Securonix Takes On Data Costs, Detection Gaps, and AI Agent Risk at Black Hat USA 2026

0
135
Securonix Takes On Data Costs, Detection Gaps, and AI Agent Risk at Black Hat USA 2026
Securonix Takes On Data Costs, Detection Gaps, and AI Agent Risk at Black Hat USA 2026

INDIA, August 4th 2026-  Securonix, Inc., a six-time Leader in the Gartner® Magic Quadrant™ for SIEM, today announced expanded Data Pipeline Manager (DPM) licensing, the now-shipping Securonix DPM agent, expanded Threat Analytics for Microsoft Sentinel, and new Governed AI Agent Detection and Response capabilities at Black Hat USA 2026. These additions extend the Securonix Unified Defense SIEM platform to help enterprises and managed security providers control data costs, improve detection coverage and response, and govern risks introduced through enterprise AI adoption.

Security teams face three pressures at once. Telemetry volumes and SIEM costs continue to rise. Threats increasingly span identity, cloud, endpoint, application, and third-party environments. Enterprises are also deploying AI assistants, autonomous workflows, and digital workers that can access sensitive systems and act on behalf of users. Security leaders must address these pressures while preserving visibility, protecting existing technology investments, and improving outcomes without proportionally increasing staff or operational complexity.

Securonix is addressing those priorities through three areas of expansion: Governed AI Agent Detection and Response for identifying risky activity across human and non-human identities , expanded DPM licensing and the now-shipping Securonix DPM agent for greater control over security data economics, and deeper Threat Analytics for Microsoft Sentinel for enterprises, MSSPs, and MDR providers.

“Security operations cannot scale by continually adding more data, more tools, and more analyst effort,” said Toby Weiss, Chief Executive Officer of Securonix. “We are giving customers better control over the data they retain, stronger detection across the platforms they already use, and clear oversight of automated activity. That gives the SOC room to grow without losing control of cost, context, or risk.”

Strengthen Microsoft Sentinel Without Replacing It

Securonix has expanded Threat Analytics for Microsoft Sentinel, a lightweight, cloud-nativen analytics and enrichment layer designed to improve detection fidelity while keeping Microsoft Sentinel at the center of the SOC.

Threat Analytics applies behavior-driven analytics, industry-leading UEBA, advanced correlation, entity context, dynamic risk scoring, and continuously maintained Threat Labs content to telemetry already available in Sentinel.  It returns enriched, higher-confidence detections directly to Sentinel for triage, investigation, and response. Analysts continue working in their existing Sentinel workflows. Customers gain broader coverage and richer behavioral context without deploying additional endpoint agents, duplicating customer data, building new customer-side pipelines, replatforming the SOC, or operating a second SIEM.

“Sentinel customers have already made their platform choice,” said Hunt. “We are adding depth where it counts: behavioral context, cross-source correlation, and risk-based prioritization. Analysts stay in Sentinel, while the detections reaching them carry more evidence and a clearer reason to act.”

With more than 2,400 continuously maintained, Threat Labs-backed detections, Threat Analytics helps teams identify identity attacks, insider threats, ransomware, cloud compromise, and advanced persistent threats with greater context and confidence.

For MSSPs and MDR providers, the offering creates a path to differentiated managed detection services across multi-tenant environments. Behavioral analytics, cross-source correlation, and risk-based prioritization help providers reduce noise, standardize investigations, and focus analyst attention on the threats carrying the greatest risk. The offering helps service providers strengthen managed detection without disrupting customer environments, replacing Microsoft Sentinel, or introducing a disconnected analyst workflow.

Detect and Govern Risk Across Enterprise AI Agents

Securonix is introducing new Governed AI Agent Detection and Response capabilities designed to help organizations identify and respond to abnormal or risky activity involving enterprise AI assistants, autonomous workflows, and digital workers. AI agents increasingly interact with users, identities, applications, sensitive data, tools, and business processes. Security teams need visibility into what those agents are doing, which resources they are accessing, and whether their behavior changes in ways that indicate misuse, compromise, or policy violations.

Securonix applies behavioral analytics across human and non-human identities to detect abnormal agent activity, suspicious human-to-agent interactions, risky tool invocation, unusual prompt behavior, unauthorized AI adoption, and potential misuse or compromise, or policy violations.The capabilities are designed to monitor activity from supported enterprise AI environments, including Anthropic Claude, Google Gemini, Microsoft Copilot, and GitHub Copilot. Detection findings retain behavioral context, investigations remain explainable, response actions can be reviewed and audited, and human analysts maintain oversight of consequential decisions.

“The moment an AI agent can access a mailbox, call an API, or change a business process, its behavior belongs in the security picture,” said Simon Hunt, Chief Product Officer of Securonix. “Analysts need to know what it touched, why it acted, and whether that activity fits policy. We are bringing that context into the same investigation and response process teams use every day.”

Control Security Data Costs Without Sacrificing Visibility

Securonix has expanded DPM licensing across eligible SIEM environments and is now shipping the Securonix DPM agent. Together, these capabilities give enterprises and service providers greater control over how telemetry is collected, routed, retained, and analyzed.

Many security data strategies force teams to choose between managing costs and preserving visibility. Securonix helps organizations align telemetry with its operational and security value. High-priority data can support real-time analytics and detection, while other telemetry remains available for investigation, threat hunting, compliance, and long-term retrieval. Analysts retain access to the data required for investigations. Security leaders gain more predictable economics. Enterprises and MSSPs can expand coverage without discarding telemetry that may later prove critical.

Securonix Data Pipeline Manager can help organizations reduce SIEM data costs by 30–50% by ensuring that only security-relevant data is processed through the Analytics Pipeline, while investigation and compliance data are routed through cost-efficient pipelines.

Behavioral Analytics Recognized by QKS Group

Securonix was named a Leader in the 2026 QKS SPARK Matrix™ for Insider Risk Management.  The recognition reinforces Securonix’s behavioral analytics foundation for insider risk management. That same behavioral analytics foundation powers a broader portfolio of innovations, including Threat Analytics for Microsoft Sentinel, identity and entity analytics, and Governed AI Agent Detection and Response. With these new capabilities, Securonix is helping organizations govern emerging AI agent activity, preserve access to valuable telemetry, and improve detection across existing environments without abandoning trusted platforms or adding unnecessary operational complexity.

Availability

  • Expanded DPM licensing is available for eligible SIEM environments, and the Securonix DPM agent is now shipping.
  • Securonix Threat Analytics for Microsoft Sentinel is available for enterprise SOCs, MSSPs, and MDR providers using Microsoft Sentinel.
  • Governed AI Agent Detection and Response capabilities are available as part of the Securonix Unified Defense SIEM platform.

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.