CrowdStrike announces synchronized multi-agent inquiries spanning five domains.
CrowdStrike has revealed coordinated multi-agent investigations built on a shared context layer, enabling customers to determine the level of autonomy ranging from human-in-the-loop approvals to fully self-sufficient execution. The NIS2 directive commences its 24-hour reporting countdown once an organization becomes aware of a significant incident and holds management accountable for the measures they endorse.
According to CrowdStrike, AI agents now conduct attacks across multiple systems simultaneously, necessitating that investigations adapt accordingly. The company has introduced coordinated multi-agent investigations spanning endpoint, identity, SaaS, cloud, and network.
Michael Sentonas, CrowdStrike’s president, framed the issue as one of trust. He stated that agents in the Security Operations Center (SOC) are fundamental, and the central question for every Chief Information Security Officer (CISO) is how to trust the findings of these agents.
The promise is swift investigation, transforming hours into minutes. The market is competitive, and Databricks purchased Panther Labs this year to compete with Splunk and CrowdStrike.
Agents operate in parallel within a shared context layer, maintaining persistent memory across all agents, investigations, and tenants. Customers have the flexibility to define the level of autonomy for each workflow, whether it involves human review or total automation.
In Europe, this expedited process carries an additional implication. The NIS2 directive mandates that essential and important entities must provide an early warning within 24 hours and complete notification within 72 hours.
The countdown begins once an organization recognizes a significant incident, rather than when an analyst completes documenting the incident.
Therefore, streamlining the investigation reduces the available time. An agent reaching a conclusion in minutes effectively brings forward the moment of awareness, consuming a larger portion of the 24-hour window.
Another significant aspect pertains to who must approve these actions. Automating the responsibilities of analysts does not automate the approval required from the designated individual referenced in the directive.
Article 20 mandates that management bodies endorse the cybersecurity risk-management strategies and supervise their execution, stating they can be held accountable for any breaches. Members are also obliged to undergo training.
There is no level of autonomy designated for this task. A board may authorize fully autonomous operations but remains responsible for the outcomes of any decisions made within that framework.
Sentonas is posing an important question, especially in light of a recent event in Europe. Attackers compromised the scanner used by the European Commission, leading its automated pipeline to implement a flawed update.
This breach occurred through a security tool operating as intended. Increasing autonomy also raises the stakes of similar failures.
However, the implementation of these regulations has not yet been uniformly enforced. The deadline for transposition passed in October 2024, and the Commission pursued 23 member states before referring four to the Court of Justice in July.
Other articles
CrowdStrike announces synchronized multi-agent inquiries spanning five domains.
CrowdStrike reports that their agents reduce investigation times from hours to minutes. NIS2 allows for a 24-hour period from the moment of awareness, so quicker conclusions minimize this timeframe.
