CrowdStrike has introduced a multi-agent investigative system that runs coordinated AI agents simultaneously across endpoint, identity, SaaS, cloud, and network layers. This technology offers customers configurable autonomy levels, from requiring human approval to fully autonomous operations, aiming to speed up incident detection and response within strict regulatory timeframes like those mandated by the European NIS2 directive.

  • AI agents investigate simultaneously across five security domains
  • Customers can choose between human-in-the-loop and full autonomy
  • NIS2 regulation imposes strict 24-hour reporting and liability rules

What happened

The system is designed to address the increasing complexity and speed demands in cybersecurity incident response. By running agents in parallel and sharing context, CrowdStrike claims it can reduce investigation times from hours to minutes, a significant improvement for security operations centers (SOCs) seeking faster breach detection and mitigation.

Why it matters

This advancement aligns with the European Union’s NIS2 directive, which requires essential and important entities to report significant incidents within 24 hours of becoming aware. Speeding up investigations means earlier awareness of incidents, helping organizations meet the strict regulatory timelines for early warning and full notification obligations.

Moreover, NIS2 holds management bodies personally liable for the cybersecurity measures they approve, emphasizing the need for transparency and control despite automation. While AI agents can operate autonomously, ultimate responsibility remains with human leadership to ensure compliance and risk management, raising important questions about balancing automation with legal oversight.

What to watch next

The effectiveness of CrowdStrike’s multi-agent approach will be tested as organizations integrate these systems into their workflows, particularly in regulated environments governed by NIS2. The balance between human oversight and full automation will be critical as stakeholders evaluate trust in AI-driven investigations versus traditional analyst-led processes.

Additionally, market competition is intensifying with players like Databricks entering the SOC tool space through acquisitions such as Panther Labs. How CrowdStrike maintains differentiation and adapts to evolving regulatory requirements and attacker sophistication will influence its position in cybersecurity operations moving forward.

Source assisted: This briefing began from a discovered source item from The Next Web. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings