
Episode notes
James, Emma, and SOC transformation specialist Maya unpack Microsoft's Agentic SOC whitepaper and its proposed operating model for continuous defense. The episode explains why task-driven alert queues struggle against outcome-driven attackers, how protection objectives become the new unit of work, where specialized agents fit, how human roles change, and why an integrated SOC needs shared context, governance, and assurance. It also adds a practical adoption roadmap, implementation guardrails, a payment-service scenario, and recall questions to help the ideas stick. Based on Microsoft Security's 2026 whitepaper, Agentic SOC: The new operating model for continuous defense.