---
title: Multi-agent architectures in cybersecurity, the new defense paradigm for enterprises
description: How multi-agent architectures are transforming the SOC, improving automation, and making threat response more effective
image: https://newsroom.kireygroup.com/hubfs/Cybersecurity_13-1.jpg
---

[kireygroup.com](https://www.kireygroup.com/)

[![](https://newsroom.kireygroup.com/hubfs/item-2020-dicembre/logo-Blog-v2.svg)](https://newsroom.kireygroup.com/en/news)

- [Ita](https://newsroom.kireygroup.com/news/architetture-multi-agent-in-cyber-security-il-nuovo-paradigma-di-difesa-per-le-aziende?hsLang=it)
- Eng
- [Esp](https://newsroom.kireygroup.com/es/news/arquitecturas-multi-agente-en-ciberseguridad-el-nuevo-paradigma-de-defensa-para-las-empresas?hsLang=es)

[Kireygroup.com](https://www.kireygroup.com/)

# Get your daily dose of tech!

## We Shape Your Knowledge

# [Legacy modernization in banking: discover the true cost of legacy systems](https://newsroom.kireygroup.com/en/news/legacy-modernization-in-banking-discover-the-true-cost-of-legacy-systems?hsLang=en)

The banking sector is one of the world’s largest investors in digital transformation and innovation,...

[Read more](https://newsroom.kireygroup.com/en/news/legacy-modernization-in-banking-discover-the-true-cost-of-legacy-systems?hsLang=en)

 10 MIN READ

22 September 2026

### Latest News

- [Legacy modernization in banking: discover the true cost of legacy systems](https://newsroom.kireygroup.com/en/news/legacy-modernization-in-banking-discover-the-true-cost-of-legacy-systems?hsLang=en)
- [Context Engineering, the art and science behind AI Agents](https://newsroom.kireygroup.com/en/news/context-engineering-the-art-and-science-behind-ai-agents?hsLang=en)
- [Agentic AI Governance: how to effectively manage AI that can act](https://newsroom.kireygroup.com/en/news/agentic-ai-governance-how-to-effectively-manage-ai-that-can-act?hsLang=en)
- [Autonomous SOC: reality, limitations, and prospects for AI-driven security](https://newsroom.kireygroup.com/en/news/autonomous-soc-reality-limitations-and-prospects-for-ai-driven-security?hsLang=en)
- [Data Virtualization, the pillar of data-driven companies: what it is and how it works](https://newsroom.kireygroup.com/en/news/data-virtualization-the-pillar-of-data-driven-companies-what-it-is-and-how-it-works?hsLang=en)
- [Cloud Economics: the goal is not to spend less, but to spend better](https://newsroom.kireygroup.com/en/news/cloud-economics-the-goal-is-not-to-spend-less-but-to-spend-better?hsLang=en)

- [Cybersecurity](https://newsroom.kireygroup.com/en/news/tag/cybersecurity) /

# Multi-agent architectures in cybersecurity, the new defense paradigm for enterprises

#### Kirey

[![](https://newsroom.kireygroup.com/hubfs/it.svg)](https://newsroom.kireygroup.com/news/architetture-multi-agent-in-cyber-security-il-nuovo-paradigma-di-difesa-per-le-aziende?hsLang=it)    [![](https://newsroom.kireygroup.com/hubfs/ES.svg)](https://newsroom.kireygroup.com/es/news/arquitecturas-multi-agente-en-ciberseguridad-el-nuevo-paradigma-de-defensa-para-las-empresas?hsLang=es)

 21 MIN READ

22 May 2026

- Share on:
- <https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fnewsroom.kireygroup.com%2Fen%2Fnews%2Fmulti-agent-architectures-in-cyber-security-the-new-defense-paradigm-for-enterprises>
- <https://www.twitter.com/share?url=https%3A%2F%2Fnewsroom.kireygroup.com%2Fen%2Fnews%2Fmulti-agent-architectures-in-cyber-security-the-new-defense-paradigm-for-enterprises>
- <http://www.linkedin.com/shareArticle?mini=true&url=https://newsroom.kireygroup.com/en/news/multi-agent-architectures-in-cyber-security-the-new-defense-paradigm-for-enterprises>

