The Agentic SOC: Pipe Dream or Reality?
The agentic SOC is not a pipe dream — and Chris Corde has the roadmap. Three months into his role as Chief Product Officer at SentinelOne (and after 20+ years spanning RSA Security, VMware Carbon Black, and Google Cloud Security), Chris joins Alan Shimel on TechStrong TV to make the case that model-provider progress is turning autonomous security operations into a working reality. He walks through Purple AI, SentinelOne’s autonomous SOC layer, and the new Purple auto-investigation capability that puts expert-level analysis on every alert — not just the ones humans can get to. Chris argues the story is efficacy and efficiency, not headcount cuts: SOCs already can’t touch a fraction of the alerts they receive, so AI is the leverage that lets human defenders focus on the highest-risk work while nothing hides under the covers.
Transcript
Hey everyone. Welcome back here to Techstrong TV. My next guest is Chris Cord.
Chris is the chief product officer, CPO, over at SentinelOne. Hey, Chris, welcome to Techstrong TV. It's great to have you on here.
Yeah, thanks, Alan. Thanks for having me. Chris, I mentioned you're the chief product officer.
I think a lot of our audience knows SentinelOne, but give people a sense kind of your journey and how you became chief product officer here. Yeah. I've been in the security industry for probably going on 20 plus years now, maybe a little bit longer.
So never actually expected to be in security, to be honest. So I came out of school, I was a software developer, worked at a number of dotcom-era startups. In 1999, 2000, focused on building out internet startups in a number of places.
But after going to business school, I took a job at RSA Security, if you know that company. So they're behind- Sure do ... the RSA Conference.
That was my first entry point into this space, and I actually fell in love with it. It felt like there was a very unsolved problem in the sense of- Right ... because there's an adversary, an attacker on the other side, and there seemingly was so many large-scale attacks happening, including to RSA.
So when I was there, we went through the RSA token breach, if anyone remembers that. And it was just fascinating to me that this was this untapped area that really felt like it needed a lot of innovation, a lot of thought. So that's what's got me into this space.
Most recently, before joining SentinelOne, I was at Google, so I was running security products and user experience for Google Cloud security. Our main product was something called Chronicle, which some- Sure ... people might be familiar with, which was really taking over a lot of the things happening on the security operations in the same space.
Yeah, and then joined SentinelOne three months ago. So, joined- Oh, I didn't realize you were that new to SentinelOne. Very cool.
Yeah. I'm fairly recent into the organization. Very good.
Well, welcome to SentinelOne, and welcome to being here on Techstrong TV. I was listening to you, Chris, and like you, I got into security 25 years ago, and back then, no one consciously got into security. There wasn't- Sure ...
a school like today. They have cyber- Yeah ... security curriculums and majors and all this stuff.
When we first got into it, it was usually the network guy who got tapped to play with the router, then the firewall, and whatever else we were building on the moat. The help desk guy got suckered into running the AV and the desktop- Yeah ... security.
And that's how it was. And then one day, boom, you're a security guy. Exactly.
So it was interesting times, and of course, RSA back then, RSA was RSA, right? They owned that brand. Yeah.
We were probably the preeminent security brand when I had started, so it was cool to be part of it. Absolutely. Yep.
Then I had a lot of friends at Google Security as well. Some still there, most I think have moved on, but anyway, SentinelOne, of course, is a company with a rich history in security, too. Maybe not 25 years ago like when we started, but- Yeah ...
they've made a big mark. They're one of the leaders. But, for people out here who may not be sure, they maybe have heard of SentinelOne, Chris, how would you describe SentinelOne to them?
Yeah, I think SentinelOne, obviously, we're leaders in the endpoint space, or one of- Yes ... the leaders in the endpoint space. So we have a huge endpoint footprint.
