Normalized claim
Data-gathering time per event: 1 minutes decrease
"This entire data-gathering process takes the agents just one minute"
SEP2 uses Gemini Enterprise Agent Platform to deploy custom AI agents for faster triage and enhanced threat detection capabilities. In its UK-based security operations center, SEP2 was facing growing log volumes and a manual bottleneck because analysts spent up to 20 minutes manually checking firewalls, endpoints, and threat feeds for each event. SEP2 built an ecosystem of interconnected agents with distinct personas, including triage agents and threat intelligence agents, to gather and summarize multi-step threat context for human review. The approach integrates Google Security Operations and supports rapid iteration of new rules and external feed integrations.
Reported outcomes
6x
threat-detection rule authoring speedTime & speed
Strategic outcomes
Catalog median for time & speed deployments: +60% across 143 reported metrics. Compare benchmarks →
Normalized claim
Data-gathering time per event: 1 minutes decrease
"This entire data-gathering process takes the agents just one minute"
Normalized claim
Manual checking time per event: 20 minutes decrease
"SEP2 security analysts spent up to 20 minutes manually checking firewalls, endpoints, and threat feeds for a single event"
Normalized claim
Threat-detection rule authoring speed: 6 x increase
"build new threat detection rules six times faster"
Google Security Operations supports the workflow, and new feeds or summary formats can be deployed within hours
Primary read
Showing 1 of 1
Custom AI agents built with Gemini Enterprise Agent Platform and Gemini models operate alongside human analysts in a security operations workflow. Separate agent personas gather data across firewalls, endpoints, and external threat feeds, summarize the findings, and hand them to human reviewers. Google Security Operations is used alongside the platform, with configuration designed for data isolation and UK data residency.
AI-generated summary. Verify important details with the linked sources before relying on this case.
Was this useful?
Community
No published comments yet.