- [All](https://newsroom.kireygroup.com/news?hsLang=en)
- Categories + 
    - [Corporate](https://newsroom.kireygroup.com/en/news/tag/corporate)
    - [Cybersecurity](https://newsroom.kireygroup.com/en/news/tag/cybersecurity)
    - [Events/Webinars](https://newsroom.kireygroup.com/en/news/tag/events-webinars)
    - [Cloud](https://newsroom.kireygroup.com/en/news/tag/cloud)
    - [Data Value](https://newsroom.kireygroup.com/en/news/tag/data-value)
    - [Innovation](https://newsroom.kireygroup.com/en/news/tag/innovation)
    - [Artificial Intelligence](https://newsroom.kireygroup.com/en/news/tag/artificial-intelligence)
    - [Monitoring](https://newsroom.kireygroup.com/en/news/tag/monitoring)
    - [DevSecOps](https://newsroom.kireygroup.com/en/news/tag/devsecops)
    - [Software Development](https://newsroom.kireygroup.com/en/news/tag/software-development)
    - [Corporate Social Responsibility](https://newsroom.kireygroup.com/en/news/tag/corporate-social-responsibility)
    - [Data Privacy](https://newsroom.kireygroup.com/en/news/tag/data-privacy)
    - [Advisory](https://newsroom.kireygroup.com/en/news/tag/advisory)
    - [Accessibility](https://newsroom.kireygroup.com/en/news/tag/accessibility)
    - [Automation](https://newsroom.kireygroup.com/en/news/tag/automation)
    - [Digital Banking](https://newsroom.kireygroup.com/en/news/tag/digital-banking)
    - [Digital Industry](https://newsroom.kireygroup.com/en/news/tag/digital-industry)
    - [Use case](https://newsroom.kireygroup.com/en/news/tag/use-case)
    - [Welfare & Social Services](https://newsroom.kireygroup.com/en/news/tag/welfare-social-services)
- [Press & PR](https://newsroom.kireygroup.com/en/news/tag/press)

According to [Gartner](https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025) forecasts, by the end of 2026, 40% of enterprise applications will integrate *task-specific* AI agents, compared to less than 5% in 2025.

In this scenario, one of **the most promising areas is cybersecurity**. Not only because cyber security is by nature a highly operational domain, but also because it perfectly lends itself to a multi-agent logic.

## Multi-agent architectures: the latest frontier of automation 

Multi-agent architectures are the **most mature step** AI has taken so far within enterprise processes. More than a sequence of technologies, this journey can be interpreted as a progressive increase in operational autonomy.

### Automation of individual tasks

In an initial phase, AI was used to improve specific functions, such as pattern recognition and data analysis, without directly intervening in processes.

### Advanced decision support

With the introduction of more advanced models, AI began supporting complex activities such as information interpretation, synthesis, and content generation, assisting operators within workflows.

### Multi-agent operational autonomy

The next step is represented by systems capable not only of supporting, but also of acting. No longer a single central engine, but a network of specialized agents that collaborate, coordinate, and contribute dynamically to process execution.

This latest evolution addresses a **structural limitation of monolithic models.** A single system tends to be difficult to control, test, and govern, especially in complex contexts. In a multi-agent architecture, instead, each system is responsible for a specific function, such as data collection, analysis, enrichment, and decision support, operating within defined boundaries. As a result, the system becomes **more efficient, transparent, and easier to govern,** as well as more scalable over time.

A key characteristic of an [AI Agent](https://newsroom.kireygroup.com/en/news/agentic-ai-in-action-how-to-use-it-and-what-could-be-the-next-killer-application?hsLang=en) is its ability to exchange information and activate sequentially or in parallel according to **orchestrated workflows.** The result is a modular system in which each component can be updated, replaced, or controlled independently, without a potential **single point of fragility.**

## AI agents, the new bet in cybersecurity

Agentic architectures are attracting strong interest in the cybersecurity world because they address a structural tension: on one side, the continuous increase in threats, attack surfaces, and the complexity of IT environments; on the other, the difficulty for security teams to manage growing **volumes of alerts and operational activities with limited resources.**

### The limits of the traditional approach

The operational model of Security Operations Centers (SOC) is based on a combination of advanced tools (SIEM, EDR…), well-defined processes, and **multiple activities directly assigned to analysts,** including event correlation, context enrichment, and validation of alerts generated by threat prevention platforms.

