惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
博客园 - 司徒正美
美团技术团队
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
人人都是产品经理
人人都是产品经理
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
Troy Hunt's Blog
S
Schneier on Security
T
The Exploit Database - CXSecurity.com
P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
Engineering at Meta
Engineering at Meta
Cisco Talos Blog
Cisco Talos Blog
T
Tor Project blog
B
Blog
NISL@THU
NISL@THU
月光博客
月光博客
博客园 - 【当耐特】
AWS News Blog
AWS News Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
腾讯CDC
L
Lohrmann on Cybersecurity
The Cloudflare Blog
L
LINUX DO - 最新话题
S
Security @ Cisco Blogs
S
Secure Thoughts
Spread Privacy
Spread Privacy
有赞技术团队
有赞技术团队
The Last Watchdog
The Last Watchdog
Project Zero
Project Zero
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Vercel News
Vercel News
H
Hacker News: Front Page
S
SegmentFault 最新的问题
Schneier on Security
Schneier on Security
aimingoo的专栏
aimingoo的专栏
P
Privacy & Cybersecurity Law Blog
博客园 - 三生石上(FineUI控件)
Forbes - Security
Forbes - Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
I
InfoQ
T
Tailwind CSS Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
G
GRAHAM CLULEY
W
WeLiveSecurity
小众软件
小众软件
Recorded Future
Recorded Future
Cyberwarzone
Cyberwarzone
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org

Cisco Blogs

Edge opportunity for service providers: Turn infrastructure into new services MRC and SRv6: How Foundational Networking Innovations Are Enabling the Next Generation of AI Supercomputers The SMB Marketing Reset: Winning Customer Trust in a Digital-First Economy Inside the SOC: AI-powered DNS defense against ransomware Our Path Forward Securing the Federal Digital Experience with Cisco ThousandEyes for Government Cisco at ONUG Dallas 2026: Securing the AI Data Center in the Agentic Era Cisco and Red Hat are powering intelligent core to edge: Red Hat Summit insights Building the Capabilities That Win: How Cisco Partners Can Lead in the SMB & Mid-Market Era How Two Hours Felt Bigger Than My To-Do List Announcing Foundry Security Spec Ace the CCIE Collaboration Lab: Success Tips from a TAC Engineer Turned CCIE Protecting Agents with Cisco AI Defense and Google Agent Development Kit Powering an Inclusive Future: Your guide to the Purpose Pavilion at Cisco Live Las Vegas The Infrastructure Behind the Mission: SOF Week 2026 Cisco Networking App Marketplace Partners at Cisco Live 2026 Beyond the Pilot: Building the Clinical Data Fabric for the Agentic Era Benchmarking scale-out AI fabrics with Cisco N9000 + AMD Pensando™ Pollara 400 NICs Month of Developer Productivity: Build and Forget The race to autonomous transport networks: A new study Lean IT, future-ready: How to save time and simplify wireless management with AI Reading Between the Pixels: Failure Modes in Vision Language Models Biochar’s triple win: Healthier soils, improved crops, and decarbonization Designing a Proactive Customer Journey Modernize your data center operations with Cisco Nexus Dashboard Why your automation stack needs Cisco Agentic Workflows Try Cisco AI Defense Explorer Edition in this hands-on lab From Bandwidth to Intelligence: How Cisco is Powering AI-Ready Networks Spotlight on digital transformation | FY25 Purpose Report Galaxy Mode is live: A limited-time look at what your Cisco AI Assistant and AgenticOps can already do Securing the Agentic Workforce: Cisco Announces Intent to Acquire Astrix Security Understanding CISA BOD 26-02: Mitigating Risk from End-of-Support Edge Devices Digging Deeper: The Future of Mining with Automation and Ultra-Reliable Wireless Voices from the field: Helping farmers build resilient local economies across rural America Built like a startup, scaled like Cisco: Transforming data center cooling for the AI era Defining Model Provenance: A Constitution for AI Supply Chain Safety and Security Introducing Model Provenance Kit: Know Where Your AI Models Come From Security Insights: A Threat-First View for the Platform That Enforces Access How I Turned My Curiosity into a Patent From Strategy to Architecture: How Cisco is Building a Quantum-Safe Future Maximizing Managed Security Services: A Strategic Guide to Optimizing Your Portfolio (Part 1 of 2) Simplify access control in five easy steps Trust: Why security is your next growth engine Cisco IQ is generally available. Here’s what that actually means. From Vision to Reality: Intelligence in Action with Cisco IQ How connectivity is shaping the future of surgical care The power of your network: Solving a physical security incident on Vision portal 5 signs your data center is holding your AI strategy back Stop Overthinking OT Security: The Total Cost of Ownership and Being Smart with Refreshes AI-Ready, Simpler, and More Secure WAN: Cisco SD-WAN Innovations Scaling the digital future: Why AI and skills investments matter for business and society Expanding our Product Organization Recap Scaling the Future: Reddit AMA on Network Automation at Scale Bringing Professional-Level Skills to Cisco Networking Academy Announcing Cisco Availability in Google Cloud Marketplace: A New Path to Scalable, Partner-Led Growth The Innovation Paradox: How We Reduced Incidents by 25% While Deploying Faster Funding the AI-ready data center: Why flexibility wins The switch that quantum networking has been waiting for From a Message I Couldn’t Believe to a Stage I’ll Never Forget The Hidden Bottleneck Slowing Down Manufacturing Transformation 30 Years as a CCIE: Why Certifications Matter in the AI Era Securing Enterprise AI: Cisco AI Defense Expands to Google Cloud How ThousandEyes Closed the Cloud Visibility Gap by Solving It Themselves First Energy Will Define the Scale of AI Introducing the AI Agent Security Scanner for IDEs: Verify Your Agents Stop Overthinking OT Security: People, Process and Technology Powering the Future of Research: Join Cisco at NLIT 2026 Building the Digital Foundation for a Smarter West Lincoln Memorial Hospital How Cisco built an AI-RRM that maximizes your wireless solution From Automation to Autonomy: Cisco and Rockwell Power a New Era for Manufacturing Unlocking the Future of Fan Engagement: The Power of VisionEDGE Find Yourself in the Future: AI Is the New Baseline—Here’s How to Build Your Skills One Day with Our Customers: Driving better outcomes through customer centricity What It Really Takes to Build an AI-First Workforce From Connectivity to Security: How E80 Future-proofed its AGV Operations with Cisco The Infrastructure of a Floating City: AIDA Cruises’ CX-Led Digital Transformation Scaling your network for AI without a forklift upgrade Why modern networks are moving DDoS defense to the edge Evolve IP Media to AI-Driven Media Fabrics: Future-Proof Broadcast with Cisco and NVIDIA Cisco and Generation are scaling AI-powered pathways to employment Reading Between the Pixels: Assessing Prompt Injection Attack Success in Images Lean IT, future-ready: Why Wi-Fi is your AI growth strategy Cisco Modeling Labs: Bringing the Network Digital Twin to Life AI on the Factory Floor: Why Manufacturing Requires a New Architecture with Cisco Unified Edge Designing for What’s Next: Securing AI-Scale Infrastructure Without Compromise Scaling the Future: Join Our Reddit AMA on Network Automation at Scale 5 wireless trends retail IT teams can’t ignore in 2026 Can your infrastructure management tools do that? Sustainability 101: Let’s talk about energy efficiency From Chai Breaks to Checkpoints: A Day at Cisco Bengaluru Preparing for Post-Quantum Cryptography: The Secure Firewall Roadmap Non-Obvious Patterns in Building Enterprise AI Assistants Making AI Trustworthy and Observable in Real-Time: Cisco Announces Intent to Acquire Galileo A simpler path to unified, AI-ready network operations Cisco Celebrates The Smart Industry Industrial Transformation Award Winners Mobile World Congress 2026: AI-powered Network Security Powering MWC Barcelona – Building a Unified SOC and NOC with Splunk in Record Time How New Data Streams Transformed Cisco Store’s Decision-Making AI-powered Network Security at the Mobile World Congress 2026 SNOC Inside the Mobile World Congress 2026 SOC: Detecting Shadow Traffic with Firepower 6100
Deloitte Japan Advances Security Operations with Cisco Foundation AI’s Open-Source Model
Huaibo Zhao · 2026-06-13 · via Cisco Blogs

