Tektronix TIF 2026
This page was machine-translated and may differ from the original. View original

Pago Networks presents AI-based security operations blueprint…"Better decision-making over more detections"

Google 우선 소스Published2026.09.01 16:24


DeepACT Platform Unveiled, Integrated Strategy for Defense, Attack, and Detection Engineering

Final Decision-Making is Human Domain, Presenting 'Human + AI' Based Operating Model


As AI simultaneously transforms both attack and defense methods in cybersecurity, Pago Networks has presented a new blueprint for AI-based Security Operations. The company has declared a shift away from traditional MDR (Managed Detection & Response) that focused simply on discovering more threats, moving toward a SOC (Security Operations Center) operating system centered on fast, accurate judgment and response.


Pago Networks held an event on the 1st at the Grand Intercontinental Seoul Parnas in Samseong-dong under the theme 'SOC as a Service - The Future of Security Operations Expanding on MDR,' unveiling AI-era security operations strategy and a next-generation service platform to implement it.


CEO Kwon Young-mok, who made the presentation that day, diagnosed that the goal of security operations itself has changed due to AI proliferation.


CEO Kwon Young-mok stated, "It is no longer about how many threats we detect, but how quickly we can detect and accurately judge and respond to them," and emphasized that "AI will not replace analysts but will serve to augment security operations capabilities."


Indeed, AI is being rapidly applied across all security areas including EDR, NDR, threat intelligence, and SOC platforms.


Pago Networks explained that it aims for a structure where AI performs repetitive and large-scale data analysis work, while security analysts focus on threat context analysis, response prioritization, and final decision-making.


To this end, Pago Networks officially unveiled the AI-based security operations platform 'DeepACT.'


The platform consists of three core services: 'PAGO DeepACT DEFENSE' centered on defense, 'PAGO DeepACT ATTACK' from an attacker's perspective, and 'PAGO DeepACT Detection-Engineering' responsible for threat hunting and detection enhancement.


First, DeepACT DEFENSE is a blue team-focused service that extends traditional MDR services to the next level.


It provides 24/7/365 threat detection and response by leveraging various security solutions such as EDR, NDR, and XDR in an integrated manner.


In particular, it advocates a proactive security operations model that goes beyond simply reporting detection results to customers, performing threat blocking, isolation, and response prioritization.


CEO Kwon Young-mok stated, "Many MDR services stop at discovering threats and telling customers how to address them, but in reality, customers often lack the capability to execute immediately," and said, "After witnessing countless cases leading to ransomware infections, we concluded that we must now perform actual blocking and isolation rather than just providing information."


DeepACT ATTACK is a red team service from an attacker's perspective.


It provides integrated ASM (Attack Surface Management), AEV, AI red teaming, and dark web intelligence.


Using AI-based automation technology, it performs everything from vulnerability identification to actual penetration validation, with the goal of converting traditional penetration testing conducted 1-4 times per year into a continuous operations system.


In particular, rather than simply listing vulnerabilities, it validates whether actual attacks are possible and provides specific attack paths and configuration errors if infiltration is possible, offering substantive improvement grounds.


Pago Networks is currently operating the service for infrastructure environments and announced its official launch that day.


Detection-Engineering, the third pillar, is the core module of the DeepACT platform.


It combines Google Threat Intelligence (GTI), global threat intelligence, and frontier AI technology to automate threat hunting and detection engineering processes.


According to Pago Networks, when new threat information (IoC) is secured, AI analyzes it and automatically generates and updates sigma rules applicable to various security solutions.


By automating rule creation work that was previously performed manually by security analysts, response time to new threats can be significantly reduced.


CEO Kwon Young-mok stated, "The threat hunting work that previously took several hours is now shortened to a matter of minutes, and malware analysis time is also significantly reduced," and explained, "We converted from the method of people directly creating rules to an AI-based automation system."


Pago Networks drew a line that while AI will ultimately advance toward fully autonomous SOC, final decision-making remains a human domain for now.


The explanation is that while AI can detect and analyze threats, judgment considering a specific organization's business environment and business context remains the role of experts.


Accordingly, the company presented a 'Human + AI' based operating model.


AI is tasked with data analysis and automation, while security experts determine the meaning and impact of threats and response prioritization.


CEO Kwon Young-mok stated, "We view AI not as a technology but as a virtual analyst to work with," and revealed, "The future of security operations lies not in more detections but in faster and more accurate decision-making, and DeepACT is the result of reestablishing 9.5 years of accumulated MDR operations experience to fit the AI era."

To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.
배종인 기자
배종인 Reporter