COMMENTARY | If you're not using AI to defend against AI, then the adversary has already closed the gap. #
The threat landscape changed the moment generative artificial intelligence became broadly accessible.
Adversaries are no longer just nation-states and elite criminal organizations, but anyone with AI tools and a prompt. And the public sector agencies least equipped to respond to that shift are often the ones with the most sensitive missions.
For years, cybersecurity operations have been fundamentally about human analysts processing alerts, building context manually and making decisions under pressure. That model worked when attackers operated on human timeframes. It doesn’t hold when an adversary can compress reconnaissance, social engineering, malware development and exploit chaining into a single automated campaign. According to a recent Five Eyes cyber agencies statement, the urgency is clear: AI is not a future consideration. It is here today and lowering barriers for malicious actors and increasing the speed and complexity of attacks, shrinking the window between vulnerability discovery and exploitation ever more quickly.
For public sector and defense agencies, many of the nation’s most sensitive missions operate in disconnected, air-gapped environments where cloud-based AI services and continuous updates are not available. As adversaries compress attack timelines using AI, agencies need a new model for cyber defense — a modernized SOC that is built around agentic security operations that preserve human oversight while matching the speed of the threat.
A critical challenge in a unique environment
There is an assumption that air-gapped environments buy defenders time — they do not. Supply-chain compromises have nearly quadrupled since 2020, with intrusions traveling through removable media, periodic update packages, insider access and tampered hardware. Isolation reduces the attack surface, but it does not stop a well-resourced, AI-driven adversary who has retooled for speed.
What air-gapping does is restrict the defenses. Most AI-powered cybersecurity tools assume cloud connectivity, continuous model updates and external enrichment feeds. None of those conditions exist in classified environments, so adversaries can get faster while defenders stay constrained.
The real problem is not just the attack. It’s that the organizations with the most sensitive data often end up with the least adaptive defenses. That is not acceptable, and it is not inevitable.
There are ways to properly secure air-gapped environments to face modern threats. In doing so, public sector cyber teams must change the way they think about how a SOC should operate and look.
Four principles for an agentic SOC in air-gapped environments
For public sector and defense SOCs operating in air-gapped environments, it’s important to understand what the right kind of agentic approach looks like and what elements are most important for the specialized work being done. The silent partner: Agentic workflows should operate inside the analyst’s existing environment, not alongside it. During an active incident, agents are pulling process frameworks, cross-referencing local threat intelligence and scoping blast radius — by the time an analyst is notified, the observe and orient phases are complete. They start with assembled context, not a blank screen.
Precision containment and agentic response: When breakout times are measured in seconds, post-compromise investigation is already a recovery exercise, not a defense. Agencies need pre-approved automated actions for containment, isolation, credential rotation and evidence preservation. Speed matters, but every automated action must also be auditable, policy-aligned and reversible where possible. The goal is to compress detection-to-containment without weakening human command authority.
Model sovereignty: Air-gapped environments exist for a reason, and that reason doesn’t evaporate because an AI vendor’s architecture assumes cloud access. Agencies must retain control over what model runs, where it runs, what data it can see and how it updates. Whether that is an agency-hosted model in a fully disconnected environment, a smaller local model optimized for certain security tasks, or a frontier model approved for specific use cases — AI works on the agency’s terms, not the vendor’s.
Searchable scale: Air-gapped environments generate massive telemetry, and the answer is not to centralize all of it or force data across segmentation boundaries. The answer is to let questions and search travel to where the data lives. In segmented public sector environments, this is not a performance optimization. It is a mission readiness requirement. Messy data living in siloed systems across a classified enclave is still useful data, if the query layer can reach it.
A diamond, not a pyramid
The traditional SOC is structured like a pyramid: a large base of entry-level analysts manually triaging alerts, with a thinner senior tier handling investigation and escalation. That model is already strained in commercial environments.
In air-gapped federal environments, where talent is scarce and every false positive consumes irreplaceable analyst hours, it’s a structural liability.
The agentic SOC flips that geometry into a diamond. Routine triage is absorbed by AI agents operating within pre-approved boundaries, and security analysts are elevated into threat engineers — experts who define, calibrate and oversee the agents rather than process the raw alert themselves.
The base of the pyramid becomes the AI layer and human expertise concentrates on judgment, validation and mission-critical decisions.
Let me be direct about something: defensive AI is not a replacement for expertise. It is the minimum entry fee to stay level with the modern adversary. Every manual triage step that an agent can absorb is analyst capacity returned to the problems that require human judgment. That is not an efficiency gain. That is a structural redesign of how security operations work.
For public sector and defense agencies working in sensitive, disconnected environments, this concept of a mission-controlled agentic SOC is important because the stakes are higher and the margins are thinner. They cannot always depend on cloud-based threat intel, outside managed services or quick updates, so every false positive and manual triage step consumes scarce talent.
AI agents inside the environment can take on the routine work, apply mission-specific playbooks and keep analysts focused on priority threats — resulting in faster triage, greater consistency and more capacity without a smaller workforce.
In today’s threat landscape, the public sector teams that succeed will not be the ones that added AI to an existing SOC. They will be the ones that redesigned operations around mission-controlled speed — AI agents working inside approved boundaries, analysts elevated into threat engineers, models and data remaining firmly under agency control.
If you are not using AI to defend against AI, the adversary has already closed the gap. Sean MacKirdy is Area Vice President of National Security at Elastic, where he brings search analytics to the missions of customers across the national security and defense community. With more than 25 years of experience spanning software development, cybersecurity and public sector technology leadership, he has led mission-critical modernization efforts and data-driven technology implementation to solve an array of complex mission challenges.