Organizations in South Africa are facing increasingly complex cyber threats. As digital transformation accelerates, cloud adoption grows, and regulatory requirements tighten, security teams are expected to manage a higher volume of alerts, increased complexity, and greater business risks, often without a corresponding increase in resources.
For Managed Security Service Providers (MSSPs), this problem is compounded by the fact that each new client brings with them diverse technologies, security controls, compliance requirements, and threat profiles. While business growth is a positive aspect, it also places significant pressure on Security Operations Centers (SOCs) to maintain speed, consistency, and accuracy.
According to Tim Lihili, Vice President of Corporate Strategy and Operations at Strike48, this is where agentic AI is beginning to change how modern SOCs operate.
Agentic AI Does Not Replace Analysts
Lihili emphasizes that 'Agentic AI is not intended to replace analysts or reduce headcount.' He notes that the true potential lies in enhancing the amount of work a security team can realistically handle before operational strain begins to affect decision quality. As organizations grow, the issue is not just about processing more alerts, but about maintaining consistently high decision quality amid increasing complexity.
Traditionally, SOC scaling followed a predictable model: an increase in clients led to more alerts, prompting organizations to hire more analysts, implement additional operational processes, and create new management tiers. However, this approach eventually reaches a point where adding personnel yields diminishing returns in efficiency.
Analysts spend increasing amounts of time switching between security tools, gathering context, correlating telemetry, verifying information, and determining whether an alert represents a real threat. While service levels may be maintained, sustaining this productivity requires significantly more behind-the-scenes effort.
For organizations in South Africa already experiencing a shortage of experienced cybersecurity professionals, this operational pressure continues to mount.
Agentic AI Improves Workflows, Not Replaces People
One of the most common misconceptions about artificial intelligence in cybersecurity is the idea that it exists to substitute SOC analysts. In reality, agentic AI proves most valuable by augmenting the work of security professionals. Instead of simply automating isolated tasks or generating more alerts, agentic AI continuously gathers evidence, links activity across various security platforms, enriches investigations with contextual information, and provides analysts with a much fuller picture of an incident before human intervention.
As a result, analysts begin investigations with substantial preparatory work already completed, rather than spending valuable time collecting data. Lihili explains: 'The workflow becomes less sensitive to volume because the effort required for each investigation becomes more consistent.' He adds that 'analysts spend less time re-establishing context and more time applying their expertise where it matters most.'
Solving the Skills Gap in South Africa
South Africa continues to face a well-documented shortage of qualified cybersecurity specialists, which hinders the expansion of organizational security teams at the pace of business growth. Agentic AI offers a way to maximize the effectiveness of existing security resources. By automating routine investigative tasks and accelerating contextual analysis, organizations enable experienced analysts to focus on higher-value tasks such as threat hunting, incident response, and proactive risk reduction.
Timothy Whitaker, Head of Engineering Group and Lead Developer at Maidar Secure, states: 'Organizations in South Africa are under pressure to strengthen their cyber resilience while managing limited budgets and insufficient security skills.' He adds that 'Agentic AI allows organizations to boost the capacity and efficiency of existing SOC teams without compromising the quality of security decisions. The goal is not to reduce the number of analysts, but to empower skilled professionals to spend their time solving real security problems, rather than manually assembling data.'
Consistency Becomes a Real Advantage
As organizations scale, maintaining uniformity in security decision-making becomes more difficult. Different analysts naturally investigate incidents differently, and as alert volumes increase, inconsistencies in prioritization, escalation, and response can emerge. Agentic AI helps create a more structured investigation process by automatically gathering telemetry, historical activity, threat intelligence, environmental context, and corroborating evidence before the analyst even begins assessment. This ensures greater consistency within the SOC while reducing investigation time and improving governance.
For highly regulated industries in South Africa, including financial services, healthcare, telecommunications, mining, and the public sector, this consistency contributes to stricter regulatory compliance, improved auditability, and more predictable security outcomes.
Rethinking Security Operations Scaling
According to Lihili, the most significant advantage of agentic AI is changing the very approach organizations take to growth. He says: 'As MSSPs scale, relying solely on individual expertise becomes increasingly difficult.' Agentic AI introduces greater consistency into investigations, ensuring analysts start with a more complete understanding of every incident. Capacity grows not just because there are more people, but because each analyst can work more effectively within the same operational structure.
Whitaker believes this evolution is particularly crucial for South African enterprises adopting cloud services, hybrid work, and AI-driven digital transformation. He concludes: 'Cybersecurity can no longer rely solely on increasing headcount to meet growing demand. The future lies in combining seasoned security professionals with intelligent automation that strengthens investigations, improves response times, and allows organizations to scale securely as their digital environment evolves.'
In conclusion, agentic AI offers a practical path for organizations in South Africa grappling with rising cyber threats, tightening regulatory expectations, and persistent skill shortages in cybersecurity, to build more resilient, scalable, and efficient security operations.
