attack and defense environment. The platform then analyzed and blocked the activity while the audience watched.

Adam says approximately 395 attacks were initiated during the demonstration and all were successfully blocked. That result comes from a controlled Barracuda demonstration rather than an independent test, but it gave attendees a rare view of the speed required during an active incident.

We also discuss how Barracuda Managed XDR uses behavior and telemetry across email, endpoints, cloud services, identities, networks, and other technology. An employee traveling with a familiar laptop and phone should not create the same response as an unknown device attempting an unusual login. Historical patterns, device identifiers, signatures, and location data can help reduce unnecessary alerts while highlighting activity that deserves attention.

For Adam, the purpose of AI is to increase the speed and reach of security experts rather than remove them. People determine strategy, examine high-consequence decisions, test systems, and remain accountable for customer outcomes.

Could the Agentic SOC give security teams the speed they need without surrendering the judgment and accountability customers expect? Listen to the episode and share your thoughts.

Useful Links

adam vid

00:00:00 Neil: So today we're recording here at the Barracuda Tech Summit in Alpbach, Austria. And I'm once again incredibly honored to have you join me today. Can you tell everyone listening a little about who you are and what you do for anyone that missed our last conversation?

00:00:14 Adam: Thank you for having me, Neal. And, uh, my name is Adam Khan. I'm the VP of Global Security Operations and AI Security at Barracuda Managed XDR. I've been in the security and tech space for over twenty five years, and I manage a security team that, uh, leads automation and AI and ML engineering and also central intelligence team and MDR led expert team that helps our customers be protected.

00:00:42 Neil: And a question I've got to ask you, twelve months has passed. It's almost been a lifetime in, uh, in old money, so to speak. But what has been keeping you busy in the last twelve months? Because last time we, we, uh, spoke, nobody was talking about AI and agents. Of course, now that's all anyone's talking about. But what's been keeping you busy?

00:01:00 Adam: I think the overall the exponential increase in attacks that have taken place since AI's adoption. And literally when you saw, like OpenAI, come to the picture with their first models, you started seeing threat actors leveraging this literally like a hockey stick. If you were to graph it and security teams were already burdened. We used to talk about the number of attacks before. Now, when you compare it, it's unheard of. So us having the ability to use AI to thwart AI attacks, just like Neil was mentioning, it's been hugely impactful, right? And the speed that they're coming in and the complexities increase as well. So our busyness has been how do we protect our customers faster? How do we provide better efficacy? How do we make sure we give great context to what we're seeing in the environment? Um, you know, and for the much better visibility. So our focus has been customer customer protection and then, you know, making them realize that this is, like I said, in my, in my presentation, this is a, this is a race. This, you have to be consistent and resilient throughout this whole endeavor. And we have to make sure we're successful because the bad guys are never going to stop.

00:02:24 Neil: Yeah. And you mentioned your presentation there a moment ago. And I know you're a very humble guy, not a big fan of compliments, but you have a real gift for storytelling. And I still remember clearly your presentation from last year where you brought security topics, complex security topics like, uh, to life using home alone and soccer. So expectations were high this year. So why, why did you choose formula One as the storytelling framework for bringing complex technology to life again?

00:02:51 Adam: I think it was a great parallel when I started thinking about, you know, how do we talk about the SoC? And when you talk about AI, it's all about acceleration. Yeah. And there's no faster car than Formula One and what they do. And that just, you know, kind of clicked and became a really good message about there's so much to formula one that parallel cybersecurity like I was talking about. Yeah, yeah. Um, you know, everybody's focused on that one driver, right? And think of that driver, like our customer, you know, and their, their business and how fast they want to accelerate their business. But behind the scenes is a whole team protecting that customer, right? And that's what resonated, especially like formula one, it's not just the driver. You have, you know, whole race team strategists, engineers, pit crew and mechanics, and they're utilizing top of the tools. Yeah. So that was the whole vision to tell the story about how we have morphed from, you know, a traditional SoC into a sock to be able to not just address the threats that we're seeing today, but the threats that are coming in the future as well.

00:04:08 Neil: And there will be many people listening and watching when they think of Formula One, they just see the car and the driver. But racers, as you said, they won by engine engineers, technology strategists, telemetry simulations, and so many decisions go on behind the scenes there. So how does this compare, though, with what happens inside a modern SoC?

