South African organisations are feeling the strain of more alerts, higher complexity and tighter budgets. For managed security service providers (MSSPs) and in-house security operations centres (SOCs), the pressure is especially acute because each new customer adds a unique mix of technologies, compliance rules and threat patterns.
Tim Leehealey, vice-president of corporate strategy and operations at Strike48, says agentic artificial intelligence (AI), a form of AI that can act autonomously to gather evidence, correlate data and suggest next steps, is beginning to change how modern SOCs work. “Agentic AI isn’t about replacing analysts or reducing headcount,” Leehealey explains. “The real opportunity is improving how much work a security team can realistically absorb before operational strain begins to affect decision quality.”
Traditional scaling in a SOC follows a simple pattern: more customers generate more alerts, organisations hire more analysts, add new processes and create extra layers of management. After a point, each additional hire adds less value because analysts spend more time switching between tools, pulling context and validating alerts. The result is longer investigation times and higher risk of missed threats.
How agentic AI reshapes the workflow
Agentic AI differs from basic automation that merely triggers alerts. It continuously pulls telemetry from multiple security platforms, enriches it with threat intelligence and builds a narrative of the incident before a human analyst sees it. The analyst then starts with a pre-assembled picture of the event, allowing them to focus on interpretation and response rather than data collection.
“The workflow becomes less sensitive to volume because the effort required for each investigation becomes more consistent,” Leehealey adds. “Analysts spend less time rebuilding context and more time applying their expertise where it matters most.”
Timothy Whitaker, engineering team lead and lead developer at Maidar Secure, echoes the sentiment. He notes that South African organisations face a well-documented shortage of skilled cybersecurity professionals, making it hard to grow security teams at the same pace as business expansion. “Agentic AI allows organisations to increase the capacity and effectiveness of their existing SOC teams without compromising the quality of security decision-making,” Whitaker says. “The goal isn’t fewer analysts, it’s empowering skilled professionals to spend their time solving real security problems instead of manually piecing together data.”
Beyond speed, the technology brings consistency. When analysts investigate incidents in different ways, priorities and escalations can vary, especially as alert volumes rise. By automatically assembling telemetry, historical activity, threat intelligence and environmental context, agentic AI gives every analyst a common starting point. This improves governance, auditability and compliance, a crucial benefit for highly regulated sectors such as financial services, healthcare, telecommunications, mining and the public sector.
Regulatory pressure in South Africa is increasing. The Department of Communications and Digital Technologies (DCDT) has issued stricter cyber-risk management guidelines for critical industries. Consistent investigation processes help organisations meet those guidelines and demonstrate due diligence during audits.
For MSSPs, the technology changes the economics of growth. Instead of hiring large numbers of analysts to keep pace with new customers, they can rely on agentic AI to deliver a baseline level of investigation quality across all engagements. This means capacity can grow without a linear increase in headcount, preserving profit margins while maintaining service levels.
SMEs that outsource security to MSSPs also stand to benefit. With tighter budgets, they can access a higher level of protection without paying for a larger team of analysts. The key is that the AI does not replace the human element; it amplifies it.
While the promise is clear, the technology is still emerging. Vendors are refining models to reduce false positives and ensure the AI’s recommendations align with local threat landscapes. Organisations considering adoption should pilot the solution in a controlled environment, measure investigation time reductions and verify that compliance reporting improves.
South African businesses that are already moving to cloud services, hybrid work and AI-driven digital transformation will find agentic AI a natural complement to their security stack. By pairing experienced security professionals with intelligent automation, they can protect assets more effectively while navigating a talent-short market.
For companies looking to evaluate the financial impact of such tools, the Tech & Telco section offers a commercial-funding suite that can model cost-benefit scenarios for security investments.


