Alert triage is a reasonable place to start with AI. It is not a reasonable place to stop.
Most of what slows down security service providers has nothing to do with triage.
It's the onboarding that takes multiple days. The cross-tenant configuration work nobody wants to touch. The detection rules that need to be written, tested, and deployed across fifty environments.
Vendor AI addresses one use case at a time, which means a separate product, a separate workflow, and a separate wait for the next release.
ASW takes a different approach.
Give it hundreds of tools, describe the outcome you want, and it finds a way to get there. That's not a feature. That's a fundamentally different way of getting value from AI, across the whole operation, not just the alert queue.
Watch the full keynote: https://www.youtube.com/watch?v=QS0DzO2rNJw


