The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Secure Networks: Endace Packet Forensics Files
Secure Networks: Endace Packet Forensics Files artwork

Episode 67: Erik Dove, Security Sales Engineer and incident response expert, Cisco

Secure Networks: Endace Packet Forensics Files · 2026-08-03 · 16 min

0:00--:--

Key moments - from our scoring

Substance score

43 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber11 / 20
Specificity & Evidence8 / 20
Conversational Craft8 / 20

Erik Dove brings incident response expertise from his work across telecom, authentication, and vulnerability prioritization roles to discuss the operational shift toward agentic AI within security operations centers. The conversation centers on how AI agents improve SOC efficiency not by replacing human analysts but by automating triage, enriching correlations across detection platforms, and enabling faster mean-time-to-response. Dove emphasizes establishing service level agreements as a foundational step, then layering in AI agents - treating each agent as a specialized worker handling SOAR automation, MITRE ATT&CK tactics, or summarization. He advocates for always-on packet capture (via Endace) integrated with SIEM, firewall, and XDR tools to validate alert signals, reduce false positives, and provide the bandwidth and communication context that distinguishes genuine incidents from DNS cache artifacts. For teams maturing their SOCs, Dove recommends first understanding what's critical via SLAs, then automating proven manual responses, and progressively raising the sophistication of incidents humans handle. His Law and Order analogy frames the future: as threats grow more sophisticated, digital fingerprints remain identifiable, and comprehensive packet forensics enable faster incident resolution.

Key takeaways

  • →Establish service level agreements across all alert types before implementing agentic AI, so you understand what your organization can realistically handle and where to automate versus manually triage.
  • →Packet data enrichment via tools like Endace validates whether alerts represent genuine malicious activity or false positives (such as DNS cache artifacts) by showing bandwidth consumption and full communication context.
  • →Agentic AI agents function as specialized workers - one handling SOAR automation, another mapping MITRE techniques, another writing summaries - allowing a single analyst to operate faster on high-confidence, true-positive alerts.
  • →Human analysts remain essential because threat actors are human; machines cannot yet replicate the reasoning required to understand adversary intent and methods across novel attack scenarios.
  • →Automate response workflows only after manually validating them once, then progressively remove automated alerts from analyst queues, allowing triage resources to focus on novel or complex incidents.

Guests

Erik Dove

Topics in this episode

Agentic AIService Level Agreements (SLAs)MITRE ATT&CKAlert fatiguePacket ForensicsMean-time-to-triageEndace packet captureCisco SIEMCisco XDRSOAR automation

Questions this episode answers

How does adding always-on packet capture change SOC operations compared to relying only on logs and alarms?

Packet capture provides bandwidth and communication forensics that validate whether alerts represent real malicious activity or false positives, enabling faster triage and deeper incident investigation within a specific time window, complementing SIEM logs and firewall/XDR detections.

What is mean-time-to-triage and why is it different from mean-time-to-response?

Mean-time-to-triage focuses on finding the why or how an incident happened to understand the core of the problem, whereas response is the action taken; agentic AI accelerates triage by handling routine work so analysts focus reasoning on genuine threats.

What first step should organizations take before implementing agentic AI in their SOC?

Establish service level agreements for all alert types so you understand what your organization can realistically respond to within defined timeframes, then automate alerts proven to be accurately and safely handled without human intervention.

How do AI agents reduce alert fatigue while maintaining detection fidelity?

By focusing analyst attention only on alerts deemed critical and high-priority per the organization's SLA and data sources, while ensuring lower-priority alerts are not forgotten but deprioritized, so humans engage only with actionable, high-confidence signals.

What role do humans play in a fully optimized agentic AI SOC?

Humans provide the reasoning and threat-actor perspective needed for novel or complex incidents, while AI agents automate routine triage, enrichment, and response tasks, allowing analysts to operate faster on work that is genuinely valuable and not false positives.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode contains some solid operational guidance on SOC practices (SLA-driven triage, mean-time-to-triage, automation workflow progression) but relies heavily on abstract framing and repetition without deep specifics. The core insight - that packet data enriches alert accuracy and reduces false positives - is valuable but not particularly novel, and much of the discussion circles back to the same points rather than layering new ideas.

alert fatigue I think starts at what you deem necessary as an organization because you have to find a baseline of what's important and you get that through understanding what's critical, high, low
packet data enrichment is probably the troubleshooting step that's needed for accuracy

Originality

7 / 20

The guest recycles familiar SOC concepts (SLAs, mean-time-to-triage, automation playbooks, incident response cycles from SANS) without offering contrarian or first-principles thinking. The Law and Order analogy is memorable but not intellectually original. The discussion of agentic AI in SOCs is current but not particularly differentiated from vendor marketing messaging.

