What Can Agentic Cybersecurity Do And 2027 CISO Budgets
Agentic cybersecurity is transforming operations and shaping 2027 security budgets. New Cisco and Omdia research found that 95% of enterprises say their existing AIOps tools can’t keep up. More than half of 1,000 IT and network operations leaders at organizations with 500 or more employees say they have already moved to AgenticOps.
While CISO notes that the volume of the current threat landscape would require the average organization to hire 100 IT specialists just to clear its daily network alert backlog by hand, trust remains an issue.
The global October PwC survey found that 84% of senior leaders expect cyber budgets to rise as frontier AI models are rolled out but only 22% would authorise fully autonomous execution by AI agents for cyber defence.
In this report, Google Cloud’s CISO, Moonlock by MacPaw’s senior malware research engineer, and Orcus’ CEO explain what agentic cybersecurity tools can do today, and how they are shaping 2027 CISO budgets.
What Can Agentic Cybersecurity Tools Do?
As agentic cybersecurity technologies evolve, and security teams play catch up, understanding what they can do and they cannot do is central to operations.
“AI agents are increasingly showing their ability in taking over the tasks that used to bury analysts, such as alert triage and investigation,” Chris Betz, CISO of Google Cloud says.
Agents can now enrich an alert, analyze command lines, build process trees, and hand a human a verdict with recommended next steps, following the same playbook frontline analysts use, says Betz.
“But we’re also seeing agents who are strong at synthesizing threat intelligence, checking new product designs against security requirements, generating fuzz tests, catching configuration drift, and drafting and verifying patches,” Betz explained.
“Where I still want a human approving is anything that’s hard to undo or where the results have significant impact: changes to production, disabling high-privilege or executive accounts, customer-facing actions, and anything involving legal or regulatory obligations,” says Betz.
Mykhailo Pazyniuk, senior malware research engineer at Moonlock by MacPaw explains that beyond bug hunting, agents are good at triaging alerts, enriching IoCs, clustering malware variants, checking suspicious URLs and emails (among other things),” says
In Moonlock Lab, agentic cybersecurity tools are used mostly for reverse engineering and threat intel, says Pazyniuk.
“They peel apart obfuscated multi-stage chains, pull out IoCs, and pivot to related infrastructure in minutes instead of hours,”says Pazyniuk. “Still, it’s near-real-time and always with an analyst in the loop, not ‘set it and forget it’.”
Pazyniuk explains that agents can also partly help with live digital attack surface monitoring, but no end point security.
“Agents can help map assets and prioritize exposures, but endpoint protection still runs on deterministic engines like signatures, behavioral rules, and ML models, because it has to be fast and predictable/auditable,” says Pazyniuk.
“For us, agents work upstream: the faster we take a new stealer sample apart, the faster a detection lands on users’ Macs,” says Pazyniuk.
How Agentic Cybersecurity Tools Can Help Companies Respond to Ransomware, Fraud and Brand Impersonation?
Verizon’s 2026 Data Breach Investigations report shows that ransomware grew again to 48% of all breaches, up from 44% from the previous year, while Socure’s report found that AI-based fraud attacks surged more than 8,000% across all industries and companies of all sizes.
On the other hand, Microsoft notes that ClickFix attacks, where trusted and known brands are impersonated to lure users into downloading malware, were observed by Microsoft Defender on more than 1.1 million unique devices, between February and early May 2026, roughly an eightfold increase compared to 2025. Can agentic cybersecurity tools respond in real time to these threats?
“Technically, yes,” says Pazyniuk, on ransomware and brand impersonation.
Hooked into EDR or SOAR, an agent can isolate a host, kill a process, or block a hash (sample), Pazyniuk says. “But one wrong call (or one prompt-injected agent) can knock out legitimate systems, so most teams keep a human on the trigger for high-impact actions.”
On the other hand, Pazyniuk explained that ransomware is a job for endpoint behavioral detection, because mass file encryption and wiped backups have to be stopped at machine speed.
“Agents earn their keep after the alarm by scoping the incident and speeding up decisions,” says Pazyniuk.
“Brand impersonation is a better fit since agents can spot lookalike domains, fake installers, and/or malvertising, and group them into campaigns, which is exactly what we keep catching in the wild,” says Pazyniuk.
“But spotting a fake site isn’t the same as taking it down, and that still depends on registrars, hosts, and ad platforms,” says Pazyniuk and explains that an agent can collect evidence and file abuse reports faster, but it can’t make a registrar act.
Flagging, enriching, and blocking IoCs at scale is where agents shine, from extraction to verdict to blocklist update, Pazyniuk explains. “Attackers also rotate infrastructure and chain redirects to dodge automated checks, so a blocked domain can be stale by the next morning,” Pazyniuk adds.
Speaking of agentic cybersecurity capabilities to respond to ransomware, Nic Adams , CEO of 0rcus ,a cyberkinetics company, says an agent spots mass renames, entropy spikes, and shadow copy deletion within seconds. “It then kills the process tree, isolates the host via EDR, revokes the user’s IdP sessions, blocks C2 at DNS, then sweeps every endpoint for the same behavior before an analyst finishes reading the alert,” says Adams.