Introduction 

We are excited to announce that Deloitte Japan is beginning production validation of Cisco Foundation AI’s Foundation-sec-1.1-8B-Instruct model for its security operations. By using this security-focused, open-source large language model (LLM), Deloitte Japan has automated key tasks such as security alert analysis, prioritization, and false positive reduction. This adoption highlights how open-source generative AI can enhance traditional security operations and offers practical insight into implementing purpose-driven workflows with cost-effective LLMs.  

Background 

As a managed security service provider, Deloitte Japan receives numerous security alerts from customer environments every day and must analyze and triage them. Some of these tasks are labor-intensive, such as analyzing raw alert logs and drafting summaries for each alert. Others require specific security knowledge and experience, like identifying false positives and creating suppression rules to prevent similar issues from recurring. 

By implementing Cisco Foundation AI’s Foundation-sec-1.1-8B-Instruct model, Deloitte Japan has streamlined these tasks using workflows based on human analysts’ expertise. This approach accelerates alert triage and improves detection quality. Thanks to task-specific prompt tuning and workflow design, Deloitte Japan achieved stable and accurate results with the Foundation-sec-1.1-8B-Instruct model, matching the performance of models with over 15 times more parameters. 

Based on this approach, Deloitte Japan is now introducing LLM-driven automation into the SOC workflow. The objective is not full automation of every analyst task, but practical automation of the most repetitive and time-consuming parts of alert handling. 



Figure 1: SOC workflow and target areas for LLM-based automation.

Workflows 

Using the Foundation-sec-1.1-8B-Instruct model, Deloitte Japan developed three core workflows.

1. Alert Analysis Support 

This workflow supports analysts in alert analysis. It analyzes alerts handled by security analysts, assesses the impact of an attack, and provides the results along with the steps leading to the decision. 

