Alert volumes are climbing. And in July, the theoretical version of the AI threat stopped being theoretical. An autonomous agent framework driven by OpenAI models ran an end-to-end intrusion against Hugging Face, executing roughly 17,600 recorded actions across a four and a half day campaign, at machine speed, with command and control staged on ordinary public web services. Hugging Face called it the agentic attacker scenario the industry had been forecasting.
AI-led cyberattacks are here, and they move faster than most security operations centers can respond. Which puts a sharper edge on the question every CISO keeps returning to: what does a SOC actually look like when AI becomes part of its core architecture, not a tool bolted onto the side of it?
On September 15, a small group of CISOs and SOC leaders will sit down together to answer that from the inside. The AI-Speed SOC: A Peer Workshop for Security Leaders runs at 8:30 AM PT / 11:30 AM ET, and it is built as a working session rather than a broadcast.
Seats are limited to 20 to 25 security leaders and every application is reviewed. Apply to attend here.
The people in the room
The session opens with a moderated conversation between two leaders who have approached the AI-speed SOC problem from opposite sides of the buyer-builder line.
Oren Saban, Co-Founder and Chief Product Officer, Mate Security
Before co-founding Mate, Saban led product for Microsoft Defender XDR and Security Copilot, which put him at the center of two of the largest bets the industry has made on AI-assisted detection and response.
Mate was founded in 2025 in Tel Aviv by Saban alongside CEO Asaf Wiener, previously a product leader at Wiz and Microsoft, and CTO Guy Pergal, a veteran of Microsoft’s threat intelligence center and a former engineering leader at Axonius. The company has built an agentic security operations platform that helps enterprises detect and respond to machine-scale attacks. The platform operates across the entire incident lifecycle including threat hunting, detection, triage, investigation and response. It emerged from stealth in November 2025 with a $15.5 million seed round from Team8 and Insight Partners, and raised a $35 million Series A in August 2026 led by Canaan Partners with participation from Microsoft’s M12, Insight Partners and Team8, bringing total funding past $50 million.
The relevance to this session is direct. The question of what an AI-native security operations center should look like is not abstract for Saban. It is the problem he left one of the world’s largest security product organizations to keep working on.
Jami Hughes, Deputy CISO, Zions Bancorporation
Hughes brings the operator’s side of the conversation. Zions is one of the larger US bank holding companies, with more than $90 billion in total assets, and she is responsible for security inside an environment where getting the architecture wrong is measured in more than dwell time.
She has served as an information security officer eight times across her career. After a tenure at American Express she founded a managed service provider business in Utah, then moved to WebBank as Chief Information Security Officer, where she worked with new fintechs on building technology controls and cyber programs. She spent three years as CISO at Progressive Leasing before joining Zions, where her work on the Enterprise Information Security group has focused on increasing efficiency through automation.
That last point is why she is in this room. The question of how much of the security operations workload can be handed to machines is not a forward-looking one for Hughes. It is what she has been doing.
She was also one of the founding leaders of the Utah professional affiliate of Women in CyberSecurity.
The conversation is moderated by Carly Page, formerly senior cybersecurity reporter at TechCrunch and editor of The Inquirer, who now writes on security for Forbes, WIRED, The Register and The New Stack.
Why the format is what it is
After the opening conversation, the room breaks into small-group roundtables. Participants share approaches and challenges directly with peers who live the same operating reality, in groups small enough that everyone speaks.
Chatham House Rules apply throughout. That is a deliberate choice. The honest version of this conversation includes the tooling that did not work, the automation that created more triage work than it removed, and the staffing decisions that looked right on a slide and did not survive contact with a real incident queue. None of that gets said in a room that might be quoted.
Attendance is capped at 20 to 25 security leaders, and every application is reviewed for alignment. The goal is a room where every person contributes, not an audience that listens passively.
Who should apply
The session is built for CISOs, SOC Directors, Incident Response Managers, and security operations leaders at enterprises running dedicated SOC teams of 10 or more.
It will be most useful if you are:
- Actively managing alert volume and the analyst load that comes with it
- Evaluating AI-driven detection and response tooling and trying to separate capability from positioning
- Rethinking how your security operations team is structured for what is coming next
The reason this is worth the morning
Most conversations about AI in the SOC happen at one of two altitudes. Either they stay at the level of strategy, where nothing is specific enough to act on, or they happen inside a vendor demo, where the operating constraints of a real environment are assumed away.
This session sits between those. Saban brings the product perspective from someone who shipped AI security tooling at Microsoft scale and is now building it at Mate. Hughes brings the pressure test from someone accountable for security operations at a major financial institution and already running automation inside one. The roundtables bring the rest of the room into it.
Apply now to be considered for one of the 25 seats available for this closed-door roundtable on. September 15, 8:30 AM PT / 11:30 AM ET.Â
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

