Episode #67 Erik Dove from Cisco talks Agentic SOC and Security Operations

In the Packet Forensic Files, Episode 67, Michael talks to Cisco’s Erik Dove.

By Michael Morris, Senior Director of Global Business Development, Endace


How Agentic AI is changing Security Operations.

Michael Morris, Director of Global Business Development, Endace

Artificial intelligence is rapidly reshaping Security Operations Centers (SOCs), helping security teams investigate incidents faster while reducing alert fatigue. But as AI becomes more capable, what role do human analysts and packet data play in an increasingly automated SOC?

In Packet Forensics Files Episode 67, I sit down with Cisco Security Sales Engineer and Incident Response expert Erik Dove to discuss how Agentic AI is changing incident response, where packet data fits into modern SOC workflows, and why experienced analysts remain essential.

Erik’s first point was that AI’s biggest benefit isn’t simply speed. It’s improving the accuracy of incident triage. By helping analysts identify which alerts genuinely deserve attention, AI reduces time spent on false positives and lets teams focus on real threats.

He also explained that effective AI starts with strong foundations. Organizations need clear priorities and service level agreements so AI can accurately identify the alerts that matter most.

We explored where always-on packet capture fits into an AI-assisted SOC. While SIEMs, XDR platforms and firewalls all provide valuable telemetry, packet data gives investigators the evidence to validate alerts, reconstruct communications and build accurate timelines. Rather than relying solely on logs, analysts can quickly determine whether activity is truly malicious and understand the “why” behind an alert.

One of my favourite parts of the discussion was Erik’s perspective on the future role of analysts. Rather than replacing people, he sees AI acting as a team of specialists that can summarize incidents, assist investigations, support orchestration and document findings. Human judgement remains essential because cybersecurity investigations still require context, experience and decision-making that AI cannot provide on its own.

To wrap up, I asked Erik what a fully optimized Agentic AI SOC might look like. He compared modern investigations to Law & Order. The tools continue to improve and the cases become more complex, but investigators still rely on evidence. In cybersecurity, those digital fingerprints are preserved in packet data, giving analysts the visibility they need to understand exactly what happened.

If you’re interested in how AI, automation and packet capture are shaping the future of security operations, I encourage you to watch the full episode. It’s a fascinating discussion with plenty of practical advice for organizations looking to build more effective SOCs.

Other episodes in the Secure Networks video/audio podcast series are available here. Or listen to the podcast here, or on your favorite podcast platform.