Quorum Cyber Acquires Ontinue to Deploy Autonomous AI‑Driven SOC for Managed Security Clients
What Happened — Quorum Cyber announced the acquisition of Swiss MSSP Ontinue, a Microsoft Gold Partner that built an autonomous investigation system for Security Operations Centers. The combined offering will embed AI‑driven decision‑making into threat detection, investigation, and remediation for customers using Microsoft Defender XDR.
Why It Matters for Trust & Control Assurance
- Autonomous SOC technology forces organizations to formalize policies that dictate when an AI agent may act without human approval – a classic control‑objective scenario for AI governance.
- Continuous, policy‑driven automation generates auditable evidence of threat‑handling activities, supporting a defensible control‑assurance posture.
- The integration highlights the need for a documented framework that maps AI‑related controls to multiple standards (e.g., NIST AI RMF, ISO 42001) in a single evidence set.
Who Is Affected – Managed Security Service Providers, large enterprises adopting Microsoft E5/E7 suites, and any organization relying on AI‑augmented detection and response.
Recommended Actions
- Review and codify AI‑agent decision policies against your organization’s AI governance objectives.
- Incorporate automated SOC logs into your continuous control‑monitoring program to create a defensible audit trail.
- Map the new AI‑related controls to your primary compliance framework (e.g., NIST CSF 2.0) to ensure coverage across standards.
Source: DataBreachToday
Technical Notes
- Ontinue’s platform leverages Microsoft Defender XDR data, applying machine‑learning models to triage alerts and execute predefined response playbooks.
- Customers can configure policy boundaries that limit autonomous actions to specific asset groups or severity levels.
Source: DataBreachToday