

Converging SOC and NOC with Agentic AI
Converging SOC and NOC with agentic AI could change how organisations manage cybersecurity, network performance and incident response. As enterprise environments become more distributed and cyberattacks accelerate, the traditional separation between security operations centre (SOC) and network operations centre (NOC) teams is becoming increasingly difficult to maintain.
Cloud adoption, distributed workforces, operational technology (OT), software-defined networking and AI-driven applications have expanded enterprise environments. At the same time, cybercriminals are using automation and AI to move faster across those environments.
For organisations still running their SOC and NOC as separate functions, the result can be fragmented visibility, slower investigations and more manual work.
Agentic AI could help change that model. Instead of simply analysing information or recommending actions, AI agents can investigate problems, correlate data and take approved actions across networking and security systems.
Cornelius Mare, chief information security officer, Australia, Fortinet, said, “The challenge organisations face today is not simply detecting threats faster. It’s reducing the operational friction between networking and security teams so they can respond as a single function. AI agents have the potential to help close that gap by connecting visibility, decision-making, and response across both domains.”
Why Converging SOC and NOC with Agentic AI Matters
A network problem and a security incident are not always separate events.
Unusual traffic, configuration changes, degraded performance, or unexpected connections can be signs of both operational problems and malicious activity. When NOC and SOC teams work with different tools and datasets, determining what happened can take longer.
Agentic AI offers another approach. AI agents working across shared network and security data could investigate events, correlate threat intelligence and coordinate responses without waiting for multiple manual handoffs.
However, giving AI systems greater autonomy also creates risk. Organisations need clear governance, human oversight and controls around what an AI agent can change.
The goal is not simply more automation. It is faster coordination without sacrificing accountability.
Agentic AI Moves Beyond Security Recommendations
AI has already become part of cybersecurity operations. Security platforms commonly use AI and machine learning to identify suspicious behaviour, prioritise alerts and help analysts investigate incidents.
Agentic AI goes further.
Instead of stopping after an analysis or recommendation, an AI agent can potentially investigate conditions, validate policies, recommend remediation and execute approved actions.
That capability could become increasingly important as security and network environments grow more complicated.
According to Fortinet’s 2026 Cybersecurity Skills Gap Global Research Report, 91 per cent of organisations are already using or experimenting with AI-powered cybersecurity solutions.
That level of adoption suggests many organisations are becoming more comfortable with AI supporting cybersecurity operations.
The next question is how much operational authority organisations are prepared to give it.
Cybersecurity Skills Shortages Add Pressure
Enterprise infrastructure increasingly stretches across cloud platforms, branch offices, wireless networks, SD-WAN, OT environments and remote workplaces.
Security teams must protect those systems while managing large alert volumes and, in many cases, multiple disconnected security products.
Finding enough experienced people to manage that environment remains another problem.
Fortinet’s research found that 71 per cent of organisations believe the cybersecurity skills shortage creates additional cyber risk.2
Agentic AI could reduce some of that pressure by taking over repetitive investigations and operational tasks. However, automation does not eliminate the need for experienced security professionals.
It changes where their time is spent.
Instead of manually moving information between systems or repeatedly checking routine conditions, analysts could concentrate on incidents, policy decisions and business risks that require human judgement.
Converging SOC and NOC with Agentic AI Reduces Operational Gaps
A conventional enterprise may have its NOC monitoring availability, network performance and infrastructure while its SOC watches for threats and suspicious behaviour.
The problem begins when an event crosses both domains.
A NOC may detect unusual network behaviour and then escalate the issue to the SOC. Security analysts must investigate it separately, often using different tools and data.
That process introduces another handoff precisely when speed matters.
Cornelius Mare said, “Attackers take advantage of operational gaps. If networking and security teams are operating from separate datasets and different tools, it becomes harder to identify the root cause, understand exposure, and respond quickly. Unified visibility is becoming critical for both resilience and operational efficiency.”
Shared Data Could Give AI Agents More Context
Converged SOC and NOC environments aim to reduce those gaps by bringing network and security telemetry, analytics and policy enforcement closer together.
That shared context is particularly important for agentic AI.
