news.mlab.sh
Back to the feed
threat-intel

Google Bets 'Agentic Defense' Strategy Can Outpace Attackers

High
Summary

Google is implementing an ‘agentic defense’ strategy, leveraging its acquisition of Wiz to automate threat detection and response in a rapidly evolving cybersecurity landscape. This involves deploying AI-powered agents across its cloud infrastructure to proactively identify and mitigate threats, particularly those utilizing AI themselves. Google is emphasizing a ‘chips-to-code-to-cloud’ security stack, integrating Wiz’s graph technology with its Gemini AI models and Mandiant incident response services to create a self-governing security system. This shift is intended to address the increasing speed of attacks and the growing use of AI by threat actors.

Google is shifting its cybersecurity approach with a new ‘agentic defense’ strategy, built around its acquisition of Wiz and a commitment to automating threat detection and remediation. This strategy centers on deploying AI-powered agents across its cloud infrastructure, aiming to proactively identify and mitigate threats, especially those leveraging AI. Google is positioning this as a key turning point in cybersecurity, emphasizing the need to fight fire with fire in response to adversaries already using AI to aggressively accelerate attacks.

Google has completed its $32 billion acquisition of Wiz, a cloud security company known for its graph-based analysis, to bolster its existing AI, threat intelligence, and incident response features. The acquisition provides Google with a cloud-native security platform that supplements its existing capabilities.

Principal analyst Jack Gold of J. Gold Associates notes that agents are necessary to take the burden of handling mundane tasks such as sorting through false alarms. Google’s Security Operations platform, which unifies Chronicle SIEM and Siemplify SOAR, now uses AI agents and a consolidated framework to protect AI applications and multicloud infrastructure. Google’s first security operations agent, Triage and Investigations, launched last year, has triaged over 5 million alerts and has reduced the typical 30-minute manual analysis time to about a minute.

Google’s strategy is underpinned by its ‘chips-to-code-to-cloud’ security stack, integrating Wiz’s graph technology with its Gemini AI models and Mandiant incident response services. The company also recently rolled out the Wiz AI-BOM tool, designed to automatically create inventories of AI frameworks, such as LangChain and models and extensions to development tools. Google’s move to autonomous defense signals a broader shift in how experts view security teams operating as attacks accelerate.

Despite competition from established vendors like CrowdStrike, Palo Alto Networks, and Microsoft, who are also adding AI-based threat detection and remediation capabilities, Google believes its agentic SOC transition, combined with its vast AI and cloud arsenal, provides a significant advantage. Google’s focus on self-governing systems and AI that can act much faster than humans is intended to address the increasing speed of attacks and the growing use of AI by threat actors.

Read the full article at Dark Reading