The 2027 Security Operating Model: Lean. Agentic. Owned.
A webinar hosted by Elastic & UnderDefense on how AI visibility and agentic response connect into one operating model, and what it takes to run it with a small security team today.
Who you'll hear from
Andrew Hural
VP of ProductsVP of Products at UnderDefense.
Former Director of Security Operations at McDonald’s.
Josh King
Senior Security Solution Architect18+ years in threat detection, security analytics, and enterprise defense.
Former IT Specialist, US Army.
Anthony Rossini
Security Specialist Sales Executive4 years across MSSP, MDR, and end-customer security use cases on the Elastic platform.
Most companies have an AI policy on paper. Almost none enforce it at the data level. This session shows what it looks like when you do.
Employees are already using ChatGPT, Copilot, Claude, and other AI tools with or without security team visibility. But AI tools are no longer passive assistants. They can read files, call tools, execute commands, connect to business systems, and act on behalf of users. If an attacker abuses an AI-enabled workflow, manipulates an agent through prompt injection, or takes advantage of over-permissioned connectors, AI is the path to unauthorized access, data exposure, or destructive actions.
Elastic and its partner UnderDefense built a complete operating model around this problem. Elastic indexes every AI interaction as a structured, searchable security event. UnderDefense Agentic AI SOC converts alerts into structured incident reports, with a hypothesis, chain of evidence, and recommended actions — ready for the CISO, auditor, or insurer. The full cycle, from detection to closed investigation, is already running in production.
What we'll cover
The shadow AI risk vector
AI tools can be manipulated through prompt injection, model abuse, or over-permissioned connectors, leading to data loss, compliance exposure, or unauthorized access.
Elastic + Anthropic Claude Compliance API
What gets captured: who, when, which device, which model, which policy violation. We'll talk about how prebuilt detection rules for AI-specific patterns ship with the integration, and how any AI provider feeds into the same pipeline.
What happens after the alert fires
How UnderDefense Agentic AI SOC enriches alerts with identity and threat context, runs parallel investigation, and produces a report ready for the CISO, auditor, or insurer within a defined SLA.
Three strategies for 2026–2027
An AI usage audit, AI-specific detection rules, and a response playbook — with a concrete sequence your team can act on before end of Q3.
What you'll walk away with
A live example from a real production incident — detection by Elastic, triage and closure by UnderDefense Agentic AI SOC, with actual timestamps.
A technical walkthrough of the Elastic + Anthropic Claude Compliance API: what it captures, what ships prebuilt, and how it connects to your existing SIEM pipeline.
A clear map of where shadow AI creates security exposure that standard SIEM rules were never designed to catch.
Three concrete steps your team can prioritize before Q4 to close the gap between AI visibility and AI response.
Built for teams where AI is already in the building.
CISOs, Heads of Security Operations, and security leads at enterprises where employees are already using AI tools — whether approved, shadow, or both.
If your organization has deployed Microsoft Copilot, GitHub Copilot, or any SaaS product with an embedded LLM, and your team doesn't have a defined SLA for AI-related security alerts, this session is built for you.
Elastic provides the data layer — indexing every AI interaction as a structured, searchable security event. UnderDefense provides the response layer — turning alerts into closed investigations. This session shows what a complete operating model looks like when both are running in production.
every AI event
closes the loop
in production
See what a complete operating model looks like.
Elastic provides the data layer, UnderDefense provides the response layer.