Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Mobot: Sumo Logic's natural language AI for SOC investigations

Mobot is Sumo Logic's conversational interface designed to streamline investigations for SOC analysts and observability users. Ask a question in plain English and get a full SOC analyst-style investigation without writing a query. Inside an Insight, Mobot pulls context like the C2IP, ransomware hash, host, and exfiltration data automatically. A six-word question, "anyone else hit by the campaign?", triggers a full investigation across every mailbox and endpoint tied to that attack, with a link to the raw query behind every answer.

Sumo Logic's SOC Analyst Agent: Automated triage for every tier one alert

Sumo Logic's SOC Analyst Agent automatically triages every insight within the SIEM, replacing the manual work that used to fall to a tier-one analyst. Using Sumo Logic's own SOC as customer zero, we found that 100% of tier-one alerts are triaged end-to-end by the agent, resulting in a 89% reduction in median time to triage, from 28 minutes to 3 minutes. In this demo, you’ll see.

Black Hat FOMO? Dojo AI Demo

On this episode of Masters of Data, we take you inside the Dojo AI demo we're bringing to the show floor at Black Hat. We walk through the SOC Analyst Agent, Mobot, and MCP back to back. SOC Analyst Agent triages every tier one alert down to the one that actually matters, and Mobot picks up from there, running the investigation in plain English to track down other phishing victims and lateral movement. We also show how MCP pulls that same insight into Claude or Slack. SOC leads tired of alert fatigue and analyst burnout will want the numbers here: 100% of tier one alerts triaged automatically, and 25 hours a week back per person.

Called it (mostly): Checking in on 2026 predictions so far

On this episode of Masters of Data, we revisit the predictions Adam White, Zoe Hawkins, and David Girvin made at the end of last year, checking our own scorecard halfway through 2026. The hits: agents running amok and deleting databases, MCP becoming the backbone for tracking what agents actually do, growing security gaps around personal data, and a collective rejection of low-quality AI content. The misses: we underestimated how fast companies would cut staff for AI, then quietly start rehiring once the agents couldn't cover the work, and we're still arguing about whether token burn is a cost problem or a coming attack vector.

Stop building security dashboards nobody reads

On this episode of Masters of Data, we dig into one of data's most contested formats: the dashboard. We explore why so many dashboards get built and never opened, tracing the shift from in-person SOC culture (big screens, shared visibility, immediate feedback) to the remote-work era of folders full of charts no one reviews. The conversation covers North Star metrics, the tension between practitioner and leadership dashboards, and the uniquely tricky problem of security metrics that can look green while a threat actor has quiet dwell time in your environment.

EU data sovereignty and security operations: how Sumo Logic solves both at once

EU organizations in finance, healthcare, telco, and government face a real tension: keep the business running or satisfy an ever-growing stack of data regulations. Most end up choosing one over the other. Sumo Logic and AWS just changed that. At Infosecurity Europe 2026, Bill Peterson, Senior Director of Product Marketing at Sumo Logic, sat down with Sean Martin from ITSPmagazine to break down Sumo Logic's integration with the AWS European Sovereign Cloud — and what it means for security and operations teams operating in the EU. In this interview, Bill covers.

AI Quality EXPLODES Unlock Productivity SECURELY & FAST! #podcast #cybersecurity

On this episode of Masters of Data, Adam White and David Girvin dig into Sumo Logic's freshly launched compliance apps for Claude, ChatGPT, and LiteLLM, and why your IT team will want to pay attention before the token bill arrives. We unpack how enterprises can move beyond the "AI black hole" era of shadow IT and actually get eyes on who is using what, how much it is costing, and whether any of it is moving the needle.

AI is a NEW Gold Rush But Token Burn is STUPID! #podcast #cybersecurity

On this episode of Masters of Data, Adam White and David Girvin dig into Sumo Logic's freshly launched compliance apps for Claude, ChatGPT, and LiteLLM, and why your IT team will want to pay attention before the token bill arrives. We unpack how enterprises can move beyond the "AI black hole" era of shadow IT and actually get eyes on who is using what, how much it is costing, and whether any of it is moving the needle.

LLMs Data Spies or Security Nightmares #podcast #cybersecurity

On this episode of Masters of Data, Adam White and David Girvin dig into Sumo Logic's freshly launched compliance apps for Claude, ChatGPT, and LiteLLM, and why your IT team will want to pay attention before the token bill arrives. We unpack how enterprises can move beyond the "AI black hole" era of shadow IT and actually get eyes on who is using what, how much it is costing, and whether any of it is moving the needle.