Regarding impersonation and fraud, Adams says agents watch CT logs, new domain registrations, and app stores for lookalikes, confirm credential harvesting, file registrar and host takedowns, and then push IoCs to email gateways and blocklists. “So a phishing site can come down within hours of registration,” says Adams.
On attack surface monitoring, agents map exposed assets and leaked keys around the clock, then validate exploitability with safe offensive testing so teams patch what attackers can actually reach, Adams explained.
“Rule of thumb: require human sign-off only for destructive actions such as wiping hosts,” says Adams.
How to Use Agentic Cybersecurity Tools Safely to Mitigate Cyberattacks
To use agents to mitigate ransomware, phishing, and brand impersonation without creating new exposure, Betz says that agents need to be secured as active operators, not passive copilots.
“That starts with identity and least privilege, tight controls on outbound network access, segmentation, and logging for every agent,” says Betz. “Then deal with the risk specific to security work: a phishing agent is, by definition, reading content the attacker wrote.”
“Every email and every lookalike site is potentially a prompt,” says Bertz. “So keep untrusted content separate from the agent’s instructions, filter inputs and outputs at runtime, and never give an agent that reads attacker content broad permissions to act.”
“Against ransomware, an agent can spot precursor behavior at machine speed, but it’s immutable backups, MFA, and patching that keep a bad day from becoming a catastrophic one,” says Bertz.
Navigating Agentic Cybersecurity Trust Via the Technical Route
As the CISCO report notes, security leaders are taking a technical route to navigate the trust issue. 99% of organizations say they won’t trust AI to act without guardrails, including explainable AI actions, human approval for actions, policy-based operational limits emergency override mechanisms, role-based access control, and immutable audit trails.
“I advise CISOs to treat an agent like a new employee with a very fast hand on the keyboard,” says Betz.
Betz explains that before letting an agent act, companies should have five things in place. Identity, Granularity, Reversibility. Logging, Scalability (circuit breakers), Defined actions.
Agentic Cybersecurity Benefits: Triage and Investigation, and Vulnerabilities, and How to Measure Them
Betz explains that the clearest benefits from agentic tools today include cutting alert fatigue through automated triage and investigation, a key area where analysts spend significant effort, and where agents can unlock substantial time savings.
“The second, and the one I think is most fundamental, is prioritizing exploitable risk and closing the gap between finding and fixing,” says Betz. “Security leaders keep telling me they’re facing a tenfold increase in the vulnerabilities they have to address,” says Betz. “Finding more problems isn’t the bottleneck anymore: Fixing the ones that matter is”.
Agents that combine code context, runtime exposure, and threat intelligence can tell companies which handful of issues an attacker can actually reach, and then help verify and ship the fix, says Betz.
To measure these benefits Betz says companies should measure outcomes, not activity. This include false and negative-positive rates, time to fix, time to detect, analyst hours returned, and exposure window and coverage.
“If those numbers aren’t moving, you haven’t changed your security posture,” says Bertz. “You’ve just added a tool.”
How Agentic Cybersecurity is Shaping CISO 2027 Budgets
“I advise CISOs to protect the foundation,” says Bertz. It’s a dangerous misconception that fundamentals are becoming obsolete in the AI era, Bertz explains. “They’re what makes agentic security work,” says Bertz.
Gerz says companies should protect or increase:
- Identity, especially for machine and agent identities: MFA, Zero Trust, least privilege.
- Logging, telemetry, and data quality. This is the context your agents reason over.
- Integration and open architecture, so agents can act across your stack.
- Governance and evaluation: testing, monitoring, and kill-switch capability for agents.
- Your people: the best investment to innovate, supervise, tune, and challenge with agents.
While consolidate or reduce:
- Overlapping point tools that each do one narrow job and duplicate your data.
- Manual, rules-based tier-1 triage that agents now handle better.
- Custom glue code holding siloed tools together.
- Paying a premium for a single model on every task when a mix of models gets better results at a lower cost per token.
“The biggest hidden cost in most security budgets is the time between finding a problem and fixing it,” says Bertz. “Spend to shrink that”.
Adams, CEO of 0rcus says that attackers already run agents. “Which is why every 2027 dollar spent on humans triaging Tier 1 alerts is a dollar handed to them,” says Adams.
“I would move that budget into autonomous containment, continuous offensive validation, and automated takedown; then redeploy analysts into threat hunting and agent oversight,” Adams says, noting the IBM’s 2025 data which shows AI and automation power-users saved ~$1.9M per breach.
Final thoughts on Agentic Cybersecurity and 2027 Budget
Berz says that a responsible path to near future more autonomous operations and which decisions stay human-led should be thought as a dial, not a switch.
Companies should move from assisting, to recommending, to acting with approval, to acting within defined limits, and expanding those limits only when the evidence supports it.
“Some decisions should stay human-led: accepting risk and making business trade-offs, disclosure and regulatory notification, actions that broadly affect customers or production, and any change to an agent’s own permissions,” says Bertz.
“Autonomy should be earned, never self-granted.”