Every day, more than 15 billion computing events are analyzed across Lenovo’s global network. Approximately 4,000 require deep investigation. From those, Lenovo’s Security Operations Center (SOC) must identify the 25 most critical issues requiring its experts’ attention.
Separating those threats from the noise has become increasingly difficult. Lenovo’s SOC helps protect 140,000 devices used by 80,000 people across 150 countries, and the company’s threat landscape has doubled over the past five years as attacks have grown faster and more sophisticated.
In the past, analysts responding to an alert had to manually review device status, file hashes and network information to determine whether the activity presented a genuine threat. Fragmented workflows across different security tools made investigations more time-consuming and increased the risk of human error.
Separating signal from noise
Through Lenovo Powers Lenovo, the company used its own global SOC as a real-world proving ground for a new AI-powered security model. The goal was to reduce manual alert review while giving analysts better context to identify and respond to genuine threats.
An intelligent data-ingestion platform brings together relevant signals from across Lenovo’s security environment and reduces noise before alerts reach analysts. AI agents triage incoming alerts, resolve lower-level incidents and enrich cases requiring human attention with relevant context and suggested next steps.
The model does not replace the judgment of Lenovo’s cybersecurity experts. Instead, it directs their time and expertise toward the incidents where they can make the greatest difference.
“If AI is essential to keeping pace with the threat landscape, then customers rightly expect us to use our own AI capabilities to protect Lenovo before we ask them to trust us with their own enterprise,” says Thirumalai Seshadri Krishnakumar, Director of Advanced Service Delivery at Lenovo.
Building confidence one workflow at a time
Lenovo did not deploy the new model all at once. Over several months, the team worked iteratively with SOC analysts and cybersecurity partners to test and refine AI outputs for different types of alerts.
As accuracy improved and analyst confidence grew, Lenovo introduced the new workflows into day-to-day operations. Alert-specific playbooks helped guide consistent AI-supported decisions and created a foundation that could be extended to additional security processes.
Real-world deployment also required changes beyond the technology. Lenovo upskilled and cross-skilled employees, adapted existing processes and integrated AI capabilities into the SOC’s operating environment. Strict controls were established to segregate, mask and log data, helping protect sensitive information throughout AI-supported workflows.
The result is a model shaped by the people who use it. The AI learns from Lenovo’s cybersecurity expertise while analysts retain responsibility for the complex decisions that require human judgment.
From faster detection to proactive protection
Information that previously took an analyst 45 to 60 minutes to investigate can now be assembled in seconds. Lenovo has reduced mean time to detect an attack by 87.5%, from four hours to 30 minutes, while improving the accuracy of malware and attack identification by 20x.
More than 80% of low-level incidents are now resolved without analyst intervention. This allows Lenovo’s experts to focus on more complex, higher-priority threats and has helped reduce cybersecurity total cost of ownership by 60%.
“By leveraging AI to shift SOC processes from reactive to proactive, our mean time to resolution has been reduced from 96 hours to just 24 minutes,” says Rakshit Ghura, Vice President and General Manager, Digital Workplace Solutions at Lenovo. “It also gives Lenovo a more resilient, scalable security model for a threat landscape that will continue to evolve.”
Lenovo is also using insights from alerts and reports to identify patterns, refine policies and improve its security operations over time. The company is now extending AI-powered workflows to additional threats, including phishing and brute-force login attempts.
By becoming customer zero for this model, Lenovo gained firsthand experience building, governing and operating AI-supported security at global scale. Those lessons now inform Lenovo’s AI-enhanced cybersecurity services, combining technology, processes and expert oversight to help customers strengthen security from pocket to cloud.
The experience also contributes to the Lenovo AI Library and Lenovo Hybrid AI Advantage—helping other organizations apply validated AI use cases and move from experimentation to measurable outcomes.