Episode 109 - From Alert Fatigue to Agentic Defense: Redesigning the Human Role in the AI-Native SOC
In Episode 109 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Joshua Weinick, AI Automation Engineer at Blink Ops, to examine a question every security leader is now facing: what happens when the volume, velocity, and variety of cyber threats exceed what any human-staffed security operations center (SOC) can handle, and what role do humans play in a security function that increasingly depends on AI agents executing at machine speed. Analyzed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) Framework, the episode reframes the SOC transformation not as a story about replacing security professionals, but about redesigning where human judgment adds the most value once the mundane, repetitive, and time-critical work is handled by governed AI systems.
To access and download the entire podcast summary with discussion highlights: https://www.dchatte.com/episode-109-agentic-ai-in-the-security-operations-center-redesigning-the-human-role-in-automated-threat-detection-and-response/
In Episode 109 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Joshua Weinick, AI Automation Engineer at Blink Ops, to examine a question every security leader is now facing: what happens when the volume, velocity, and variety of cyber threats exceed what any human-staffed security operations center (SOC) can handle, and what role do humans play in a security function that increasingly depends on AI agents executing at machine speed.
Drawing on his background in cybersecurity consulting and his time embedded in Fortune 500 SOCs at Ernst & Young, Josh traces the limitations of legacy SOAR automation — rigid, Python-coded pipelines that broke whenever an edge case or a system change occurred — and explains why agentic AI, unlike its predecessors, is built to absorb change rather than collapse under it. The conversation moves through the three forces breaking the traditional SOC model — overwhelming alert volume, attack speed that has compressed response windows from hours to minutes, and the cognitive toll of analyst burnout — and arrives at a reframed model Josh calls “human after the loop,” in which agentic systems take initial action within guardrails while humans review, audit, and reverse where needed.
The discussion examines what this shift means for emerging security talent, walks through a real-world 3 a.m. incident scenario that illustrates why a 45-minute human approval delay is now functionally equivalent to no response at all, and lays out five concrete steps organizations can take to begin the transition responsibly. Analyzed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) Framework, the episode reframes the SOC transformation not as a story about replacing security professionals, but about redesigning where human judgment adds the most value once the mundane, repetitive, and time-critical work is handled by governed AI systems.
To access and download the entire podcast summary with discussion highlights: https://www.dchatte.com/episode-109-agentic-ai-in-the-security-operations-center-redesigning-the-human-role-in-automated-threat-detection-and-response/
Connect with Host Dr. Dave Chatterjee
LinkedIn: https://www.linkedin.com/in/dchatte/
Website: https://dchatte.com/
Books Published
Cybersecurity Readiness: A Holistic and High-Performance Approach
Articles & Cases Published
Chatterjee, D. (2026). The Cryptographic Reckoning: Why Quantum Readiness Begins with Agility, Not Algorithms, The INFORMS Analytics Magazine, June 26, 2026
Chatterjee, D. (2026). The New Digital Fragility: How AI-Enhanced Cyber Threats Are Reshaping Operational Resilience, The INFORMS Analytics Magazine, March 4, 2026
Chatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026.
Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024.
Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023.
Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, Switzerland
Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020
Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3.
Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.