Automation exists and relies on rules, operational playbooks, and dedicated tools such as SOAR platforms, but it is **largely deterministic and limited to known scenarios.** Automating remediation or mitigation actions requires a very high level of trust, which is generally not yet assigned to machines except in typical and obvious cases. Consequently, a significant part of operations and decision-making remains in the hands of analysts, **especially in ambiguous or high-impact situations.**

When volume and complexity increase, **this generates bottlenecks** and highlights scalability limitations: the system holds up as long as the team grows, but struggles to sustain increasingly rapid dynamics and threats that, [leveraging the same AI,](https://newsroom.kireygroup.com/en/news/ai-agents-on-the-offensive-the-new-face-of-cyber-threats-and-how-to-defend-against-them?hsLang=en) become more frequent, numerous, and sophisticated.

### Multi-agent architectures: making security sustainable without losing control

Multi-agent architectures offer an approach closer to the real nature of security operations, which are **by definition iterative and multi-step.** Dividing work among specialized agents enables more efficient management of activities such as **data collection, correlation, analysis, and response, reducing operational bottlenecks.**

For companies, the key point is that **agentic architectures are not designed to improve threat detection,** an area where mature and highly effective tools have existed for a long time. Their value instead lies in **making the entire security operating model sustainable.**

Multi-agent architectures make it possible to increase decision speed, automate repetitive activities, and **free up human expertise**, allowing it to focus on the most complex cases.

## How a multi-agent system works: a 4-step workflow

The core element of a multi-agent system is the workflow, namely the **dynamic operational flow that can be adapted based on what emerges throughout the process**. It is therefore a flow that evolves in real time under the control of a supervisor, activating different agents depending on the situation. Each organization can **model this workflow according to its own needs**, but some key steps can be identified.

1. The process starts with a security event such as **an alert generated by an endpoint or a cloud environment**. This is a decisive phase, but also one of the most critical: according to analysts, the main inefficiencies are concentrated here, due to the high volume of alerts and the difficulty of quickly distinguishing what is relevant from what is not. In this phase, the system can make and **execute decisions, but only in the most obvious cases.** The objective is to transform a chaotic flow of signals into a manageable set of relevant events.
2. Orchestration then comes into play as the **coordination point of the system**: it analyzes the nature of the event and activates, case by case, the most suitable agents. If the issue concerns an endpoint, for example, **the sequence of activities on the device is reconstructed;** if instead it involves the network, traffic, connections, and possible anomalous external communications are analyzed. The difference compared to traditional flows is that these checks can occur in parallel, reducing analysis times and aligning them with the needs of modern cybersecurity.
3. The results then converge into a **synthesis and planning phase,** where the platform builds a view of the incident: what happened, how it developed, what the possible cause may be, and what actions are available. **At this point, the system may assign a risk score and a reliability level,** which are key elements in deciding the system’s degree of autonomy.
4. **The response is therefore managed differently** depending on the case. Low-impact actions can be executed automatically, while more critical actions always require a *human-in-the-loop* step to ensure control and proper accountability.

## The role of the analyst in agentic security

As in many business domains, multi-agent architectures are not intended to bypass analysts or, more generally, SOC professionals, but **they inevitably end up transforming their work** and redefining their contribution within the operating model.

After all, cybersecurity is a suitable domain for relieving professionals from repetitive activities, since a significant part of their time is absorbed by alert triage, data collection and correlation, and **report compilation.** With agentic automation, these activities can be handled by the system, freeing up the cognitive resources needed to address more sophisticated threats.

