Case StudyCybersecurity

They went first: How Orbis proved the Agentic SOC inside its own business

Protecting a global enterprise with more than one million devices generates a relentless stream of alerts. Inside the company's security operations center (SOC), analysts were spending up to 80% of their time reviewing false positives and carrying out routine investigations, leaving less time for threat hunting and complex cases.

Executive Summary

Orbis went first, so customers can move forward with greater confidence.

At a glance

Orbis CyberGuard is delivering measurable value across security operations

Orbis saw an opportunity to rethink the model and made its own operations the proving ground.

Outcomes
  • 99% of alerts automated
  • 67.5% reduction in investigation time
  • Greater than 95% remediation accuracy
  • More than 225,000 hours of SOC analyst time saved
  • Consistent, audit-ready documentation across every incident and shift
The Challenge

What stood in the way

Protecting a global enterprise with more than one million devices generates a relentless stream of alerts. Inside the company's security operations center (SOC), analysts were spending up to 80% of their time reviewing false positives and carrying out routine investigations, leaving less time for threat hunting and complex cases.

As part of Orbis's pivot to becoming an AI-first company, the cybersecurity team began exploring how AI could help protect the business more effectively. The team looked widely across the market, but much of what was found focused on adding chatbot capabilities to existing security tools. These assistants could search, summarize findings and support analysts, but they didn’t fundamentally change how investigations were carried out. Orbis needed AI that could go further by taking on repeatable investigation work and helping teams respond faster. The SOC offered a clear place to start. Many early investigation tasks follow established processes, making them well suited to AI agents.

“Most of the market was still bolting in chatbots and calling it AI. Orbis was looking for something truly agentic that could transform the way the company operates cyber at machine speed.”

The Approach

How Orbis got to work

Rather than waiting for the technology to mature elsewhere, Orbis chose to go first. Orbis deployed Orbis CyberGuard, powered by autonomous AI agents, across its own global security environment. This made Orbis Customer Zero and allowed the company to prove the approach under real operating conditions before bringing it to customers.

The solution uses autonomous investigation and AI reasoning to handle high-volume, repeatable alert work.
It investigates alerts in parallel, correlates evidence from across the security environment and gives analysts clear, evidence-based findings.
Running the solution in production also helped refine how it operated. Cybersecurity teams reviewed investigations and used that feedback to improve agent capabilities and investigation strategies over time.
This gave Orbis practical, firsthand experience of managing and improving agentic AI in a live security operation.
The Solution

The result delivered

Automating repeatable investigations has opened up new opportunities for analysts to build skills and grow their careers. Tier-1 work still exists, but it no longer needs to define an analyst’s role. With AI agents handling much of the routine triage and investigation, people can take on more complex cases and move into higher-value areas such as threat hunting and intelligence. Their expertise also helps validate findings and refine how agents respond as threats evolve.

99% of alerts automated
67.5% reduction in investigation time
Greater than 95% remediation accuracy
More than 225,000 hours of SOC analyst time saved
Consistent, audit-ready documentation across every incident and shift

“The outcome the team is most proud of is that Orbis has put itself in a position to demonstrate real value and show the rest of the industry what is possible.”

Orbis CyberGuard can also integrate with Orbis FlowOps, the agentic IT operations platform, bringing cyber and IT operations into a single, unified view. Leaders gain real-time visibility of security performance across the wider IT estate, shortening the path from threat detection to remediation. By connecting systems, data and AI agents on one platform, Orbis FlowOps helps organizations move from reactive operations to more predictive, adaptive ways of working, with a Human + AI approach at the center.

Customer Zero

From internal proof to customer confidence

Becoming Customer Zero has changed what Orbis can bring to customers. Teams know what it takes to deploy AI agents in live security operations, assess their performance and improve their capabilities over time.

Across a diverse set of customer environments, Orbis CyberGuard has processed more than 100,000 security incidents in production, delivering improvements of approximately 88-95% in mean time to investigate, 83% in mean time to resolve and 95% in analyst handling time.

Orbis also stress-tested Orbis CyberGuard to expose where it could fail, helping understand where agents perform well, where stronger guardrails are needed and what effective governance looks like in practice. Those lessons shape the operating model now brought to customers.

And the SOC is only the beginning. As AI-enabled threats continue to evolve, Orbis can apply this experience across more cybersecurity processes and help organizations strengthen their cyber resilience.