# How SLED can win the cybersecurity race with agentic AI

> Source: <https://www.elastic.co/blog/sled-agentic-ai-cybersecurity>
> Published: 2026-08-21 00:00:00+00:00

# How SLED can win the cybersecurity race with agentic AI

Adversaries are using AI to launch cyber attacks in record time, forcing security teams to measure responses in minutes instead of months. Phishing campaigns built with large language models (LLMs) achieve click-through rates 4.5 times higher than traditional methods,1 and the average time between initial compromise and lateral movement has fallen to just 29 minutes.2 This is a 65% increase from the prior year.2

[State and local governments](https://www.elastic.co/industries/public-sector/state-and-local) and [higher education institutions](https://www.elastic.co/industries/public-sector/education) are at an inflection point. Most security stacks weren't built for this level of speed, and security teams are stretched thin by staffing challenges and budget constraints that don't move nearly as fast as the threat.

State CISOs see that gap widening: 55% consider AI-enabled attacks a major threat in the coming year, but only 2% are confident their state's information assets are protected from them. At the same time, budgets aren’t increasing to address this gap. Just 22% of CISOs reported cybersecurity budget increases of 6% or more, while 16% saw budget reductions.3

To respond at the speed of AI-enabled attacks, teams need AI working on their side. That's why a growing number of SLED organizations are considering an [agentic SOC](https://www.elastic.co/blog/agentic-socs-public-sector-cybersecurity).

## Fragmented security data slows response

SLED organizations were never built as unified entities. Agencies, departments, and campuses buy tools independently, often over decades with each solving a specific problem in isolation. The result is a complex security landscape with multiple platforms, legacy systems, and varying levels of technology maturity, limiting interoperability across the technology stack and collaboration across teams. That fragmentation used to be an inconvenience, but now it's a structural risk.

Every week, 66% of SOCs lose an entire day manually aggregating data across disconnected tools.4 When adversaries can move laterally in under 30 minutes,2 hours spent reconciling consoles are hours of exposure. A single event rarely tells the whole story. Attackers often perform many small actions that look harmless individually but become suspicious when connected.

## How an agentic SOC accelerates investigations

An agentic SOC uses AI agents to perform multistep security tasks: correlating alerts, gathering context, investigating entities, and preparing response plans. Unlike traditional automation, which follows a fixed set of rules, agents can reason across changing information and adapt as an investigation develops.

That autonomy doesn't mean removing analysts from the process. An agentic SOC keeps humans in control of consequential decisions while cutting the manual work required to reach them, which is essential for any organization that answers to a board of regents, a city council, or a legislative committee. Adoption is already moving past experimentation. In 2026, eight states reported having agentic AI tools in production.5

[Elastic's agentic SOC](https://www.elastic.co/security) is built on the human-in-the-lead model. Agents correlate alerts, investigate entities, and stage response plans across the threat lifecycle. Before taking an action, isolating a host, or disabling an account, an agent presents the plan and waits for analyst approval. Every decision is documented, so reviewers can trace the reasoning. Instead of starting the day with a wall of raw alerts, analysts review a focused list of threats already investigated and enriched with context, letting a small team operate with the capacity of a much larger one.

## Agentic AI extends state and local security teams

State and local security leaders are solving different versions of the same problem. A state CIO or CISO may be focused on [whole-of-state cyber defense](https://www.elastic.co/blog/whole-of-state-cyber-defense), shared services, and coverage across dozens of agencies. Local governments often rely on small IT teams wearing multiple hats while facing constant pressure to keep essential services running.

The readiness gap between those environments remains significant. In the survey of state CISOs, none were very confident in local governments’ cybersecurity practices, and 43% were not very confident. Although 88% of state CISOs oversee an enterprise-wide SOC, only 12% participate in a regional SOC that pools cybersecurity resources across agencies and local organizations.3

Agentic AI cannot replace those missing resources, but it can help extend the capacity and expertise already available by accelerating correlation, triage, investigation, and response.

### Different scales, the same data challenge

California's Employment Development Department manages more than 850 billion records across nearly 3,000 servers and a 60-person security team and cut mean time to response by 99% using Elastic's Attack Discovery. [Read the full story →](https://www.elastic.co/customers/caedd)

Arizona's Department of Homeland Security represents the other end of the spectrum: a lean team managing 12 terabytes of daily logs and using prebuilt alerts to move from reactive to proactive without adding staff. [Read the full story →](https://www.elastic.co/blog/arizona-department-of-homeland-security-elastic-ai)

Whether it’s 60 analysts or 3, the underlying problem is identical. AI didn't replace either team's analysts. It gave them their time back by automating repetitive work, providing context and accelerating investigations.

