IdentitySecOps: The Closed-Loop Model for AI-Speed DefenseĀ 

Aug 05, 2026
6 minutes

For 25 years, enterprise security has tolerated a structural flaw: treating the identity security team and the Security Operations Center or SOC as separate silos. Instead of rapid response, we've built security by bureaucracy. When an identity risk pops up, the SOC logs a ticket, hands it to the identity team, and waits for it to act.Ā 


Key Takeaway: IdentitySecOps, or IdSecOps, is a cybersecurity framework that merges identity management and security operations into a continuous loop. By automating workflows for identity threat detection and response, or ITDR, IdSecOps helps teams detect, provide context, and close the "open loop" vulnerability, neutralizing AI-speed attacks.


This ticket-based relationship caused a break in the loop, but it wasn't fatal. It could take days or weeks for a human to breach a system, probe the network, locate valuable data, and figure out how to slowly extract it without tripping alarms. When adversaries operated at human speed, so could defenders.Ā 

Today, this open loop is one of your biggest attack surfaces.

AI Attacks Can Outrun Human-Speed Defense

AI compresses the two most critical variables in cybersecurity: how quickly an attack unfolds and what an attacker needs to target to achieve their goal.

The 2026 Unit 42 Global Incident Response Report found that fastest 25% of real-world intrusions reached data exfiltration in 72 minutes, four times faster than the year before. In a separate controlled test using AI at every stage of a simulated attack, Unit 42 completed a full data heist in just 25 minutes.

You can’t get a low-priority support ticket assigned to a human analyst in 25 minutes, let alone investigate and neutralize a threat.Ā 

Enterprises are standing up AI agents at scale: swarms of digital workers that move at machine speed. Each one has its own identity. It holds real privileges, accesses data, and can "think" for itself. Governing AI agents effectively requires teams to answer two different questions:

  • The Posture Question (Identity Team): What should this agent be allowed to do?
  • The Detection Question (SOC): What is this agent actually doing right now?

However, ifĀ  you split posture and detection across siloed teams, a hijacked AI agent will look perfectly normal to both sides. The identity team checks its systems and sees the agent has the correct database permissions; the SOC sees an automated tool moving incredibly fast and touching lots of data, exactly what AI agents are supposed to do. Unfortunately, neither team has the context to realize the agent has gone rogue. This is the open loop that attackers can exploit in less than half an hour.

To match that speed, the agentic enterprise needs a new operating model.

If you split posture and detection across siloed teams, a hijacked AI agent will look perfectly normal to both sides.

IdSecOps Connects Detection and ResponseĀ 

ITDR provides critical detection and response capabilities, but technology alone cannot close the loop.

Organizations must connect identity posture, threat detection, automated response, and continuous learning. IdSecOps enables identity teams and security operations to share context, response, and accountability, forming a feedback loop that closes in seconds.Ā  Ā 

DevSecOps Left the Return Path UnfinishedĀ 

A decade ago, developers shipping to the cloud and security teams guarding production didn’t understand each other's work. DevSecOps fused their workflows, integrated security into the pipeline, and forever changed how existing teams worked. But it left the job half-finished.Ā 

DevSecOps never fully solved the return path: insights from production rarely flowed back to the start of the pipeline, meaning teams just repeated the same mistakes. A decade later, the DevSecOps community is still trying to retrofit that feedback loop.

IdSecOps begins where DevSecOps stalled. The loop is a smarter design, not a retrofit. Security learns from the left, where entitlement context lives. Identity learns from the right, where the detection signal lives. Neither direction is optional.

Four Questions That Define IdSecOps

The underlying principle is simple: detection has limited value if the response still depends on a ticket or a second console. The real test is what happens immediately after an identity threat is detected. Who has to do what next? Does the alert trigger another process or does it begin the response?Ā 

If the answer includes requesting approval or waiting for someone to change the identity’s access, you've found the open part of your loop.

At a high level, closed-loop architecture should help all teams answer four questions:

  1. How much damage could this identity do?
  2. What is the identity doing right now?
  3. Can we stop it fast enough?
  4. Will what we learn make us better prepared next time?
IdSecOps connects governance, detection, response, and learning through a shared data foundation.

Closing the loop means replacing a slow, sequential process with a continuous exchange of context, detection, and action.

Test Your IdSecOps Maturity

So: how open is your loop today? Most organizations sit somewhere between two disconnected teams and a fully connected architecture.

For example, identity context may already reach the SOC while the response remains manual. Teams may collaborate during major incidents but operate separately the rest of the time. One identity scenario may be automated while every other detection still becomes a ticket.Ā 

In Unify Identity and Security Operations to Stop AI Attacks,Ā  we follow that loop from beginning to end, from the decisions that shape an identity’s access before an attack, to the response and learning that follow a detection. We show you why connecting a few tools or sending more identity signals into the SOC is not enough, and why information and action must travel in both directions around the loop.

The ebook also provides a maturity model that examines people, process, and technology together to reveal where the loop breaks. It helps organizations identify whether their biggest obstacle is missing context, manual processes, divided ownership, or technology that can detect risk but can't act on it. We'll show you how to assess that gap and determine the next practical move toward closing it.

Download the ebook.

Meet us at Black Hat 2026, where we will present the IdSecOps approach and launch Cortex ITDR 2.0.


FAQs

What is IdentitySecOps?

IdentitySecOps, or IdSecOops, is the practice of running identity operations and security operations as a continuous loop so identity posture informs detection, detection triggers identity response, and incidents improve future posture.Ā 

How is IdentitySecOps different from DevSecOps?

While DevSecOps integrates security into the software development lifecycle, IdSecOps integrates real-time identity posture and access context directly into active threat detection and response workflows.

Why is a ticketing system no longer sufficient for SOC and identity teams?

Modern, AI-driven cyber attacks can exfiltrate data in minutes. Manual ticketing systems between SOC and Identity teams create an "open loop" delay that allows attackers to succeed before humans can intervene.