00:04:28 Adam: There's a lot of parallels like from the data ingestion point, uh, where in Formula one, they're always looking at various data points from the sensors of the cars, no different than us. Like we are monitoring various technologies, various network devices, whereas IoT devices, you know, endpoint, you name it, all this creates telemetry. Um, and you have to make sense of what is happening in each one of these components. And then you have to connect the dots and connect the dots and see where are your risks? Lie. Where is the, you know, attacks coming from and how do we mitigate those in real time? So that really helps in accomplishing the goal that we're out there to protect the customers.

00:05:16 Neil: And something else that stood out in your keynote today was the idea of the Agentic SoC. So what does that term actually mean? How is it different from the traditional security operation center using conventional automation? What's changed there?

00:05:30 Adam: Absolutely. Great question. So there's I would do two flip two components of that. One is the people side, right? So you had a before in a traditional SoC, you have humans that are analyzing these threats in real time. Now there's just so much capacity, right? The number of alerts are growing. There's just so much capacity in speed to be able to make accurate decisions. When you're dealing with, you know, from hundreds to thousands to millions for a certain team to be able to do that efficiently. Right? And when we mean a genetic stock, is how quickly we'll be able to implement various agents that actually follow the same playbook that our analysts would write. So you would do look at an endpoint alert, and then you would look at it, what device it is happening on, where, um, what malware it's connecting to, what type of artifacts it has access to. What is the threat intelligence look like? All this would be in a playbook. Now the agent, which is nothing but a program, is able to follow that playbook is a much quicker format, right. And much, consistently. So the team that was doing this is actually now the humans got elevated to be a threat hunter. Yeah, yeah. So now they're doing more strategic work. Now they're doing more like critical thinking work, being proactive in hunting for attacks rather than waiting for signals to come in. So the signals part is taken care of by agents, which is transformed us into an Agentic SoC. As I said, we have hundreds of agents with over one hundred different skills to be able to, you know, protect the customers and attacks we're seeing. So the humans are actually elevated to do much higher efficacy work, much higher elevated work. While the I would say the grunt work is taken care of by AI. This is exactly what the security community needed, I think, and it's been hugely impactful for us.

00:07:34 Neil: And when you use the term playbook, I'm immediately thinking NFL, maybe, maybe there was a future NFL playbook idea for next year.

00:07:43 Adam: But no, there's it's interesting. A playbook is something that a lot of SoC operations follow. Yeah. And we have thousands of them for every different types of attacks. Like think about an airline pilot, right? When they get into their seat, they go through a checklist. And this is a A requirement by the regulatory bodies. You have to go through the checklist before you could even turn the plane on, before you could get things going. You have to check your instruments and everything in security operations center is very similar. When you see an attack, you have to go through that playbook because if you miss one step, which it is possible for a human to do, you have, you know, you could run into issues, you might miss a, you know, critical event that came in for this attack. And AI is the fact that it's able to take that away helps these guys to actually, you know, do a lot more other things in there.

00:08:42 Neil: And I would imagine it would also help tackle alert fatigue as well. Those dashboards where people, they become immune. Oh, we know what that is. We just ignore it. Yes. Exactly the same.

00:08:51 Adam: Thing. Yeah. The attacks have increased into like I said, literally when we saw hundreds, it went to. Yeah. You know, millions and exponentially very quickly.

00:09:00 Neil: So when we're talking about AI here, what parts of threat detection, investigation and response do you think AI agents can handle best? And. And where must a human security expert always remain involved? Because there's that accountability question as well.

00:09:14 Adam: Yeah. Well, there's two things AI right now can handle a full end to end. Yeah. All the way from triage to gathering intelligence, looking at different correlation. And then actually the response piece where when we are confident that a certain login from a certain location is definitely malicious, it did not happen. And we were able to identify that risk. The AI can take an action like disable that account right now where the humans come in is that loop where if it's an administrative account, do you want to do that? No. Right. We want to have a double check on that because that will lock down their whole whole, um, you know, tenant. So those are the higher efficacy work when it's a normal user, when it's a normal laptop or endpoint. No issues. That's how we have built in the format. And then there's a audit trail that we have for every single action every single query does, because we want to know every single time to our infrastructure, what it's querying, where it's going, what it's asking, and it's following the guidelines. And there's a watcher for every single one of those data points.