And that's what's really excited me about coming here is I think endpoint is the most critical, what I call control footprint in the enterprise. So many attacks and attack activity surfaces on endpoint or compute, as the first place that you can really see it and recognize it. So, when you're trying to provide overarching security operations or even autonomous security, which I'm sure we'll touch on, it's hard to do that without a deep visibility into what's happening at runtime on compute, whether it's servers or endpoints or mobile environments and now agents running in the system.
If you don't have pervasive visibility into what's happening, it's just very hard. You're missing a big part of the picture. And so I was really excited about coming and joining a company that has a pervasive footprint on endpoint devices, a leader in the space, a recognized leader in the space on endpoint devices, and the ability of expanding beyond that control footprint into kind of really allowing organizations to kind of lead into this more autonomous future.
So, yeah, to me, it's a very exciting kind of footprint that they have here, that they've built here, that we can really leverage and kind of build off of. Agreed. com?
Yep. Yeah, you can get all the information there. And then obviously there's some main events that, if you're interested, we have a conference called OneCon coming up in October, which is our user conference, like our big- Very cool ...
user conference. So, I think registration's open for that, so if people are interested, that's a great place to come and learn more about the organization if you want. Very cool.
All right. Let's switch gears a little bit. And I wanted to talk today to you, Chris, about the agentic SOC.
Pipe dream? Reality today, if not today, when? Yeah.
You guys have been working on this a while. You've got a new release out. Yeah.
Pull it all together for us if you can. Yeah, definitely not a pipe dream. So I would say just taking the top-level trend line, at the pace in which AI models are evolving and advancing, the reality is things around automation will come way faster than we expect.
So if you liken it back to the Moore's law of compute years ago, where people couldn't believe the kind of computing power that you can now deliver and the power that the exponential growth in how chips can really process things, that's what's happening now to a degree, where each model release that comes out, you see this really large-scale exponential growth in processing power and the ability to reason over complex tasks and really perform a lot of things autonomously that couldn't be done just even a year or two ago. And we expect that innovation to continue. It's not going to stop.
So we're still in the middle of the curve of the model providers, specifically Anthropic, OpenAI, Google, really advancing their core underlying engines, and we build off those engines to really provide a lot of advancement in, I think, autonomy. So to start off with, definitely not a pipe dream. So I think it may not be entirely realizable today to go full autonomous, and we could talk a little bit more about that.
So there's going to be areas where you can say you're not going to just get humans all together. You're going to have places where you can drive autonomy into some parts of your workflow, but I think in the future, you're going to start to see more and more capability to really automate a lot of the tasks that are highly repetitive, highly commoditized in most security operation centers. I don't disagree with you at all, to tell you the truth.
I'm very bullish- Yeah ... on doing this. But let's set all these people out here at ease, any SOC analysts we have.
Chris, is this going to cause people to lose their jobs, or is this just going to make our SOC people today better? I think it's better, for sure. I often liken it to two main things.
There is efficiency and efficacy, right? Which is you want to be able to drive more efficiency in your SOC. The reality is every organization in the world cannot comprehend looking at the amount of alerts and signals that are generated in the SOC with the humans that they have in their organizations today.
Forget about adding more or reducing more. They can only get to a small fraction of the alerts and the signal that they see. And that's the reality of why a lot of breaches still happen, is that things tend to be able to still hide underneath the covers.
Misconfigurations still happen. Humans aren't on top of the entirety of the surface. " Right?
I don't think that ultimately will be the case in a widespread way. Now, look, some organizations may not hire as much as they were previously in the past. Some organizations may selectively not choose to invest certain dollars into agentic workflows versus maybe human workflows.
So you might see some reallocation of maybe some spend. But by no means are we at the point where you can really replace humans in most organizations completely. And I think there's so much uncovered surface, right, in these environments that need to be protected, that if you're taking a risk-focused view, just allowing humans to focus on the highest risk things really provides a higher degree of efficacy, right?
So it's like when email was introduced into the environment. Work shifted. The way in which you did work shifted, for sure.
