Cyberattacks operating at machine speed can overwhelm defenders working at human speed. By the time a security engineer completes an hourlong investigation, an attacker may already have moved deeper into the organization.
Lenovo deployed an AI-powered security operations center (SOC) across its internal infrastructure, which spans more than 140,000 devices. According to the company, the multimonth implementation reduced mean time to detect threats by 87.5% and produced a 20-fold improvement in threat-detection accuracy.
The deployment is part of Lenovo Powers Lenovo, an internal program launched in May 2024 to test the company’s technology within its own operations before offering it to customers.
Thirumalai Seshadri Krishnakumar, director of advanced service delivery at Lenovo, said: “If AI is essential to keeping pace with the threat landscape, then customers rightly expect us to use our own AI capabilities to protect Lenovo before we ask them to trust us with their own enterprise.”
How Lenovo changed its SOC operations
A traditional SOC relies on cybersecurity professionals to monitor, detect, investigate and respond to threats across an organization. Lenovo added AI agents to parts of that workflow.
The company says that it gradually incorporated AI-supported workflows by creating “playbooks” that AI could follow. For example, Lenovo created alert-specific playbooks that allowed AI agents to triage incoming alerts using predefined procedures. Rather than replacing standard operating procedures, the system automated parts of those established workflows.
Although AI agents participated in threat detection and handled most lower-level incidents, Lenovo said human analysts retained responsibility for critical threats.
AI systems can still misclassify legitimate activity or overlook malicious behavior. Lenovo reported a false-positive rate below 10%, but organizations should also examine false negatives, detection coverage and the controls governing automated responses.
More must-read AI coverage
- SS&C Intralinks DealCentre AI vs. Datasite: Which platform is built for the future of dealmaking?
- SS&C Intralinks FundCentre AI vs. Juniper Square: Which platform better supports modern private markets fund managers?
- Why Data, Not Models, Determines AI Success
- The Rise of the AI-Native Factory: How Physical AI Is Transforming Manufacturing
What this means for enterprises
Lenovo tested the agentic SOC in its own production environment. Its results offer other enterprises a case study, although performance may vary depending on infrastructure, data quality and the extent of automation.
By integrating AI workflows, security teams can focus on critical incidents instead of chasing every alert, although recent discussions about AI agents in the SOC emphasize the continued need for governance and human oversight. Automating routine triage could give security analysts more time to investigate high-risk incidents and maintain the quality of their work.
“AI allows us to apply our expertise where it matters most. By automating routine work and continuously learning from new patterns, the SOC can deliver more consistent protection today and strengthen our defenses as new threats emerge,” said Pradip Dabir, senior manager of services delivery engineering at Lenovo.
Lenovo’s results suggest that AI-assisted triage can shorten detection times and reduce repetitive work, but enterprises should treat the figures as a starting point rather than a guaranteed outcome. Security leaders should test agents against their own alert data, measure false positives and false negatives, and decide which actions must continue to require human approval.
Read more: Learn how agentic AI is changing work and where businesses are combining automated workflows with human oversight.