00:10:29 Neil: And barracudas message seems to be that AI is accelerating security experts rather than replacing them. So refreshing to hear there. But what does that partnership look like during a very real incident when decisions must be made within seconds? It's like the old Mike Tyson. Yeah, everyone's got a plan till then.

00:10:45 Adam: Punch in the face. Yeah, exactly. So I'll give you a good, um, indicator. Our team size has doubled since AI.

00:10:53 Neil: Wow.

00:10:55 Adam: Now everybody's like what the industry is saying the opposite, right? Because the team that used to do X work like the threat analysis piece has now shifted into like you saw Miriam's team. They're actually building the models. They're actually providing the strategy. Their skill sets have changed. All the teams are, you know, learning new coding languages, learning how to do prompt engineering, better learning, attack and defend exercises using attack simulators. So those roles have basically morphed into other components within security itself. So it's been a really good impact. And everybody's we're not waiting for attacks anymore. We're actually attacking ourselves in real time, just like an attacker would. So we are better prepared with our AI agents to make them more intelligent the next time a certain vector comes into place.

00:11:51 Neil: Well, you've busted a few myths there, and I think that's the kind of story we. We need to hear more of. Our LinkedIn newsfeed will tell you how AI is replacing X amount of jobs. So you've actually doubled the amount of human cyber security. Now, of course, when we look at AI, the AI systems can make mistakes, generate false positives, or reach conclusions that are difficult to explain. So how do you maintain human judgment, accountability and customer trust when agents are acting at machine speed because humans can't keep up with that kind of speed?

00:12:20 Adam: I think there's a whole governance piece. There's we have a loop mechanism where the threat analysis piece, the investigation, and then there's a human piece which actually looks at those on a regular basis and says, okay, AI has made a decision correctly on X, Y, Z, you know, hundreds of these, but these twenty were incorrectly classified. So we feed that back in and it continuously learns. So it becomes more and more trustworthy as we're, I can tell you from from our last conversation, last tech summit. And when we were in the midst of this, the performance was nowhere near what it is now. The models were not as good as now, right? And just if you remember, I think if you're aware, forty eight hours ago, a new model just got released with this jev.

00:13:10 Neil: Yes.

00:13:10 Adam: Right. And it is not giving you text prompts anymore. It's like focused on just making decisions and it's extremely accurate based on the data. So this continuously keeps improving, you know, and it's going to help companies. It's going to help security folks to to be better as we go on.

00:13:29 Neil: And of course, we're talking about defending here, but the attackers have the exact same technology. And you highlighted just how easy this is in the keynote today as well, where the audience participated in a live email attack demonstration, all using their phones they had in their pocket. But anyone that obviously wasn't there, can you describe what happened, what they experienced, and what what happens behind the scenes as Barracuda detects, analyzes, or blocks an attack?

00:13:55 Adam: Yeah, that was great. Yeah, it is a tech summit. And for me, it was like, it's not tech if you're not, uh, you know, actually doing a live attack on stage. So it's pretty simple. And how easy attackers like you talked about can leverage. So behind each one of those is an AI agent. The attacks one was a business email compromise, one was a QR code phishing, and one was a ransomware file being dropped. And literally what's happening behind the scenes? An actual when you click attack, there's an actual email payload attacking our attack and defend lab in the background. So a real business compromise is dropping in that environment where we have the Barracuda full portfolio suite, where it's going through the various analysis. And as you saw, the increments of attacks being blocked, that's how fast within milliseconds they were getting blocked, all those three different attack types in real time. So they're doing the analysis, like the example I gave the PDF, a snapshot is taken within milliseconds and analyzed by AI to figure out if there is any JavaScript in the script, in the PDF, or if there's any malicious URLs that are being morphed. So this thing behind the scenes is what the team is working on and like at speed, at machine speed, as you said. So we're able to protect them.

00:15:19 Neil: And a successful example as well. Were you nervous going up to that? If it was?

00:15:23 Adam: No, I've actually tested this hundreds and hundreds of times. I had the whole team, you know, slammed on it pretty good. So at the end of the thing, it was like about three hundred and ninety five attacks or so that were executed in that room and one hundred percent success. So that was a that was a good demo.