An AI agent could detect abnormal network behaviour, compare it with threat intelligence, assess relevant policies and identify affected systems.
Depending on the authority given to the agent, it could then initiate approved remediation across network and security infrastructure.
For example, an agent might identify suspicious traffic from a compromised endpoint, investigate related activity and determine which systems are affected. It could then recommend or execute containment measures according to predefined policies.
That is substantially different from generating another alert for a human analyst to investigate from scratch.
Converging SOC and NOC Is About More Than Cyberattacks
The potential benefits are not limited to security incidents.
AI agents operating across networking systems could identify congestion, detect configuration problems and validate changes before deployment.
They could also help resolve performance issues before users notice them.
That capability matters as organisations become increasingly dependent on cloud services, collaboration platforms and latency-sensitive AI workloads.
In this model, network performance, user experience and cybersecurity become interconnected operational issues rather than separate technology functions.
Human Oversight Remains Critical for Agentic AI
Greater autonomy also raises an obvious question: how much control should organisations give an AI agent?
Allowing software to make changes across critical network and security infrastructure introduces operational, security and governance risks of its own.
Organisations therefore need to define what an AI agent can investigate, recommend and execute.
High-impact decisions may still require human approval. Organisations also need auditability so teams can understand what an agent did, why it acted and what information influenced the decision.
Cornelius Mare said, “The future of AI in operations is not about removing people from the process. It’s about allowing teams to focus on higher-value decisions while AI handles repetitive operational tasks at machine speed. Human oversight remains essential, particularly when organisations are managing critical infrastructure, customer data, or operational resilience.”
Automation Needs Guardrails
Effective agentic AI governance should determine where autonomous action is appropriate and where human intervention remains mandatory.
The stakes increase when AI systems can modify firewall policies, isolate endpoints, alter network configurations or affect production environments.
A bad recommendation is inconvenient.
A bad autonomous action can become an outage.
For that reason, SOC and NOC convergence should not be treated as permission to automate every operational decision. Organisations need clearly defined permissions, escalation procedures and human approval thresholds.
Platform Consolidation Could Accelerate SOC and NOC Convergence
The shift also reflects a broader move toward consolidating cybersecurity and networking platforms.
Many organisations have accumulated separate products for networking, endpoint security, cloud security, threat detection and other functions.
Each additional platform can create another dataset, workflow and management interface.
Integrated platforms can potentially reduce that fragmentation while giving AI systems more consistent information to analyse.
That does not mean consolidation automatically produces better security. Organisations still need to assess vendor dependencies, interoperability, resilience and whether consolidation creates new single points of failure.
However, agentic AI works best when it has enough reliable context to make useful decisions. Fragmented operational data makes that considerably harder.
Agentic AI Could Reshape Security Operations
SOC and NOC convergence is unlikely to happen overnight.
Large organisations have established teams, technologies and processes built around the traditional separation of networking and cybersecurity. Critical infrastructure operators may also need particularly strict controls before allowing autonomous systems to make operational changes.
The direction of travel, however, is becoming clearer.
As networks become more complex and attacks become faster, organisations need ways to reduce the time between detecting an issue, understanding it and responding.
Agentic AI could become one mechanism for doing that.
Cornelius Mare said, “Organisations are moving toward operational models where networking and security are no longer treated as separate disciplines. The combination of shared visibility, integrated policy enforcement, and AI-driven coordination will play an increasingly important role in helping teams improve resilience, reduce complexity, and respond faster to both operational and security challenges.”
The technology will not make human security and network teams obsolete. If anything, giving software greater operational authority makes experienced human oversight more important.
The organisations that benefit most from agentic AI may therefore be those that treat it neither as another chatbot nor as an autonomous replacement for their SOC and NOC teams.
Instead, the opportunity lies in using AI to connect the two functions, remove repetitive work and help humans make faster, better-informed decisions.
Stay Informed With Cyber News Live
Cyber threats are constantly evolving, and staying informed is critical to protecting your organization.
Follow Cyber News Live for the latest cybersecurity news, threat intelligence, expert analysis, and practical guidance to help strengthen your cyber defenses.
