COMMENTARY | If you're not using AI to defend against AI, then the adversary has already closed the gap.

mustafaU/Getty Images
By
Sean MacKirdy,
Area VP of National Security, Elastic
By Sean MacKirdy
| July 30, 2026 05:38 PM ET
The threat landscape changed the moment generative artificial intelligence became broadly accessible.
Adversaries are no longer just nation-states and elite criminal organizations, but anyone with AI tools and a prompt. And the public sector agencies least equipped to respond to that shift are often the ones with the most sensitive missions.
For years, cybersecurity operations have been fundamentally about human analysts processing alerts, building context manually and making decisions under pressure. That model worked when attackers operated on human timeframes. It doesn’t hold when an adversary can compress reconnaissance, social engineering, malware development and exploit chaining into a single automated campaign.
According to a recent Five Eyes cyber agencies statement, the urgency is clear: AI is not a future consideration. It is here today and lowering barriers for malicious actors and increasing the speed and complexity of attacks, shrinking the window between vulnerability discovery and exploitation ever more quickly.
For public sector and defense agencies, many of the nation’s most sensitive missions operate in disconnected, air-gapped environments where cloud-based AI services and continuous updates are not available.
As adversaries compress attack timelines using AI, agencies need a new model for cyber defense — a modernized SOC that is built around agentic security operations that preserve human oversight while matching the speed of the threat.
A critical challenge in a unique environment
There is an assumption that air-gapped environments buy defenders time — they do not. Supply-chain compromises have nearly quadrupled since 2020, with intrusions traveling through removable media, periodic update packages, insider access and tampered hardware. Isolation reduces the attack surface, but it does not stop a well-resourced, AI-driven adversary who has retooled for speed.
What air-gapping does is restrict the defenses. Most AI-powered cybersecurity tools assume cloud connectivity, continuous model updates and external enrichment feeds. None of those conditions exist in classified environments, so adversaries can get faster while defenders stay constrained.
The real problem is not just the attack. It’s that the organizations with the most sensitive data often end up with the least adaptive defenses. That is not acceptable, and it is not inevitable.
There are ways to properly secure air-gapped environments to face modern threats. In doing so, public sector cyber teams must change the way they think about how a SOC should operate and look.
Four principles for an agentic SOC in air-gapped environments
For public sector and defense SOCs operating in air-gapped environments, it’s important to understand what the right kind of agentic approach looks like and what elements are most important for the specialized work being done.
A diamond, not a pyramid
The traditional SOC is structured like a pyramid: a large base of entry-level analysts manually triaging alerts, with a thinner senior tier handling investigation and escalation. That model is already strained in commercial environments.
In air-gapped federal environments, where talent is scarce and every false positive consumes irreplaceable analyst hours, it’s a structural liability.
The agentic SOC flips that geometry into a diamond. Routine triage is absorbed by AI agents operating within pre-approved boundaries, and security analysts are elevated into threat engineers — experts who define, calibrate and oversee the agents rather than process the raw alert themselves.
The base of the pyramid becomes the AI layer and human expertise concentrates on judgment, validation and mission-critical decisions.
Let me be direct about something: defensive AI is not a replacement for expertise. It is the minimum entry fee to stay level with the modern adversary. Every manual triage step that an agent can absorb is analyst capacity returned to the problems that require human judgment. That is not an efficiency gain. That is a structural redesign of how security operations work.
For public sector and defense agencies working in sensitive, disconnected environments, this concept of a mission-controlled agentic SOC is important because the stakes are higher and the margins are thinner. They cannot always depend on cloud-based threat intel, outside managed services or quick updates, so every false positive and manual triage step consumes scarce talent.
AI agents inside the environment can take on the routine work, apply mission-specific playbooks and keep analysts focused on priority threats — resulting in faster triage, greater consistency and more capacity without a smaller workforce.
In today’s threat landscape, the public sector teams that succeed will not be the ones that added AI to an existing SOC. They will be the ones that redesigned operations around mission-controlled speed — AI agents working inside approved boundaries, analysts elevated into threat engineers, models and data remaining firmly under agency control.
If you are not using AI to defend against AI, the adversary has already closed the gap.
Sean MacKirdy is Area Vice President of National Security at Elastic, where he brings search analytics to the missions of customers across the national security and defense community. With more than 25 years of experience spanning software development, cybersecurity and public sector technology leadership, he has led mission-critical modernization efforts and data-driven technology implementation to solve an array of complex mission challenges.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | From tool procurement to platform architecture: Rethinking the SOC for machine-speed threats | 0 | 16.79 | 27-07-2026 |
| 2 | Rethinking critical infrastructure security for the age of AI | 0 | 7.9 | 29-07-2026 |
| 3 | Why frontier AI must be stress-tested before CISOs trust it | 0 | 5 | 26-06-2026 |
| 4 | Spy agencies say AI can help combat AI cyber risks. But don’t forget the basics | 0 | 6 | 24-06-2026 |
| 5 | AI won't break your security, but your governance might | 0 | 7 | 07-07-2026 |
| 6 | How IAM providers are preparing for agentic AI | 0 | 5 | 29-06-2026 |
| 7 | Stop automating inefficiency and scale AI the right way | 0 | 5 | 25-06-2026 |
| 8 | Squaring the circle - digital sovereignty’s big picture versus its operational details | 0 | 8.68 | 30-07-2026 |
| 9 | Singapore: CSA's Addendum on Securing Agentic AI Systems | 0 | 10 | 29-07-2026 |
| 10 | Reimagining sovereign AI for India’s strategic future | 5 | 7 | 01-07-2026 |