Attackers are automating. Alert volumes are exploding. And most security teams are still making high-stakes decisions about which threats to investigate before they’ve had a chance to investigate anything at all. It’s a dangerous paradox at the heart of modern security operations — and one that Itai Tevet, co-founder and CEO of Intezer, argues the industry can no longer afford to ignore. Ahead of RSA Conference 2026, Tevet spoke with VMblog about the structural limitations of today’s SOC and MDR models and why the fix isn’t more analysts — it’s autonomous investigation at forensic scale.
Intezer’s AI SOC platform is built on a deceptively simple premise: every alert deserves a full investigation, not just the ones that make it to the top of an overburdened analyst’s queue. By combining AI reasoning with deterministic, forensic-grade analysis, the platform delivers transparent, auditable verdicts across 100% of alerts — and brings humans in only for the less than 2% that require genuine judgment or response. At RSAC 2026, visitors to Booth S-555 can see the platform in action, and with new capabilities previewing a post-MDR operating model on the show floor, this is shaping up to be one of the more substantive product stories of the conference.
++
VMblog: Give VMblog readers a quick overview of your company and its core mission.
Itai Tevet: Intezer is the AI SOC platform that investigates every alert at forensic depth, allowing organizations to scale security operations beyond human capacity while keeping their own teams in control. Across endpoint, identity, cloud, network, phishing, and SIEM data, Intezer investigates 100% of alerts and escalates only the incidents that require human judgment (less than 2%), while continuously improving detection coverage with every investigation verdict.
VMblog: Where can attendees find you at RSA 2026? What’s your booth number, and what kind of experience can visitors expect when they stop by?
Tevet: You can find Intezer at RSAC 2026, Booth S-555, where we’ll be demonstrating our AI SOC approach. Attendees can see what it’s like to have autonomous 24/7 triage and investigation across their alert sources, with evidence-backed verdicts and escalation to humans only when action or judgment is needed.
VMblog: What should RSA Conference attendees look forward to from Intezer this year, both on the show floor and beyond?
Tevet: RSA attendees who visit our booth can step back in time to try their skills at retro arcade games. Participants have the opportunity to take home an APTeddy. Also, join us for Social Hour from 5–7 pm on Monday, March 23, at Yerba Buena Bar. Visit https://intezer.com/rsac-event/ to learn more about our RSA activities or request an invitation to our exclusive dinner with Cyber Security Tribe at 6:30 PM PT on Tuesday, March 24, at the historic John’s Grill. Enjoy an evening of great food and relaxed, peer-level conversation away from the conference noise.
VMblog: What were your key learnings from 2025’s security landscape, and how have those insights shaped your solutions for 2026?
Tevet: One of the clearest lessons from our 2026 AI SOC report, which analyzed 25 million alerts across enterprise environments, is that the traditional human-scaled SOC and MDR model breaks as alert volume grows. Our data showed that real threats often originate in alerts labeled low or medium severity, typically alerts that many teams never investigate due to limited capacity.
This creates a structural risk: decisions about which alerts matter are made before full context and investigation are available.
For 2026, Intezer’s approach is to remove investigation capacity as the constraint. The AI SOC investigates 100% of alerts with consistent, forensic-grade analysis, surfacing the real incidents hiding in the noise and escalating only those that require human judgment.
VMblog: How is your company addressing the intersection of generative AI and cybersecurity – both defending against AI-powered attacks and leveraging AI agents for security operations?
Tevet: Attackers are moving faster and scaling tactics with automation, which makes comprehensive investigation (not just alert filtering) essential. Intezer addresses this by using AI agents to run continuous triage and investigation across endpoint, identity, cloud, network, and SIEM alerts—so every signal gets reviewed, correlated, and validated with evidence. Intezer’s platform uniquely integrates forensic-grade, deterministic investigation methods alongside AI reasoning, with transparent and auditable verdicts, so teams can trust outcomes at scale.
VMblog: Can you share any exclusive previews or announcements that attendees can expect to see at your booth this year?
Tevet: Intezer will be introducing new capabilities that replace and improve on the MDR operating model, showing how autonomous investigation can cover 100% of alerts.
VMblog: What sets your solution apart in today’s crowded cybersecurity marketplace? Why should RSA attendees prioritize visiting your booth?
Tevet: Intezer is built around forensic-grade investigation at scale. The platform consistently investigates every alert with evidence-based verdicts, then brings humans in only where judgment and response are required. For teams hampered by traditional MDR constraints, the differentiator is outcomes, including full alert coverage, forensic depth, and a feedback loop that continuously improves detection quality based on what investigations actually find.
VMblog: With ransomware groups increasingly using AI and targeting cloud infrastructure, how does your solution help organizations better prepare, detect, and respond?
Tevet: Intezer’s AI SOC investigates alerts across cloud, identity, endpoint, network, and SIEM data, so teams aren’t forced to ignore large portions of alert volume due to capacity constraints. That matters when real threats can begin as lower-severity signals and only become “obvious” after correlation and investigation. Intezer’s operating model is designed to escalate only the true incidents to people, and it can trigger an automated response for routine alerts according to policy while keeping humans in the loop for high-impact decisions.
VMblog: How does your solution help organizations address the expanding regulatory landscape, including AI governance requirements and emerging global privacy regulations?
Tevet: A practical requirement across regulations is being able to explain and defend security decisions. Intezer’s model emphasizes clear, evidence-based verdicts designed to be transparent and auditable, rather than a black-box escalation with limited investigative context.
Intezer also builds a continuous feedback loop so investigation learnings can be used to maintain and improve detections over time, helping organizations demonstrate ongoing control improvements rather than one-time tuning.
VMblog: What’s your perspective on the most critical cybersecurity trends that will shape the industry in 2026–2027?
Tevet: Two trends will dominate: (1) continued alert growth and expanding attack surfaces, and (2) attacker automation accelerating the speed and scale of intrusions. That combination makes “human capacity” the limiting factor in many SOCs and MDRs, leading to backlogs and risk.
The operating model that successfully scales is autonomous investigation with humans supervising outcomes, so every alert is reviewed and triaged, and teams spend their time on true incidents and strategic decisions rather than ticket volume.
##





