Stockholm

From Alerts to Autonomy: How Agentic AI is Reshaping Nordic Security Teams

Join a select group of Nordic security leaders for an intimate dinner and candid discussion about what happens when AI moves from assisting analysts to acting alongside them.

Stockholm
18:30 - 21:30 CET
In Person Autonomous Security Future of SOC

Security operations are approaching an inflection point.

Enterprise data is growing exponentially. Attacks are moving faster and becoming increasingly AI-enabled. Meanwhile, security teams are expected to detect, investigate and respond to more threats with limited resources.

At the same time, autonomous AI agents are moving from experimentation into real business processes - creating an extraordinary opportunity for security teams, while introducing an entirely new attack surface to govern.

Join a select group of Nordic security leaders for an intimate dinner and candid discussion about what happens when AI moves from assisting analysts to acting alongside them.

 

The Conversation

How far can security teams safely automate investigation and response?

What should remain firmly under human control?

And what data, governance and security architecture are required to operate an Agentic SOC at scale?

Over dinner, we will explore how real-time enterprise context, AI agents and automated workflows can transform security operations while maintaining the trust, visibility and control modern enterprises demand.

This is a peer-level conversation designed for security leaders navigating the transition from AI experimentation to operational reality.

 

Five Questions Shaping the Agentic SOC

1. The Security Inflection Point

Security teams are moving beyond copilots that summarize alerts toward agents capable of reasoning across telemetry, investigating incidents, querying data and initiating multi-step workflows.

As adversaries increasingly use AI to automate reconnaissance, exploitation and lateral movement, can predominantly human-driven SOC models continue to keep pace?

An beneath the AI challenge sits a fundamental data challenge: AI is only as effective as the quality, accessibility and freshness of the enterprise context it can reason over.

 

2. Trust & Control

Moving from AI recommendations to autonomous action fundamentally changes the risk equation.

Where should autonomy begin and end?

Which activities an safely move to AI - enrichment, correlation, investigation and triage - and which should always require human approval?

Security leaders also need to understand what an agent accessed, how it reached a conclusion, what it recommended and what it ultimately executed.

The goal may not be to remove humans from the SOC, but to move human expertise away from repetitive investigation and toward judgment, oversight and higher-value decisions.

 

3. Securing the Agentic Enterprise

The challenge isn't simply using AI for security. Increasingly, it is securing AI itself.

As autonomous agents gain access to enterprise applications, identities, APIs and sensitive data, they create a new layer of attack surface.

We will discuss emerging risks including:

  • Prompt injection and compromised agents
  • Excessive permissions and malicious tool use
  • Lateral movement across interconnected AI workflows
  • Identity, access and agent governance
  • Observability into what agents access, query, reason over and execute

 

4. Building the Agentic SOC Architecture

An Agentic SOC requires more than adding an LLM to an existing security stack.

Context over models. Models will continue to evolve. A more durable strategic asset is the organization's ability to provide trusted, real-time enterprise context to whichever models and agents it chooses.

Search and retrieval as the intelligence layer. Agents need rapid access to historical telemetry, threat intelligence, security playbooks , cloud data and organizational context.

From dashboards to action. The future SOC may move away from analysts navigating disconnected dashboards toward specialized agents continuously investigating, correlating and escalating security activity.

Sovereignty and architectural choice. For Nordic and European organizations, where data resides, which models can access it and how AI inference is governed are becoming architectural decisions - not simply technology choices.

 

5. Elastic & AWS: Turning Agentic Security into Reality

Elastic and AWS provide a foundation for organizations moving from experimentation toward operational Agentic Security.

Elastic brings together security telemetry, cloud data, threat intelligence and enterprise context, giving AI agents the information required to investigate and reason effectively.

With Elastic Agent Builder & Amazon Bedrock organizations can combine Elastic's agentic capabilities and Elasticsearch Open Inference API with foundation models available through Amazon Bedrock, enabling AI-driven security workflows while maintaining control over enterprise data and model choice.

AWS security sources including CloudTrail, VPC Flow Logs and Amazon GuardDuty can be brought together in Elastic for continuous detection, correlation and investigation.

The opportunity is to move beyond generating more alerts toward AI agents that continuously investigate activity, connect context and help security teams determine - and execute - the right response. 

 

The Discussion

Over dinner, we'll put the hard questions on the table:

Where would you trust an AI agent to act autonomously today - and where would you absolutely require a human?

Do you currently have visibility and governance over the AI agents being deployed across your organization?

What is the biggest barrier to an Agentic SOC today - technology, data, governance, trust, skills or organizational readiness?

As attackers increasingly operate at machine speed, how much of security operations can realistically remain human-driven?

 

A Private Conversation for Security Leaders

This is an intentionally small, invitation-only dinner designed to encourage an open exchange between peers.

Just security leaders, practitioners and technology experts discussing what agentic AI means for the future of the SOC - including the opportunities, risk and decisions that cannot be solved by technology alone. 

Register your interest below. 

Join the conversation

You may unsubscribe from these communications at any time. For more information on how to unsubscribe, our privacy practices, and how we are committed to protecting and respecting your privacy, please review our Privacy Policy.