Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Defending against AI-fueled social engineering

Social engineering has always been the softest edge of enterprise defense, and AI is sharpening adversaries’ attacks. Phishing, business email compromise, and impersonation still dominate the initial-access playbook, but AI has stripped out the cost, time, and skill barriers that once forced attackers to choose between reach and precision.

Machine vs. machine: The new reality of cybersecurity in ANZ

Frontier AI has handed attackers something they have never had before: the ability to move at machine speed. Attacks that once took days to craft now take minutes. Threats have not just evolved to be automated, adaptive, and operational around the clock. They have also changed category. We surveyed more than 850 IT and cybersecurity professionals across Australia and New Zealand to understand how organisations are keeping up. What the data reveals is not a capability problem. It is a pace problem.

How SLED can win the cybersecurity race with agentic AI

Adversaries are using AI to launch cyber attacks in record time, forcing security teams to measure responses in minutes instead of months. Phishing campaigns built with large language models (LLMs) achieve click-through rates 4.5 times higher than traditional methods,1 and the average time between initial compromise and lateral movement has fallen to just 29 minutes.2 This is a 65% increase from the prior year.2 State and local governments and higher education institutions are at an inflection point.

From 10 Days to Unlimited Retention: How o9 Runs SecOps on Elastic Security

Somesh Agarwal, Senior Director of Security Operations at o9 Solutions, explains how the AI planning platform behind many of the world's largest supply chains consolidated security operations and observability on Elastic Security to gain unlimited threat-hunting retention, accelerate detection engineering, and simplify multicloud security operations.

From tool procurement to platform architecture: Rethinking the SOC for machine-speed threats

The gap between attacker speed and defender readiness is widening. Attackers can now move from initial access to full domain control in less than a minute using AI.1 Large language model-generated phishing campaigns are achieving click-through rates 4.5 times higher than traditional methods.2 Most enterprise SOCs weren't built for this tempo and fidelity.

Put agentic AI to work: Real-world defense against threats

Attackers are using AI to compress timelines from hours to minutes. Most SOCs, and most security platforms, weren’t built for that speed. Join Elastic Security product and research experts for a look at how modern security teams can detect, investigate, and respond faster using agentic AI. You’ll learn how to: You’ll leave better equipped to reduce investigation time, keep analysts focused on decision-making, and modernize security operations for machine-speed threats without removing humans from the loop.

Making Waves: Elastic named a Strong Performer in The Forrester Wave: Extended Detection And Response Platforms, Q2 2026

Elastic has been named a Strong Performer in The Forrester Wave: Extended Detection And Response Platforms, Q2 2026 report. The report recognized our SIEM-replacement capabilities, open data architecture, AI innovation, and endpoint protection. Here's what Forrester found and why we believe it reflects what we've been building.

Monitor Claude activity in Elastic Security

The agentic security operations platform As more people across an organization start using Claude, security and compliance teams end up asking the same questions they ask about any other system: Who’s using it? How are they signing in? Who’s changing the configuration? Claude’s Compliance API answers all of that. It tracks more than 300 event types across Claude Enterprise, Claude Team, and Claude Platform, and every event arrives with the actor, a timestamp, and where it came from.

Compliance work is overdue for a new approach

Compliance has traditionally lived in dashboards, spreadsheets, screenshots, audit packets, and point-in-time reviews. Security teams know the reality is more dynamic. The evidence auditors need is often buried across identity providers, endpoints, cloud platforms, network controls, vulnerability scanners, alerts, and custom application logs — all generating live operational telemetry that static tools struggle to keep up with.