Research & Development · Cybersecurity · AI · Resilience
Securing the next generation of digital operations
The next era of digital security is no longer only about defending the systems we run today.
Autonomous AI agents, continuous security monitoring, automated incident handling and simulation environments in which an organisation's cyber defence can be tested before a real attack are all entering enterprise operations at once.
Regcytech Labs studies where those technologies meet business, technology, security and regulation.
Current focus
- Security Operations Center
- Cyber Range
- Agent-Driven Web
StatusResearch and concept-development directions. The approaches presented on this page are not currently standalone, commercial Regcytech services.
01 — The Future of SOC
The security operations centre, from alert handling to autonomous defence
A Security Operations Center has traditionally been the operational centre of an organisation's digital defence: monitoring and analysing security events, recognising incidents and coordinating the response.
That model is changing quickly. A modern SOC is less and less a team of analysts in front of a SIEM — the next generation brings threat intelligence, EDR/XDR, SOAR, identity security, cloud security, vulnerability management and AI-based analysis together at once.
Our research question
What could a next-generation SOC look like where human analysts and autonomous AI agents work together?
In such a system an AI agent might
- correlate several separate security alerts
- analyse the endpoints and identities involved
- gather threat intelligence
- reconstruct the timeline of an incident
- propose containment steps
- document the event automatically
- carry out certain low-risk actions under control
The human role does not disappear; it moves up a level. The emphasis can shift from manual alert triage towards oversight, decision-making, threat hunting and the handling of complex incidents.
What we are studying
- 01
Human + AI SOC architecture
How can work be divided safely between an analyst and an AI agent?
- 02
Autonomous investigation
Which analysis tasks can be automated without granting the AI dangerous privileges?
- 03
AI-assisted incident response
Where should a recommendation stop, and from where is human approval required?
- 04
Auditability
How is every decision and action taken by an AI documented?
- 05
Regulatory alignment
How does technical SOC operation connect to evidencing NIS2, DORA, ISO 27001 and other requirements?
Our view
The SOC of the future does not necessarily mean a larger analyst team. It may instead be an intelligent cyber operations platform, where people and specialised AI agents detect, investigate and respond together.
02 — Cyber Range & Digital Resilience
Documenting the defence is not enough. It has to be tested.
An organisation can have an incident response policy, security tooling, a backup system and trained people. That is still no guarantee they work together during a real attack.
A cyber range is an isolated, controlled digital environment in which realistic corporate networks, systems and attack situations can be reproduced without putting production infrastructure at risk.
The aim is not simply training. It is to examine how an entire organisation behaves under attack.
An example
In a ransomware scenario the exercise can begin with a compromised user account. The attacker may then attempt privilege escalation, lateral movement, data exfiltration, access to backup systems and finally ransomware deployment.
On the defending side the SOC analyst, IT operations, the incident response team, management, legal, communications and even company leadership may all be working at once.
Do we have an incident response policy?
Does it actually work?
Our research directions
- 01
Enterprise cyber simulation
Reproducing real corporate architectures in a virtual environment.
- 02
Attack simulation
Modelling realistic attack chains and MITRE ATT&CK techniques.
- 03
Blue Team & SOC exercises
Measuring detection, investigation, containment and recovery capability.
- 04
Executive cyber crisis
Extending technical incidents into leadership decision and communication situations.
- 05
Digital twin
Examining how a safely usable digital copy of an organisation's infrastructure can be created.
- 06
Compliance evidence
Examining how exercise results can be turned into auditable evidence.
The longer-term concept
A possible next-generation cyber resilience platform would not simply record that someone completed the training. It could measure, for example:
- Detection capability
- Incident response capability
- Recovery readiness
- MITRE ATT&CK coverage
- Team cooperation
- Management escalation
- Security tool effectiveness
- Regulatory preparedness
A continuously changing Cyber Readiness Score could be derived from these.
The aim
- Train
- Simulate
- Measure
- Improve
- Retest
03 — Agent-Driven Web
What happens when people are no longer the only ones using the internet?
The web was designed for human use. A person opens a page, reads it, clicks, searches, fills in a field, compares options and completes a transaction.
With AI agents a new actor enters that model. A modern browser agent can interpret web pages, navigate interfaces, fill in fields, gather data and carry out multi-step digital processes.
This is not a chatbot. The AI acts.
Does the company use AI?
Which operations do we allow AI agents to perform?
A corporate agent might find a supplier, compare offers, sign in to business systems, process documents, create records, update a database or even start a business process. That can create real efficiency — and a completely new attack surface with it.
New risks
An agent does not only read data: it interprets information, makes decisions and uses tools. So the following can appear, among others:
- 01
Indirect prompt injection
A web page or document can carry an instruction that tries to manipulate the agent.
- 02
Tool abuse
A compromised agent can use the tools available to it for unintended purposes.
- 03
Privilege escalation
Given overly broad permissions, an agent can reach more systems than it needs.
- 04
Data exfiltration
Confidential information can end up in an external service or on a web page.
- 05
Identity and delegation
It has to be established exactly on whose behalf, and with what authority, an AI agent may act.
- 06
Agent-to-agent trust
How can one autonomous system trust information or instructions supplied by another agent?
Agent-Ready Web
The other side of the question is how web pages themselves change. Today a page is optimised primarily for people: UX, navigation, SEO, accessibility.
A new consideration may emerge: Agent Experience — AX.
A page should be unambiguous not only to a person. An autonomous system should also be able to understand:
- what the page offers
- which operations can be performed
- what data those operations need
- which operations are sensitive
- when human approval is required
- how an agent's identity or authorisation can be verified
Alongside SEO, a new optimisation layer may therefore emerge
- Human Web
- Machine Web
- Agent Web
The three areas are in fact connected
At first the SOC, the cyber range and the agent-driven web look like three separate technologies. Over a longer horizon they may be three sides of the same change.
- 01
Agent-driven systems
AI becomes capable of performing more and more digital operations.
- 02
Security Operations
Someone has to detect and control how those systems behave from a security standpoint.
- 03
Cyber Range
And somewhere they have to be tested safely.
One possible model
- AI attacker
- AI-enabled enterprise
- AI SOC
- Human supervisor
In a future simulation it is not necessarily only people facing each other. In that setting a cyber range can become training, security validation and AI safety infrastructure at the same time.
Regcytech Research Direction
Regcytech does not primarily see separate technologies in these areas. Our question is closer to this:
How can next-generation digital systems be adopted so that they are efficient, secure, auditable and controllable from a regulatory standpoint at the same time?
That is what connects cybersecurity, artificial intelligence, governance and regulatory technology. The aim of Regcytech Labs is to study those intersections, evaluate prototypes and concepts, and develop approaches from which new products, services or research collaborations may later grow.
Current research tracks
- 01
AI-Augmented Security Operations
Studying human and AI-agent cooperation in a security operations setting.
- 02
Cyber Range & Resilience Validation
Realistic attack and incident-response environments, measurement and evidence-based cyber readiness.
- 03
Secure Agent-Driven Web
Autonomous browser agents, agent-ready web pages, identity, authorisation and agentic security.
Research & collaboration
Research or technology collaboration
These areas are currently in a research and concept-development phase. We are open to technology, academic and corporate collaborations in which the following can be examined together:
- agentic security architectures
- cyber range technologies
- AI-enabled security operations
- digital resilience
- agent identity and governance
- regulatory and auditability questions
Professional background
These research directions draw on, among others, NIST's cyber range approaches, ENISA's SOC and incident-response material, OWASP's agentic AI security research and the development of modern computer-use and browser-agent architectures.