Lessons learned. That's from Sans. Um, the lessons learned learned
when I'm working in the SoC, I think of the TV show Law and Order

Guest Caliber

11 / 20

Erik Dove holds a relevant title (security sales engineer and IR expert at Cisco) and appears to have hands-on SOC operations experience, but the transcript reveals limited depth of operator seniority. His background shows progression through telecom and vulnerability work, but he speaks more as a practitioner-facing sales engineer than as a battle-tested incident responder who has scaled incident response operations or driven major architectural decisions. He lacks the credibility markers of a CISOs, VP of Security Operations, or someone who has led large IR teams.

I live in Texas, uh, by way of Queens, New York and the Bay area of California
I studied networking for several years and then I landed a job in telecom

Specificity & Evidence

8 / 20

The episode lacks concrete numbers, named incidents, or tangible metrics. References to '10 minute window,' 'meantime to triage,' and bandwidth consumption are mentioned but never quantified. No specific incident examples are walked through, no real-world data breaches are cited, and the discussion remains at the level of process description rather than demonstrable outcomes. The one pseudo-specific reference ('that one specific alarm with Barry') is vague.

I think the 10 minute window that index gives us when we identify where the issue is
if there's no bandwidth, then nothing happened. Right? It was just maybe a DNS cache or something like that

Conversational Craft

8 / 20

The host asks reasonable opening questions but rarely pushes back, challenges claims, or demands specifics. Follow-ups are surface-level affirmations ('that's a great point') rather than probing deeper. When the guest makes vague statements (e.g., 'agentic AI gives you specialized workers'), the host does not ask for concrete examples. The conversation reads as a friendly SOC-shop discussion rather than an investigative interview designed to stress-test ideas.

Yeah, yeah, that's a great point
No, that's a great point and a perfect example

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B65%
  • Speaker A35%

Most-used words

data16packet14agentic8understand8level8leveraging7incident7point7order7security6makes6response6alert6important6human6cisco5

Episode notes

Artificial intelligence is rapidly reshaping Security Operations Centers (SOCs), helping security teams investigate incidents faster while reducing alert fatigue. But as AI becomes more capable, what role do human analysts and packet data play in an increasingly automated SOC? In Packet Forensics Files Episode 67, Michael Morris sits down with Cisco Security Sales Engineer and incident response expert Erik Dove to discuss how Agentic AI is changing incident response, where packet data fits into modern SOC workflows, and why both experienced analysts and packet data remain essential. If you're interested in how AI, automation and packet capture are shaping the future of security operations, this episode is highly recommended. It's a fascinating discussion with plenty of practical advice for organizations looking to build more effective SOCs.

Full transcript

16 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign. Hello and welcome to this edition of Secure Networks, the Index Packet Forensic Files with your host, Michael Morris. This episode's very special guest is Eric Dove, security sales engineer and IR expert with Cisco. Eric, welcome. Thanks for joining us. And tell us a little bit about yourself and your background.

Speaker B: Hello, Michael. Yeah, uh, I live in Texas, uh, by way of Queens, New York and the Bay area of California. Uh, I love basketball, video games and traveling with my wife and two kids. Uh, I studied networking for several years and then I landed a job in telecom. I upgraded that to leveraging, uh, smtp, load balancing web traffic. Um, from there I took a job heavily leveraging Kerberos and authentication. Um, and I did that all across America. And then I gained a position at a vulnerability company for prioritization. And that's where I landed my current job as a security sales engineer.

Speaker A: Great. Well, we appreciate you taking the time to join us. I know your background, working with you in the, uh, security operations centers at the, uh, Cisco lives here. Recently, um, I thought it would be a really good topic to focus on, um, the shift to agentic AI and that process within the SOC as it pertains to how SOCs operate and how um, engineers work and things like that. I think your expertise will be really fitting for that. Where I want to start is, um, agentic AI first implies that systems reason and act autonomously. I'd start with where have you seen the biggest efficiency gains from AI driven workflows in day to day SOC operations?