Figure 2: Agent workflow for alert analysis support. 

As shown in Figure 2, the agent performs alert ingestion, targeted event collection, grounding, filtering/deduplication, enrichment, assessment, report generation, and follow-up guidance. 

Specifically, it performs alert ingestion from SIEM; targeted event collection from IPS and EDR around the alert window; retrieval-augmented grounding against runbooks, prior cases, detection notes, and pre-attached threat intelligence or auxiliary logs; relevance filtering and deduplication; asset/user/context enrichment; severity and impact assessment; draft case-note/report generation; and follow-up guidance.  

Figure 3: Example output of the analysis. 

As shown in Figure 3, the output supports rationale, key evidence, uncertainty drivers, and an auditable step-by-step analysis trace. It also provides follow-up guidance (next actions and auto-closure criteria for clearly low-risk cases). The next steps are production validation and selective automation for well-bounded low-risk scenarios, with a human in the loop for anything ambiguous. 

2. Alert Severity Analysis and Prioritization (Alert Triage)


Figure 4: Agent workflow for alert severity analysis and prioritization
.
 

This workflow analyzes EDR alerts using alert details and related telemetry to support prioritization and identify likely false positives. As shown in Figure 4, the agent performs alert retrieval, event collection, relevance filtering, severity assessment, report drafting, and follow-up guidance.

To improve output quality, the workflow uses surrounding EDR activity in addition to the alert itself, while controlling event scope to avoid excessive context. It also separates severity assessment, report drafting, and next-step guidance to reduce context drift and improve output stability.
As shown in Figure 5, the output includes not only a severity label but also supporting rationale and uncertainty-related information that can guide analyst review. The next step is production validation and selective automation for clearly low-risk cases. The remaining challenge is robust evaluation of low-severity and false-positive scenarios. 

Figure 5: Example output of the triage. 

3. Alert Suppression Rule Creation based on False Positive Cases 

In this workflow, the agent uses incident data recorded in tickets. Based on that data, it produces a suppression rule that suppresses only alerts linked to events determined to be false positives. It also outputs the reasoning behind the rule. When a false positive involves misuse of legitimate tools, such as Living off the Land attacks, the suppression rule needs to reflect how the tools were used. 

Figure 6: Agent workflow for Alert Suppression Rule Creation based on False Positive Cases. 

As shown in Figure 6, this workflow runs in several phases. To support accurate decisions, the process is broken down so that each task maps to a single node, and the graph structure enables branching based on each decision outcome. As shown in Figure 7, the workflow outputs the suppression rule. Rather than having the model generate the rule conditions directly, it first selects the necessary conditions from incident-related entities and then assembles them. This is intended to improve the consistency and reproducibility of the conditions and increase the success rate of assembling the rule. 

Figure 7: Agent workflow for Alert Suppression Rule Creation based on False Positive Cases  

These workflows can support security operations by providing summarized analysis for each alert, determining severity to identify critical or false positive cases, and generating effective suppression rules to filter out false positives in the future. With these outputs, security analysts can quickly understand the content of each alert. Severity scores help analysts focus on the most critical alerts. By applying suppression rules, analysts avoid being overwhelmed by insignificant alerts and can focus on what matters most.  

Optimizations 

The Foundation-sec-1.1-8B-Instruct model is a relatively small LLM with only 8 billion parameters, which keeps inference costs low and makes practical deployment easier. To match the performance of much larger models, Deloitte Japan applied several optimization techniques. 

One effective technique was to break tasks into multiple steps within a workflow, rather than using a single, complex prompt. Workflows were designed based on human analysts’ experience, with steps such as extracting key information from alerts, reasoning over extracted values and patterns, and generating outputs based on previous steps. This allows the model to focus on each step with sufficient context and leverage organization-specific logic to ensure outputs are useful in production. 

Another technique was to use structured outputs during intermediate steps. By specifying JSON-formatted output, the workflow can pass important information between steps more reliably, reduce ambiguity, and support smoother integration with downstream processing. 

RAG is also used to improve the accuracy of the analysis. By using a combination of the security analyst’s analytical knowledge, monitored asset information, and historical response history, the agent can suggest actions more closely aligned with an analyst’s judgment.  

Conclusion 

The integration of Cisco Foundation AI’s Foundation-sec-1.1-8B-Instruct model into Deloitte Japan’s security operations marks a significant milestone in using open-source, security-focused AI models to accelerate and streamline security tasks. This helps reduce SOC analyst workload and improve productivity. We extend our sincere gratitude to the Deloitte Japan team for their outstanding implementation and for sharing the details of this use case. 

Customer Testimonials

“Through this PoV, Deloitte Japan confirmed that Cisco Foundation AI’s security-focused open-source model can support practical SOC automation, including alert analysis, prioritization, and false-positive reduction. By turning analyst expertise into structured workflows, we achieved explainable outputs with rationale and evidence. The results show that even an 8B model can deliver stable outcomes when combined with workflow design and structured outputs.” 

— Kohei Sato, Partner, Head of Cyber Intelligence Center, Deloitte Tohmatsu Cyber LLC