They went first: How Orbis proved the Agentic SOC inside its own business
Protecting a global enterprise with more than one million devices generates a relentless stream of alerts. Inside the company's security operations center (SOC), analysts were spending up to 80% of their time reviewing false positives and carrying out routine investigations, leaving less time for threat hunting and complex cases.
Orbis went first, so customers can move forward with greater confidence.
Orbis CyberGuard is delivering measurable value across security operations
Orbis saw an opportunity to rethink the model and made its own operations the proving ground.
- 99% of alerts automated
- 67.5% reduction in investigation time
- Greater than 95% remediation accuracy
- More than 225,000 hours of SOC analyst time saved
- Consistent, audit-ready documentation across every incident and shift
What stood in the way
Protecting a global enterprise with more than one million devices generates a relentless stream of alerts. Inside the company's security operations center (SOC), analysts were spending up to 80% of their time reviewing false positives and carrying out routine investigations, leaving less time for threat hunting and complex cases.
As part of Orbis's pivot to becoming an AI-first company, the cybersecurity team began exploring how AI could help protect the business more effectively. The team looked widely across the market, but much of what was found focused on adding chatbot capabilities to existing security tools. These assistants could search, summarize findings and support analysts, but they didn’t fundamentally change how investigations were carried out. Orbis needed AI that could go further by taking on repeatable investigation work and helping teams respond faster. The SOC offered a clear place to start. Many early investigation tasks follow established processes, making them well suited to AI agents.
“Most of the market was still bolting in chatbots and calling it AI. Orbis was looking for something truly agentic that could transform the way the company operates cyber at machine speed.”
How Orbis got to work
Rather than waiting for the technology to mature elsewhere, Orbis chose to go first. Orbis deployed Orbis CyberGuard, powered by autonomous AI agents, across its own global security environment. This made Orbis Customer Zero and allowed the company to prove the approach under real operating conditions before bringing it to customers.
The result delivered
Automating repeatable investigations has opened up new opportunities for analysts to build skills and grow their careers. Tier-1 work still exists, but it no longer needs to define an analyst’s role. With AI agents handling much of the routine triage and investigation, people can take on more complex cases and move into higher-value areas such as threat hunting and intelligence. Their expertise also helps validate findings and refine how agents respond as threats evolve.
“The outcome the team is most proud of is that Orbis has put itself in a position to demonstrate real value and show the rest of the industry what is possible.”
Orbis CyberGuard can also integrate with Orbis FlowOps, the agentic IT operations platform, bringing cyber and IT operations into a single, unified view. Leaders gain real-time visibility of security performance across the wider IT estate, shortening the path from threat detection to remediation. By connecting systems, data and AI agents on one platform, Orbis FlowOps helps organizations move from reactive operations to more predictive, adaptive ways of working, with a Human + AI approach at the center.
From internal proof to customer confidence
Becoming Customer Zero has changed what Orbis can bring to customers. Teams know what it takes to deploy AI agents in live security operations, assess their performance and improve their capabilities over time.
Across a diverse set of customer environments, Orbis CyberGuard has processed more than 100,000 security incidents in production, delivering improvements of approximately 88-95% in mean time to investigate, 83% in mean time to resolve and 95% in analyst handling time.
Orbis also stress-tested Orbis CyberGuard to expose where it could fail, helping understand where agents perform well, where stronger guardrails are needed and what effective governance looks like in practice. Those lessons shape the operating model now brought to customers.
And the SOC is only the beginning. As AI-enabled threats continue to evolve, Orbis can apply this experience across more cybersecurity processes and help organizations strengthen their cyber resilience.