This change translates into assigning professionals at least four responsibilities:

1. ### **Validation of decisions** The first, already mentioned, is undoubtedly decision validation: the system autonomously decides only the obvious cases and relies on well-defined rules. In the vast majority of cases, the system performs risk scoring and provides justified recommendations, engaging the analyst to confirm or reject the proposed actions. As mentioned, the human-in-the-loop approach remains essential to ensure control and accountability.
2. ### **Management of complex cases** When the system detects ambiguities or potentially high impacts, the case is immediately escalated to the analyst. In this context, the analyst’s role is not only interpretative, but also supervisory: validating hypotheses, deciding which additional investigations to activate, and directing the agents’ work by requesting further analysis or limiting their scope. In practice, the analyst takes ownership of the case*end-to-end*, leveraging agents as operational assistants to accelerate checks and build a solid assessment.
3. ### **Configuration and continuous improvement** The third area is more strategic: system configuration and continuous improvement. Analysts contribute to defining playbooks and escalation criteria. In other words, they do not simply use the system, but actively participate in its evolution.
4. ### **Training and tuning of agents** The analyst contributes to improving the system through operational feedback, error correction, and response optimization. Their role becomes similar to that of a trainer, helping agents progressively become more effective.

This shift also impacts the required skills, as the analyst increasingly becomes a figure oriented toward security governance rather than operational execution. They must be able **to interpret complex contexts, rapidly assess risk, and make informed decisions based on (even) partial evidence.**

## Kirey: innovation and expertise to address sophisticated threats

At Kirey, we help companies build [a **solid and sustainable security model**](https://www.kireygroup.com/en/competencies/cybersecurity)**.** Our approach is not based solely on the provision of **tools, specialized expertise, and managed services,** but also on a **strong orientation toward innovation,** a key element in keeping pace with increasingly advanced attacker strategies.

We operate on the frontier of innovation also in the cyber domain, a frontier that today increasingly coincides with **automation and advanced models such as multi-agent architectures.** Despite this trend, in our vision, the journey is governed, controlled, and made reliable through the experience and specialized expertise of our professionals.

[Contact us](https://www.kireygroup.com/en/contact) to discover how we can support your organization in building a security model capable of addressing today’s and tomorrow’s challenges.

- [Previous post](https://newsroom.kireygroup.com/en/news/the-knowledge-architecture-the-infrastructure-enabling-effective-and-reliable-ai-agents?hsLang=en)
- [Read all posts](https://newsroom.kireygroup.com/en/news?hsLang=en)
- [Next post](https://newsroom.kireygroup.com/en/news/cloud-pa-strategies-challenges-opportunities-for-cloud-transformation-in-the-public-sector?hsLang=en)

## Related posts:

#### [Autonomous SOC: reality, limitations, and prospect...](https://newsroom.kireygroup.com/en/news/autonomous-soc-reality-limitations-and-prospects-for-ai-driven-security?hsLang=en)

Artificial intelligence is certainly not new to the world of cybersecurity. For more than a decade, ...

[Read more](https://newsroom.kireygroup.com/en/news/autonomous-soc-reality-limitations-and-prospects-for-ai-driven-security?hsLang=en)

 11 MIN READ

22 May 2026

#### [Cybersecurity awareness must change form: human de...](https://newsroom.kireygroup.com/en/news/cybersecurity-awareness-must-change-form-human-decision-quality-at-the-center?hsLang=en)

By Roberto Marzocca, Head of Cybersecurity di Kirey For a long time, the cybersecurity sector has ar...

[Read more](https://newsroom.kireygroup.com/en/news/cybersecurity-awareness-must-change-form-human-decision-quality-at-the-center?hsLang=en)

 6 MIN READ

22 May 2026

#### [SASE, the model that connects and protects modern ...](https://newsroom.kireygroup.com/en/news/sase-the-model-that-connects-and-protects-modern-it-infrastructures?hsLang=en)

Modern companies must ensure high-performing, always-on connectivity for people and digital assets, ...

