CMOtech Asia - Technology news for CMOs & marketing decision-makers
Asia
Proofpoint launches AI SOC Analyst Agent with OpenAI

Proofpoint launches AI SOC Analyst Agent with OpenAI

Mon, 7th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Proofpoint has introduced the SOC Analyst Agent for security operations teams, its first product built through OpenAI's Daybreak Defence Network.

The agent uses OpenAI Daybreak models within Proofpoint workflows to help analysts investigate threats across connected security data. It can turn natural-language questions into findings and suggested next steps, while leaving significant security decisions to human staff.

Security operations centres face growing volumes of alerts, logs and incident data across multiple tools. Proofpoint argues this has increased pressure on analysts to connect signals, add context and decide which issues need attention first.

Its 2025 Data Security Landscape report found that 54% of organisations already use AI-enhanced tools to triage and investigate alerts. That suggests a market in which suppliers are trying to apply large language models to daily security work without handing over final authority on remedial action.

The SOC Analyst Agent works across Proofpoint's own security data, including alerts, logs, data loss prevention events and user risk signals. Analysts can use natural language instead of switching between consoles or writing separate queries to piece together an investigation.

Three functions

Proofpoint groups the product around three main functions. The first is natural-language investigation across connected Proofpoint products, aimed at reducing the manual work involved in assembling context around a security event.

The second is automated recurring analysis. Teams can set scheduled workflows for threat hunts, data security investigations and escalation reporting, with results sent to the relevant analysts.

The third is traceability and human oversight. Findings are linked back to source data so analysts can validate recommendations, and the agent does not make account changes, contain threats or trigger other consequential remediation steps on its own.

That distinction reflects a wider debate in cybersecurity over how far AI systems should be allowed to act independently. Vendors have increasingly focused on "human in the loop" approaches as customers weigh the benefits of automation against the risks of false positives, missed context and unintended disruption.

Daniel Rapp, Chief Data and AI Officer at Proofpoint, outlined the company's view of that balance.

"The challenge for security teams is to cut through the noise to quickly identify which signals matter and reach a defensible decision fast enough to act," said Daniel Rapp, Chief Data and AI Officer at Proofpoint. "The Proofpoint SOC Analyst Agent brings together our security expertise and data with advanced AI reasoning from OpenAI to give analysts a faster path from investigation to action, while keeping people in control of consequential security decisions."

OpenAI also presented the launch as an example of applying its cyber-focused models to operational security work without removing human judgment.

"Our goal through the OpenAI Daybreak Defence Network is to give defenders the advantage of frontier AI, safely," said McCall McIntyre, Head of Global Cyber Partnerships at OpenAI. "Proofpoint's SOC Analyst Agent shows how frontier AI can help defenders move faster without giving up control. By combining Proofpoint's security data and human-behavior expertise with OpenAI's Daybreak models, analysts can turn fragmented signals into clearer findings, faster investigations, and recommended next steps they can trust."

Market position

The launch gives Proofpoint its first commercial product tied to the OpenAI Daybreak Defence Network after joining the programme earlier this year. It also places the company among a growing group of cybersecurity suppliers embedding generative AI into threat analysis, incident handling and reporting.

For Proofpoint, the focus is closely tied to the areas where it already sells tools, particularly email security, data loss prevention and user risk analysis. By drawing on those existing data sources, it aims to make investigations less dependent on manual correlation across different parts of a security stack.

The product is in private preview with a select group of beta customers. General availability is expected by the end of the third quarter of 2026.

Proofpoint is also examining other defensive uses for OpenAI Daybreak models across its portfolio, including threat research, data security and AI security, as it expands the role of AI reasoning in its products and workflows.