How multi-agent AI cuts detection time by 40% and shrinks human work 12x.

The detection-engineering team is the real bottleneck in a mature SOC, not analyst triage.

3 min readInfoQ
How multi-agent AI cuts detection time by 40% and shrinks human work 12x.

The most persistent myth in security operations is that the analyst is the bottleneck. It's a comfortable story, but it is increasingly false. In mature SOCs, the real constraint is the detection-engineering team, the people who translate threat intelligence into rules faster than the threat landscape shifts. Willem Berroubache's account of a multi-agent system in a 5G core production environment finally names this problem directly, and the results are worth pausing over: a 40% reduction in mean time to detect and respond, alongside a 12x compression in human effort. That is not a marginal improvement. That is a fundamental change in how detection work gets done.

The architecture he describes uses the Agent2Agent (A2A) protocol and the Model Context Protocol (MCP) to let AI agents handle the grunt work of rule alignment, the constant, tedious recalibration that consumes engineering cycles. This is the right problem to solve. We have spent years building better alert triage, better dashboards, better SIEM ingestion, all while the rule-writing backlog quietly grows. Multi-agent systems are not about replacing the human analyst; they are about giving the detection engineer a collaborator that never sleeps and never loses context. For our readers, the practical takeaway is direct: if your SOC is mature enough to have a stable triage process, your next competitive advantage will come from automating the rule lifecycle itself, not from hiring more rule authors.

What impresses us about this specific deployment is the restraint. Berroubache is not claiming a sentient defense platform. He is describing a production system with a clear division of labor: agents propose, humans dispose. That is the correct framing. The A2A and MCP protocols matter because they provide a common language for agents to share context, but the real innovation is the workflow design. The human work that remains is the work that should remain: judgment, validation, and exception handling. This is a model that scales because it does not demand that AI be perfect, only that it be useful. If you are running a SOC and you are not actively exploring how to apply agentic workflows to your detection pipeline, you are already behind on the curve, not because you lack talent, but because the threat landscape has outrun the manual approach.

The open question we would put to any reader considering this path is not whether multi-agent AI works, the evidence is compelling, but how you will govern the delegation. If an agent proposes a rule change that turns out to be flawed, who owns the accountability? Berroubache's 12x compression in human work is a powerful metric, but it also implies that fewer humans will be in the loop for each change. That is a governance problem, not a technology problem. The teams that succeed here will be the ones that treat agent outputs as a first draft from a highly competent, but not infallible, junior engineer. Watch for how the community addresses the audit trail for agent decisions, because that is where the next bottleneck will appear. Everything else is just faster rule writing.

From InfoQ

The bottleneck in a mature SOC is rarely analyst triage; rather, it is the detection-engineering team's ability to keep the rule base aligned with a threat landscape that evolves faster than rules can be written. Learn how multi-agent system for production security operations has reduced mean times to detect and to respond by 40% and compressed the human work required by 12x.

Read the original at InfoQ