[Read more](https://newsroom.kireygroup.com/en/news/sase-the-model-that-connects-and-protects-modern-it-infrastructures?hsLang=en)

 18 MIN READ

22 May 2026

#### Explore

- [Home](https://www.kireygroup.com/)
- [Competencies](https://www.kireygroup.com/en/competencies)
- [Industries](https://www.kireygroup.com/en/industries)
- [About Us](https://www.kireygroup.com/en/about-us)
- [Tech&Partners](https://www.kireygroup.com/en/tech-partners)
- [Careers](https://www.kireygroup.com/en/careers)
- [Contact](https://www.kireygroup.com/en/contact)
- [Corporate Social Responsibility](https://www.kireygroup.com/en/corporate-social-responsibility)
- [Advisory](https://www.kireyadvisory.com/en)

#### Policy

- [Quality](https://www.kireygroup.com/oven/media/PKG-COMP-AL14-Quality-Policy.pdf)
- [Security](https://www.kireygroup.com/oven/media/PKG-CIS-LG02-Security-Policy.pdf)
- [Gender Equality](https://www.kireygroup.com/oven/media/PKG-COMP-LG03-Politica-per-la-parita-di-Genere-v2.pdf)
- [Service Management](https://www.kireygroup.com/oven/media/PKG-COMP-AL45-Politica-per-la-gestione-dei-servizi.pdf)
- [Environment](https://www.kireygroup.com/oven/media/PKG-COMP-AL44-Politica-Ambientale-Kirey.pdf)
- [Health, Safety & Wellbeing](https://www.kireygroup.com/oven/media/PKG-COMP-LG02-Policy-on-health-safety-and-well-being-in-the-work-environment.pdf)
- [ESG](https://www.kireygroup.com/oven/media/Policy-ESG-ENG-v1.pdf)
- [Info on Data Processing](https://www.kireygroup.com/en/information-on-data-processing)

#### Certifications

- [ISO 9001:2015](https://www.kireygroup.com/oven/media/KIREY-S-R-L-9001.pdf)
- [ISO/IEC 27001:2022](https://www.kireygroup.com/oven/media/KIREY-S-R-L-27001.pdf)
- [PDR 125](https://www.kireygroup.com/oven/media/PDR-125-2022.pdf)  
  <https://www.kireygroup.com/oven/media/PKG-COMP-AL45-Politica-per-la-gestione-dei-servizi.pdf>
- [ISO/IEC 20000-1:2018](https://www.kireygroup.com/oven/media/ISOIEC-20000-12018-ENG.pdf)
- [ISO 14001:2015](https://www.kireygroup.com/oven/media/ISO-14001-2015-ENG.pdf)
- [ISO 45001:2018](https://www.kireygroup.com/oven/media/CERTIFICATO-ISO-45001-KIREY-ENG.pdf)
- [ISO 22301:2019](https://www.kireygroup.com/oven/media/ISO-22301-2019-ENG.pdf)

#### Info

**Kirey Srl**

[info@kireygroup.com](mailto:info@kireygroup.com)  
Viale Francesco Restelli, 5  
20124 Milano

[kirey@pec.it](mailto:kirey@pec.it)  
**PI/CF**: 06729880960  
**REA**: MI 1910802  
**Tel**: +39 02 78625200

Capitale sociale 1.089.620,00 

[![Linkedin](https://newsroom.kireygroup.com/hs-fs/hubfs/Linkedin.png?width=20&name=Linkedin.png)](https://www.linkedin.com/company/kireygroup/)<https://open.spotify.com/show/41V5g7d4zccIrVcmNB3ZWd>   <https://www.instagram.com/kireygroup/?igshid=MzRlODBiNWFlZA%3D%3D>

- [Privacy Policy](https://www.kireygroup.com/oven/media/Kirey-Privacy-ENG-policy-art-13.pdf)
- [Cookie Policy](https://www.kireygroup.com/oven/media/Kirey-Cookie-Policy-ENG-1.pdf)
- [Terms and Conditions](https://www.kireygroup.com/oven/media/Kirey-Website-Terms-and-Conditions-1.pdf)

[![KIREY LOGO](https://newsroom.kireygroup.com/hs-fs/hubfs/KIREY_LOGO_PAYOFF_RGB_POS.png?width=200&height=72&name=KIREY_LOGO_PAYOFF_RGB_POS.png)](https://www.kireygroup.com/)

© Copyright 2026 by Kirey 