SEKOIA DEPLOYS ITS NEW SYSTEM
Elevate is live. Since 1 September every Sekoia Defend customer gets it for free until 31 October.Says Charles Ngor, Principal Product Manager:
“It’s our first autonomous operation: AI agents that investigate security alerts on their own. After 12+ months of work with the team, I’m proud of the result. Elevate doesn’t replace analysts, we never intended it to. It does the early triage, collects the evidence, shows every query it ran, writes the analysis and proposes a verdict. The analyst gets clarity on what happened and makes the final call. AI will be wrong sometimes so the decision has to stay human.
Early testers tell us they close alerts faster because the evidence is already there when they open them.
Finally, Europe gets its first complete platform with SIEM, threat intelligence, SOAR, exposure management and autonomous investigation where the AI runs on our own infrastructure and no customer data goes to an external model provider.
Run it on your own alerts for two months and make your own opinion.”
More details here
AND ALSO HERE:
99 seconds.
That’s now the average time our agentic SOC capabilities need to investigate a security alert
Not in a benchmark, not in a lab, in production.
Last week, we launched the largest AI trial we have ever run at Sekoia, opening autonomous investigation to more than 2,000 customers and hundreds of SOC analysts working on real alerts.
In just a few days:
→ 85,000+ investigations completed
→ 1m39s average investigation time
→ 15+ billion tokens processed
→ 1,200+ communities already using Auto-analysis
And the customer feedback is already very concrete. A major European MSSP told us:
“We reduced our investigation time by 5x.” A major US MSSP told us: “We’re impressed by the depth and quality of the investigations.”
For me, 99 seconds is the number that matters most.
Because it changes the operating model of the SOC.
With agentic investigation, work starts as soon as an alert is created: collecting evidence, pivoting through context, testing hypotheses, documenting findings and proposing a verdict.
The analyst doesn’t need to start the investigation anymore.
The investigation is already there when the analyst arrives.
This is where I believe the AI conversation in cyber needs to move:
We need continuous investigations available at machine scale.
AND JOINTLY WITH KUDELSKI SECURITY ISSUES A COMPREHENSIVE REPORT ON NORTH KOREA OFFENSIVE CYBERSECURITY ORGANIZATION
You can read more here
HARFANGLAB IS EXPANDING ITS PLATFORM WITH AN IDENTITY THREAT DETECTION AND RESPONSE (ITDR) MODULE.
This new capability extends the HarfangLab platform’s detection and response capabilities to identities and identity providers. In line with its strategy, the vendor is moving toward broader protection of organizations’ digital environments. HarfangLab’s ITDR solution leverages the same lightweight agent used by its EDR. Utilizing detection mechanisms comparable to those already employed on endpoints, it provides visibility specifically into the attack surface associated with identities. The software relies on Sigma-based detection engines, configurable rules, and user behavior analysis capabilities. The offering is available with feature parity across both cloud and on-premises deployments.
NUCLEON SECURITY FULL SPEED ON AI
Nucleon Security is launching ATOM AI, an agent-based AI platform designed to automate part of SOC work. Its agents can sort alerts, conduct investigations, suggest actions, and carry them out. All of this comes with safeguards to limit the risks associated with their autonomy. ATOM AI comes to complement the platform developed by the company around its EDR, XDR, and malware protection components. But Nucleon Security emphasizes a change in approach. The agents shouldn’t just summarize an alert or assist the analyst. They should be able to go all the way to decision-making and action. The agents are thus designed to analyze an event, determine its criticality level, enrich the available data, propose a response, and then, when authorized, execute it. In the case of a false positive, the platform can, for example, automatically classify the alert when it thinks it has a high enough level of confidence. When a threat is considered real, several agents can carry out the investigation and then suggest a series of actions to the analyst. The analyst still has the final say for sensitive operations.
According to the company, the system decreases the time to analyse and stop an attack by a huge factor. And to avoid the risks of agents crossing boundaries, each agent is assigned a set of rights that precisely determines the actions they can or cannot perform and that can be controlled.
RED ALERT LABS
As our member RED ALERT LABS points it, article 14 of the EU Cyber Resilience Act is now in force. Article 14 mandates that manufacturers report actively exploited vulnerabilities and severe security incidents in products with digital elements to ENISA and national CSIRTs within strict 24-hour, 72-hour, and 14-day deadlines.
Roland Atoui, CEO of the company, comments : “ The first real incident will still be stressful but it will be stressful in the way a rehearsed thing is stressful.That is the difference that matters.
To the teams that are not where they intended to be:
September 11 is the start of an obligation, not the end of your opportunity to meet it. Begin with intake. Name the decision owner. Prepare for the platform. The sequence works at any starting point.
And to everyone: September 11 is one CRA milestone, not the last. On December 11, 2027, the Cyber Resilience Act will apply in full, and the work being done today for Article 14 is also part of the foundation for that broader horizon.”


