Slide 1 (copy/paste) Title: Module 1 — Agentic SOC Upgrade (3 Slides) Content box (paste as-is): Observe & Review: Decision Context (Traditional SOC → Agentic SOC) Decision: implement an agentic SOC because traditional SOC approaches did not keep pace with modern alert volume and threat speed Constraints that shaped the decision: Budget limitations Regulatory expectations Auditability and evidence requirements Integration complexity across tools and workflows Model risk and reliability uncertainty Data access limits and quality gaps Vendor reliance for models and platform capabilities Human element observed: Accountability stress and time pressure increased the risk of “quick conviction” The process re-centred on evidence, oversight, and audit trails Decision timeline (observe → design → verify): Signals: alert overload and triage lag Frame: agentic SOC feasibility vs risk controls Governance design: oversight and logging requirements Integration planning: data/tool dependencies and boundaries Verification: scenarios, failure monitoring, and learning loops Slide 2 (copy/paste) Title: Psychology of Risk: Unit 1 Attributes Applied Content box (paste as-is): System 1 vs System 2 System 1 (fast, persuasive): urgency and momentum made automation seem like an immediate fix System 2 (evidence-based): required gating to prove governance, controllability, and safe operation Whole of Person Model (WoPM) Team stress affected willingness to challenge assumptions across security, compliance, and engineering Psychological safety was treated as a practical enabler of high-reliability decision-making Bias and heuristics (what could distort thinking) Anchoring on vendor claims, pilot metrics, or early wins Premature closure risk: treating early success as final operational proof Reduced challenge when uncertainty felt unsafe for accountability or timelines VUCA/D lens (why uncertainty was real) Volatility and uncertainty from threat dynamics Ambiguity about what “agent success” means operationally Complexity and delayed feedback: outcomes confirmable only after controlled rollout and monitoring Slide 3 (copy/paste) Title: HD-Level Rational Process + Critical Learning Content box (paste as-is): Success criteria Auditability: actions and decisions traceable Controllability: bounded autonomy with defined oversight Verified reliability: monitored behaviour under realistic conditions (not only lab performance) Structured decision process (attributes in action) Observed signals: triage lag, alert volume, tool/data dependencies Hypotheses: agentic automation can improve speed with governance safeguards Bias risks: anchoring, premature closure, reduced challenge under stress System 2 checks: audit logs, model risk assessment, autonomy boundaries, scenario testing Outcome verification: traceability plus monitored agent behaviour after integration Learning: refine scope, governance, and integration sequencing based on evidence Closing critical takeaway An ag