## Higher education faces its own form of fragmentation

Academic freedom creates a different kind of decentralization than government. Departments, research groups, and campuses often procure their own systems, and central security teams must protect environments spanning thousands of users, personal devices, and sensitive research data. AI adoption adds another layer of risk: EDUCAUSE found 94% of higher ed survey respondents had used AI tools for work, but only 54% were aware of institutional policies governing that use.6

### Small teams can secure university-scale environments

Vrije Universiteit Brussel runs its entire security operation with three engineers covering 64 billion events across more than 300 endpoints and identifies a rogue DHCP server disrupting the network in minutes rather than days. "Elastic enables a very small team to operate security monitoring at university scale," says Network Security ICT Consultant Xavier Tomaszynski. [Read the full story →](https://www.elastic.co/customers/vub)

The Texas A&M University System operates entirely at a different scale, spanning 11 universities, eight state agencies, and more than 153,000 students. Even at that scale, threat investigations that once took months can now be done in just two hours. [Read the full story →](https://www.elastic.co/customers/tamus)

### Students can help expand SOC capacity

A growing number of institutions are also bringing students into security operations as part of academic programs. But turning students into effective SOC contributors has traditionally required months of experience and training. Agentic AI changes the equation. By delivering cases with context, analysis, and prioritization already completed, newer analysts can focus on reviewing, decision-making, learning, and response instead of spending their time assembling the puzzle.

## Stronger cybersecurity starts with the data foundation

Across government and education, the smartest approach to AI cybersecurity is the same: Add context by connecting security data without moving it away from the people who own it, then let AI reduce the manual burden on top of that foundation.

Elastic's [data mesh architecture](https://www.elastic.co/industries/public-sector/data-mesh) provides holistic visibility across cloud, hybrid, and on-premises environments without centralizing sensitive data. This is a prerequisite, not a technical detail, for agencies bound by data residency requirements or operating in highly restrictive environments.

Transparency matters as agencies delegate security decisions to AI agents. Joint guidance on AI from the Five Eyes alliance, comprising the US, UK, Canada, Australia, and New Zealand, stresses the need for operational visibility. Humans must understand what agents do, why they do it, and the intent behind each action.⁷ That standard applies as much to a city council or a board of regents as to a national government agency. Transparency and accountability are foundational for building trust with an agentic AI model.

Equally important are open standards and interoperable architectures that prevent vendor lock-in and enable flexibility across complex environments. Built on open source and open standards, Elastic provides interoperability and integrates with existing tools rather than requiring organizations to rip and replace what they've already invested in.

A 60-person state agency, a lean state security team, a 3-person university SOC, and an 11-university system all operate at wildly different scales, but each made the same call. Treat the data foundation as the fix, not another point tool bolted onto an already-fragmented stack. The 29-minute breakout window isn't getting longer. The organizations responding in minutes are the ones that solved the data problem first.

Learn how to build a stronger data foundation for AI-driven security in the[ public sector cybersecurity guide](https://www.elastic.co/industries/public-sector/cybersecurity-guide-public-sector).

**Footnotes:**

Microsoft, "

[2025 Digital Defense Report](https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf)," October 2025.CrowdStrike, "

[2026 Global Threat Report,](https://www.crowdstrike.com/explore/2026-global-threat-report)" February 2026.NASCIO and Deloitte, "

[2026 Cybersecurity Study](https://www.nascio.org/wp-content/uploads/2026/04/2026-NASCIO-Deloitte-Cybersecurity-Study.pdf)," April 2026.Microsoft, "

[State of the SOC: Unify Now or Pay Later](https://marketingassets.microsoft.com/gdc/gdcZhJITG/original)," February 2026.NASCIO, "

[The Rise of Agentic AI in State Government](https://www.nascio.org/wp-content/uploads/2026/03/NASCIO_Agentic-AI-Report_2026_.a11y.pdf)," March 2026.EDUCAUSE, "

[The Impact of AI on Work in Higher Education](https://www.educause.edu/research/2026/the-impact-of-ai-on-work-in-higher-education)," January 2026.GovInfoSecurity, "

[Five Eyes Sound Alarm on Autonomous AI Security Risks](https://www.govinfosecurity.com/five-eyes-sound-alarm-on-autonomous-ai-security-risks-a-31590)," May 2026.

*The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all.*

*In this blog post, we may have used or referred to third party generative AI tools, which are owned and operated by their respective owners. Elastic does not have any control over the third party tools and we have no responsibility or liability for their content, operation or use, nor for any loss or damage that may arise from your use of such tools. Please exercise caution when using AI tools with personal, sensitive or confidential information. Any data you submit may be used for AI training or other purposes. There is no guarantee that information you provide will be kept secure or confidential. You should familiarize yourself with the privacy practices and terms of use of any generative AI tools prior to use. *

*Elastic, Elasticsearch, and associated marks are trademarks, logos or registered trademarks of elasticsearch B.V. in the United States and other countries. All other company and product names are trademarks, logos or registered trademarks of their respective owners.*
