Monday, 28 September 2026

Where technology leaders come to think out loud

ColumnCybersecurity

The NCSC has told MSSPs what an ‘autonomous SOC’ is really worth

Dave Chismon, writing on the NCSC’s website, says defenders cannot use AI as attackers do and that people, not machines, must act on what the machines find. Jay Janes on why that is a pricing model, not a warning

VETTDD cybersecurity section card
Image: VETTDD
In brief
  • In a post on the NCSC’s website on 21 September, Dave Chismon set out three principles for automating defense: machines detect, detection must not harm the organization, and any automated response is tightly scoped and acted on by people.
  • Sophos says its agentic SOC resolves 52% of cases entirely by AI in an average of 89 seconds, yet its own definition of the category keeps humans setting the boundaries.
  • MSSPs should sell detection automation as the platform line, price the named human response as the premium and write the scoping rules into the service schedule.

On 21 September, Dave Chismon, chief technology officer for architecture at the National Cyber Security Centre (NCSC), published a post on the NCSC’s website under the title “One does not simply defend agentically”. It opens with a maxim from the security researcher Halvar Flake: “All offensive problems are technical problems, and all defensive problems are political problems.” Everything that follows hangs off that line, and so should every UK managed security contract.

An attacker’s problems are technical and have a clear success state – the target program crashes, the malware calls home – the kind of problem AI agents are good at. A defender’s problems are organizational: budget for an end-of-life system, time from IT operations for patching, approval for a firewall change. A wrong defensive action lands on the live systems being protected, and a board may see little difference between an attack that takes the estate down and a poorly implemented fix that does the same. His conclusion is blunt: “Defenders simply cannot put AI to work in the same way attackers can. This is an inconvenient truth.”

He sets out three principles, drawn from how vulnerability scanning and security operations centers (SOCs) earned their trust. The first is the one I want channel leaders to memorize: “Technology is behind the detection, but humans respond with actions.” The second is that the detection must not harm the organization. The third is that any automated response “is tightly controlled and scoped (for example to a single user account or computer in response to a clear malicious signal)”. He adds a five-dimension framework for scoring the riskiness of an automated action – potency, scope, criticality, rollout confidence and recoverability – and says in a footnote that where SOCs already automate a response, each rule is crafted, tested and highly deterministic.

This is not a technologist talking down the technology. The NCSC is working on Cyber Shield, a national-scale agentic cyber defense program, and Chismon writes that delivering it means making autonomous defensive actions possible when, at present, they are not. In explaining why they are not possible yet, he has handed every MSP and managed security service provider (MSSP) in the UK the line to use the next time a vendor pitches an ‘autonomous SOC’. The state’s own cyber authority says the response half of security stays human. Partners should sell detection automation as hard as they can, price the human response as the premium and write Chismon’s scoping rules into the contract.

Look at what the vendors are selling

On 15 July, Sophos launched Sophos Fusion. Sophos says it runs the world’s largest agentic SOC, with more than 40,000 customers, and that 52% of cases are resolved entirely by AI, with an average of 89 seconds from alert to a fully automated response. Those are Sophos’s own figures, and the release does not say what kinds of case make up the 52%. Joe Levy, its chief executive, said in the release that Fusion is built as a defense system optimized for human-AI workflows, and the partner pitch is one system to sell and operate.

Read it against Chismon’s post. Sophos’s own definition of the new category includes ‘agentic autonomy with human governance’, where the system acts inside boundaries that analysts set and keep adjusting. That is Chismon’s third principle, written by a vendor. The 89 seconds is detection and triage at machine speed, the half Chismon says technology should own. What the release does not claim, because no serious vendor will, is that the machine should decide to isolate a domain controller at 3am on a signal it cannot fully explain.

Sell the detection, price the response

Vendor and authority agree on the split, even if the marketing does not. The MSSP’s choice is which half it wants to be paid for.

Detection automation will be on every platform’s price list. Sophos is bundling it and every rival will match it or claim to. The partner that tries to charge a premium for owning a faster alert is charging for the vendor’s roadmap. Sell it hard, because customers want it and it lowers your cost to serve, but as the platform line.

The response is different. Chismon writes that using AI for defense quickly becomes a matter of organizational politics, and that somebody has to own whatever action gets taken. That somebody is the product. The named analyst who decides whether the signal is clear enough, who knows the finance server has no failover this month, who rings the customer before the reset rather than after: that is what a customer cannot buy from the platform, and the only part of the service it will remember at renewal. Price it as the premium, with a named response lead, an agreed decision window and a fee that reflects the liability you are carrying.

Put the scoping in the contract

Then turn Chismon’s framework into a schedule of the service description. A contract should state what the platform may do on its own: the single user account or computer, on a clear malicious signal, and nothing wider. It should say which actions stay in audit mode until the customer signs them off, what the rollback commitment is when automation gets it wrong and which systems are excluded because the customer calls them critical. Chismon’s five dimensions map onto that schedule almost line by line.

Do that and two things follow. The customer who asks for full autonomy has to put in writing which of its systems it will let a machine change, and most will stop asking. And the customer who suffers an outage from a scoped, tested, deterministic action holds a document showing the boundary was its own. A board, as Chismon points out, cannot shout at an attacker down the phone. It can shout at its MSSP. Let the vendors race to 89 seconds. Your margin is the person who answers for what happens in the ninetieth.

AdvertisementZoomInfo

Get The VETTDD BriefingThe week in the technology channel, every week.

Subscribe free
Sources
  1. National Cyber Security Centre, “One does not simply defend agentically”, blog post by Dave Chismon, 21 September 2026. https://www.ncsc.gov.uk/blogs/one-does-not-simply-defend-agentically
  2. Sophos, “Sophos Launches Sophos Fusion, the Industry’s First and Most Complete AI-Native Cybersecurity Defense System”, press release, 15 July 2026. https://www.globenewswire.com/news-release/2026/07/15/3327762/0/en/sophos-launches-sophos-fusion-the-industry-s-first-and-most-complete-ai-native-cybersecurity-defense-system.html
Jay Janes
About the author

Jay Janes

Founder and editor of VETTDD. Former chief revenue officer at Giacom and director of growth at intY, where revenue grew from £19m to £40m.

More from Jay Janes →