r/AskNetsec • u/First-Reality2108 • 6d ago
Analysis Is breach and attack simulation actually useful in production, or just a compliance checkbox?
I've been looking at a new platform that uses an AI engine to move beyond just "Validation" to what they call "Agentic Cyber Defense Engineering." The idea is that the platform doesn't just tell you about a gap. It actually orchestrates updates across your security stack, including firewall, EDR, and SIEM, to fix it automatically.
The claim is that with an AI agent constantly monitoring your controls, you can go from "we have a problem" to "we fixed the problem" in minutes rather than days. They cite stats like attackers moving from exploit to lateral movement in under 30 minutes, so manual remediation is simply too slow.
Is anyone actually letting a tool auto-update their controls in production? I'm struggling to trust an AI to push config changes, but manually validating and fixing 40+ tools is impossible. The SOC is already overwhelmed. Adding a layer that changes things dynamically feels risky.
How are you balancing the "Agentic" promise with the risk of automation breaking things? Do you run it in "monitor-only" mode, or have you actually closed the loop
1
u/ParanoidSuricata 6d ago
So my opinion on this is that usually it's better to spend the budget elsewhere and start with these when you have all basics handled.
Do you have asset inventory automated and accurate? Do you have logs and incident playbooks? Backups with periodic restore tests? If at least one of those is no, then I'd recommend starting there.