00:15:38 Neil: And just to bring to life everything we're talking about here and for people that can't attend. Can you explain how the Agentic SoC works with Barracuda managed XDR? How it identifies blind spots across email endpoints, cloud services, identities, and networks without creating more noise for security teams. Maybe you've got an analogy there, or some way of just bringing to life.

00:16:00 Adam: What do you mean the spot to come up with another analogy. Oh man, I don't know if I could do another.

00:16:07 Neil: Use.

00:16:07 Adam: Case, but yeah, use cases are great. Basically, identity threats are happening across the board where many people are traveling now and using their phones. They're using their laptops. They're not the traditional form of like sit in my office and that's my location. Yeah, right. With remote work and things like that, being able to figure out and reduce the noise to identify this is a real user who actually logged in without having to say, you know, hundreds and thousands of false positives. AI is really helping with that because it's able to pattern out, you know, ninety day data or longer that this is a common behavior for this user. The device ID matches the signatures, match the location or the geographic location they're in. Those things match and it's able to like reduce significantly the noise for not just our team, but our customers as well.

00:17:08 Neil: And at the very beginning of our conversation, you very kindly shared the story behind the keynote, how you were lying in bed at night. You woke up with the idea. You passionately wrote it down. Fast forward to today. What did you want customers to leave behind after or leave with after leaving the keynote? What did you want them to understand about people, intelligence, automation, and AI? How it protects every day or what they should maybe go away and examine in their own security operations? What did you want them to think about on the way home?

00:17:35 Adam: I think there's there's three things I wanted to leave them behind. One is in this world of AI, we, we, I guess the, the, the, the overall space is bringing the human side as not as important anymore. Yeah. And I think it's you've seen there's real people behind everything that we do, right? They're the ones that are driving the directions providing the strategy. So these people are actually critical to the success, like exactly what we said. Just like in Formula one, there's a team that is doing this work. The driver is the one in control that is executing right. For us, that's our customer. So the people side should never be forgotten. That's why I wanted to drill down and, you know, make sure the audience understood that. The second was the fact that AI is able to accelerate for the attackers and the speed of attacks, that these things are happening. And in all transparency and honesty, we just can't keep up. So the, the teams that were doing, I would say now you could think about it like rudimentary work. Back then, they have morphed themselves into other roles within the organization, the people side, the velocity of the attacks and the speed. And the third would be ultimately, if everything is the outcomes you're achieving, what does it all mean? If that business is able to go another three months without an attack, that means a lot. Because you have people's lives, their financial state and everything. Their credibility is at stake, right? And they hold that. And we hold that responsibility extremely high and in our mind. And I, you know, get up every single day making sure the customers are protected. And I take that seriously. And so does my team. Right? It means a lot. Like we're passionate about what we do. And, um, hopefully it shows.

00:19:37 Neil: It really does show. I think the passion comes across in you and just the community here as well. When I think of the Barracuda Tech Summit, I think of two things. One, the stunning location and two, the passionate community. It's just evident everywhere you look. And what are you taking away from the event this year?

00:19:52 Adam: One of my biggest things is just the feedback they've given us over the years. We continue to implement those because they're the ones that are feeling the pain. They're the ones on the front lines. They're the ones that are seeing what their customers or their users are asking about. And it's important for us to continue to listen to them and keep delivering. Like that's why these, these events like Tech Summit or Discover are extremely valuable for us because it's such a great intake method for us. No Zoom or teams is ever going to replace this. The human touch. Still to me is just as important. Um, just having a conversation over lunch or having a coffee with a customer and just that conversation piece still continues to be extremely valuable data point for us at Barracuda.

00:20:45 Neil: Brilliant. And for anyone listening and watching that, they hear the phrase a genetic security operations center sets off their tech Spidey senses. Where can they find out more information?

00:20:54 Adam: Uh, yeah. Barracuda dot com is the best place. There's a lot of information there as well. And, um, you know, we can share more information with you on a, you know, directly as well. Yeah. Barracuda dot com.

00:21:05 Neil: Well, on the blog post associated with this, I will include links to everything here so people can get in touch there. And also a few videos if I can find them as well. But just a massive thank you as always.

00:21:15 Adam: Awesome. Thank you for having me, Neal. Appreciate it. Thank you.