Blackpoint Cyber has launched its AI SOC Agent, a new feature designed for autonomous response to identity-based threats. This capability, now generally available, aims to detect and contain attacks targeting Microsoft 365 and Google Workspace accounts with minimal human intervention. The system operates on an AI and human hybrid model, with the AI component acting on threats it identifies with high confidence.
The company states that the AI SOC Agent can contain credential-based attacks in an average of less than two minutes, with some instances taking as little as 21 seconds. This rapid response is presented as a crucial advantage given the increasing prevalence of identity-focused attacks. Microsoft has reported a 32% rise in such attacks during the first half of 2025, highlighting the growing threat landscape.
Blackpoint Cyber developed the AI SOC Agent by training it on data accumulated over years of its Security Operations Center (SOC) analyst decisions. This training also incorporated forensic evidence from hundreds of past security breaches and telemetry data from nearly one million user accounts. The company emphasizes that the AI has undergone rigorous validation to ensure it only takes autonomous action on threats deemed to be of high confidence.
The goal of this technology is to provide customers with the expertise of Blackpoint's frontline security team, delivered at machine speed. This allows for threat containment within seconds, according to the company.
Sean Furman, President of STF Consulting, commented that Blackpoint's SOC has served as a trusted extension of his team. He noted the critical importance of time in defending against contemporary cyber threats and expressed confidence that the combination of Blackpoint's AI and human analysts helps them stay ahead of the increasing volume of attacks.
Gagan Singh, CEO of Blackpoint Cyber, explained the company's philosophy regarding AI in cybersecurity. He stated that their SOC is integral to the effectiveness of their AI solutions, rather than being replaced by them. Singh anticipates that future adversaries will operate at unprecedented scales, potentially without direct human command, and that the same AI technologies used for defense are also being leveraged to create new attack methods.
Singh further elaborated that the AI SOC Agent's development was informed by Blackpoint's SOC team, which includes former operators from agencies such as the NSA, DIA, and CIA. He indicated that these individuals set the operational boundaries for the AI, ensuring that while the AI can act more rapidly, human judgment remains the ultimate arbiter for securing outcomes.






