← Back to Resources

AI in the MSSP SOC: From Pilots to Production

Ken Westin, Solutions Engineer at LimaCharlie

Every MSSP is under pressure to adopt AI, and most of the advice available is either vendor hype or generic guidance written for enterprise teams with one environment to manage. MSSPs face a harder problem: any AI they adopt has to work across dozens or hundreds of client stacks, respect tenant boundaries, and produce results an analyst can defend to a customer.

On September 16, 2026, Sr. Solutions Engineer Ken Westin joined us to lay out a practical roadmap for moving AI in the MSSP SOC past the pilot stage and into production. He walked through where AI earned its keep first, what had to be true of your telemetry before any of it worked, and how AI wired into your infrastructure differs from the advisory tools most vendors ship.

What the session covered:

  • Where AI delivered value first: triage, detection engineering, and investigation
  • What telemetry had to look like before AI could help: structured, centralized, and consistent across client environments
  • How infrastructure-level AI differed from AI SOC advisory tools: agents that execute with full API access instead of recommending on top of read-only integrations
  • How humans stayed in control through approval workflows and full audit trails, so every AI action is transparent, reviewable, and taken only when you decide

See what agentic SecOps looks like in your environment

LimaCharlie gives MSSPs and MDRs a fully programmable SecOps Cloud Platform, with transparent usage-based pricing, API-first integration across every telemetry source, and the infrastructure to run multi-tenant operations at scale.