You weren't passing memos around left and right. And obviously, it made things a lot faster and a lot more efficient, but it didn't reduce the need to have meetings as an example. You couldn't completely replace the need of- Yeah ...
human conversation, but it opened up the ability for people to drive more efficiency into their workflow, right? And I think that's similar to the evolution that you'll see here as well. Look, Chris, I'll tell you from my own experience, one of the companies that I co-founded was called Still Secure, and back in the mid-2000s, 2005 to 2009, let's say 2004, we helped provide network access control to one of the largest private networks.
It was a DoD network in the world. I think back then it was over 400,000 nodes. That particular network, this is back in the day, I think they used Symantec IDS back then.
Right. If you remember. I'm sure you do.
I do, yeah. So Symantec was getting out of IDS. They were looking at another IDS.
They called us, and we looked. They were getting over 600,000 intrusion attempts a day. Right.
No kidding. And we didn't have AI, we didn't even really have machine sort of learning back then, but or maybe the beginnings of it. And trying to think, were we blocking any legitimate traffic?
Hell yeah. But weighing blocking legitimate traffic versus illegitimate intrusions, we had to err on the side of caution. And I knew back then that unless there was some way to automate this stuff, unless there was some sort of automated intelligence, we didn't think AI and stuff like that back then, but there just wasn't enough humans to do this right.
So to me, that's why this is, no pun intended, a no-brainer because even today we don't, for really high profile places, there aren't enough human analysts to really- Yeah ... go through this. Not even close.
But yeah, if you think about like, that's why I always point back to efficacy as being a huge advantage here. So if you think about the things that we just did with the Purple auto investigation capability, most of the time, humans are only looking at the really high end of the funnel, the top end of the alerts that they're getting in, and even that takes a long time, right? So they're not able to process those things as quickly as they would like.
In the future, what I'd like to be able to get to the world of, what if you were able to do a deep level of investigative analysis on every alert and every signal inside of your SOC? Literally blanket all of the alerts with expert-level analysis automatically so that you didn't have to worry about not uncovering something underneath a rock somewhere, right? Because the way in which people are trying to triage and prioritize what humans look at, that could work 90% of the time.
10% of the time it could fail you, and then you're in a situation where you've now missed something, right? And so the goal, I think, of a lot of the things that we're trying to do with automation is take away those trade-offs. You just don't have to make those trade-offs anymore, and instead, you can have this expert-level analysis running at all times, in the SOC, looking across everything, and then handing the human the things that really are important things to prioritize, right?
And that's a tremendously powerful way of driving a higher degree of value inside your SOC, for sure. Absolutely. Hey, Chris, we're about at 15 minutes.
Goes incredibly quick here. com. But is there a particular area of the website?
Should they just Google SentinelOne Purple? What's your advice? Yeah.
If you're a SentinelOne customer, this capability is offered now. We offered a free trial until August 15th. So if you're a SentinelOne customer, by all means, you can come into the platform, the Singularity platform, and turn it on and actually get a way of playing with it, using it, and kind of seeing how it operates.
So for sure, I recommend people doing that. Other than that, yeah, if you go onto the website, we have a number of materials that are driven, that talk about the autonomous SOC and talk about what Purple auto investigation can do for you, and then talk about, in general, our vision on Purple. So I'd certainly recommend diving into some of those.
So the key thing is we call our autonomous SOC layer Purple AI, and so if you just Google or look for Purple AI, you'll be able to get a lot of information and material about that. And then, like I said, OneCon's also a great place. We will be doing a number of deep level conversations, 201 level conversations directly with users about Purple and the autonomous SOC vision.
So I also recommend that being a really good place to come learn more. Love it. Hey, man.
Chris, thanks for coming on here. Keep up- Yeah, my pleasure ... the great work.
Good luck at SentinelOne. Yeah, I appreciate it. We'll see you often here on Techstrong TV.
All right. Thanks, Alan. I appreciate it.
Thank you. Bye. Chris Cord, Chief Product Officer, SentinelOne, here on Techstrong.
We're going to take a break. We'll be back in a minute.