IBM Boosts Security Analyst Efficiency with Generative AI Assistant

IBM Boosts Security Analyst Efficiency with Generative AI Assistant

The News: IBM adds generative AI capabilities to its managed Threat Detection and Response Services, in order to help IBM Consulting analysts accelerate and improve their ability to identify, investigate, and respond to critical security threats for clients.

See the press release on IBM’s website for more details.

IBM Boosts Security Analyst Efficiency with Generative AI Assistant

Analyst Take: Security teams face the challenge of keeping pace with evolving and ever-more sophisticated threat vectors. Attackers have always been innovative, and now they have access to AI to help craft increasingly difficult-to-detect, multi-layered attacks. At the same time, the potential threat landscape is more vast and diverse than before. Simply put, the Security Operations Center (SOC) faces unprecedented pressures and challenges, rendering the ability to enhance the efficiency and effectiveness of threat detection and response (TDR) services a critical necessity.

In fact, The Futurum Group’s Cybersecurity Decision Maker IQ data indicates that for Security Information and Event Management (SIEM) decision makers considering switching vendors, the main motivation is the need to meet evolving security needs (e.g., increased data volume, new cloud and mobile data sources, keeping pace with the latest threats). We also found that Extended Detection and Response (XDR) decision makers considering new vendors are most interested in expanding threat detection capabilities, for example, adding advanced threat hunting.

For its part, IBM has built the new IBM Consulting Cybersecurity Assistant Built on its watsonx data and AI platform, introducing generative AI capabilities to its managed TDR offering. The new offering will automate tasks, provide real-time insights, and streamline security operations for analysts.

The AI will automatically enrich threat intelligence data, providing a richer context for better decision-making. At the same time, the automation will boost efficiency and speed time to detection and response. This will serve to reduce “noise” and false positives within the TDR workflow. The assistant’s ability to explain commands is particularly valuable, as it fosters deeper understanding among analysts and promotes collaboration between humans and AI. This is all notable because, traditionally, TDR teams are bogged down by a deluge of alerts, requiring manual investigation to identify and prioritize real threats. This time-consuming process can leave critical vulnerabilities exposed.

Specifically, IBM’s new AI assistant automates:

  • Ticket Management, including responding to routine requests such as opening or summarizing tickets, freeing analysts to focus on complex issues.
  • Data Retrieval, including executing queries, pulling logs, and explaining commands, reducing the time analysts spend gathering information.

This announcement highlights a growing trend within the cybersecurity industry: the strategic integration of AI to help speed up complex threat investigations via historical correlation analysis of similar threats. Analyzing patterns of historical, client-specific threat activity equips security analysts to be more proactive and precise – empowering, rather than replacing, them.

Specifically, IBM’s new tool, built into IBM’s TDR Services, cross-correlates data from SIEM, network, EDR, vulnerability, and telemetry for comprehensive visibility. It built in collaboration with, and as a result taps the expertise in generative AI of, the IBM Research team.

It is relevant that IBM is in the process of selling its QRadar SIEM platform to Palo Alto Networks, in a deal that is slated to close later in 2024. As a part of the deal, IBM’s consulting practice is going to be trained on Palo Alto Networks’ modern Cortex Extended Security Intelligence and Automation (XSIAM) platform. The Futurum Group anticipates that, especially as IBM moves away from offering its own SIEM product, it will increase support for third-party SOC tools, opening up new opportunities for its security consulting team and enhancing potential value for clients. What remains to be seen is the impact of the slated move of the IBM Security X-Force Threat Intelligence team to Palo Alto Networks as a part of the deal.

Disclosure: The Futurum Group is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of The Futurum Group as a whole.

Other Insights from The Futurum Group:

Krista Gets Married and Outages, Outages and more Outages – Infrastructure Matters, Episode 49

Palo Alto Networks Acquires IBM QRadar, Enhancing AI Security

IBM Reports Q2 2024 Financial Results: Key Insights and Performance Review

IBM Q2FY24 Earnings

Author Information

Krista Case

Krista Case brings over 15 years of experience providing research and advisory services and creating thought leadership content. Her vantage point spans technology and vendor portfolio developments; customer buying behavior trends; and vendor ecosystems, go-to-market positioning, and business models. Her work has appeared in major publications including eWeek, TechTarget and The Register.

Related Insights
OpenAI’s GPT-6 Astra: Benchmarks, Cyber Risks, and Market Impact
September 4, 2026

OpenAI’s GPT-6 Astra: Benchmarks, Cyber Risks, and Market Impact

Nick Patience, VP and Practice Lead, AI Platforms at Futurum, shares his insights on GPT-6 Astra and what its cyber threshold and monitorability trade-offs mean for Anthropic and Google....
OPSWAT 5.15.0: Closing the Timeout Gap in Enterprise File Inspection
September 4, 2026

OPSWAT 5.15.0: Closing the Timeout Gap in Enterprise File Inspection

OPSWAT's MetaDefender ICAP Server v5.15.0 introduces Smart Scan Timeout, a 30-day workload heat map, and mTLS support to address enterprise security teams' top blockers in scaling perimeter file inspection....
Thales-KSSL Rocket Deal: A Sovereign-Security Signal for Cyber Buyers
September 4, 2026

Thales-KSSL Rocket Deal: A Sovereign-Security Signal for Cyber Buyers

Thales and Kalyani Strategic Systems Limited's September 2026 alliance signals durable sovereign-security commitment to government and defence buyers, combining indigenous 70-mm rocket production with cyber-physical threat convergence capabilities....
Kaseya Bets on Compliance to Unlock Regulated-Industry MSP Deals
September 3, 2026

Kaseya Bets on Compliance to Unlock Regulated-Industry MSP Deals

Kaseya's Connect Edge summit unveiled FIPS 140-3 validated cryptography and native Apple MDM for Datto RMM, enabling MSPs to capture government, healthcare, and defense contracts previously locked behind compliance barriers....
PA Consulting Bets on Sovereign AI as Regulated Sectors Demand More
September 3, 2026

PA Consulting Bets on Sovereign AI as Regulated Sectors Demand More

PA Consulting has joined a Cosine-led coalition to co-design Lumen Sovereign, the UK's first fully sovereign frontier AI model targeting highly regulated sectors where data residency and governance are critical...
PagerDuty's Scoped OAuth: The Trust Layer Agentic Ops Requires
September 2, 2026

PagerDuty’s Scoped OAuth: The Trust Layer Agentic Ops Requires

PagerDuty's Scoped OAuth for Public Apps enforces least-privilege access control, giving admins visibility over third-party integrations—essential security for autonomous operations and AI agents at scale....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.