Speaker B: Um, the biggest efficiencies I've seen are in the accuracy of the incident. That's really about. Is this something that I should really work on? When you're able to understand that you're able to then, uh, exponentially work faster. And that makes it so that way you can then standardize those procedures of what you're working faster at. And it makes it so that way, um, you're able to operate better within the SoC.

Speaker A: Okay, yeah, it was great. Jessica, the director of the soc, I loved how she talked about, um, you know, everybody got a promotion. All the first level engineers. Right. And you're a tier three SOC analysts, so you must be like supreme commander now at your level, uh, with all the level one folks promoted because of the AI, ah, automations. So with so many telemetry sources within a soc, right, you got everything from packet data, network detection, response data, endpoint data, uh, obviously all the log data within the siem. What strategies or AI driven techniques are most effective in reducing alert fatigue while preserving, um, high fidelity detections Right,

Speaker B: Yeah. Um, well, uh, alert fatigue I think starts at what you deem necessary as an organization because you have to find a baseline of what's important and you get that through understanding what's critical, high, low. And then when you do that you create a SLA or service level agreement to it. So that way you know what your responders need to action on within a certain time value. And then from there, once you understand what you're working towards, then you need to understand what's your meantime to triage. Meantime to triage is different than like just having a response. It's like finding the, the why or how it happened because then you're able to then really figure out um, like the core of the incident at that point. Um, and how is it, how does it reduce uh, alert fatigue? Um, the AI component of it is giving you the ability to just look at the alerts that are important to the organization, uh, and the um, data ingest points that are important to the organization. And that makes it so that way, um, all the other ones that are coming through that um, data source are not necessarily forgotten about, but they're less important within that time period.

Speaker A: All right, no, that's a great point. So obviously ndase is proud to be a part of uh, Cisco SOC operations and the continuous always on packet capture that we provide. So from your perspective, seeing it integrated with all the other Cisco security tools, um, from your perspective, how does adding always on packet data fundamentally change the way a SOC operates compared to relying solely on logs, uh, and alarms from the various tools, whether it be firewalls, XDR or within your siem,

Speaker B: um, when you're able to achieve the service level, uh, agreement that you have with all the fidelity, um, that's coming in from all those detections, then you can then work on what's called the incident response cycles. Um, lessons learned. That's from Sans. Um, the lessons learned learned. Part of that is at the end and when you're doing the data investigation and the analysis, when you're leveraging a siem, it gives you all the logs, right? Uh, but you don't need all the logs. Even though we're getting always on packet data capture from all the logs, I need to know which ones are important and when, how do I get to that? So the SIEM helps me having the governance of all the data in the right place. The firewall gives me the traditional allow and block of all the logs in the right direction. Um, and I think that the consumable chunks of data that we need in order to take action on indase, helps with the action items of the XDR solution, allows me to understand exactly what timetable I need to look at in depth now.

Speaker A: Yeah, yeah, that's a great point. And you know, we've talked a number of times about, uh, within the SoC, about the timeline, right, Being able to follow the timeline of events and activities. So that's a critical point you made there. How do you see the integration of packet data enriching correlations across those different platforms? And what operational efficiencies does that unlock for an analyst? Um,

Speaker B: packet data enrichment is probably the troubleshooting step that's needed for accuracy. Um, and the reason why I say that is that you, um, on the firewall or the network detection system or the siem, it validates the signal with emphasis on why the signal is important. Um, but the breakdown that you have within Wireshark and the bandwidth consumptions within n days fundamentally question, uh, the investigation as to, you know, why, uh, you would have that alert in the first place. And that gives you um, a tooling at, to where you can then find whether or not within the window that we see within it as uh, what, how much bandwidth came through? If there's no bandwidth, then nothing happened. Right? It was just maybe a DNS cache or something like that. But if you see something within the bandwidth consumption and then go into Wireshark and then see all the different, uh, uh, within the cap, uh, the captured packet there, you're able to then dive in and understand exactly, uh, what the communication was between A and B or whatever that problem might have been.

Speaker A: No, that's a great point and a perfect example of leveraging it in incident response time is critical. Uh, how does leveraging packet data packet visibility with agentic AI impact the mean time to detect or the meantime to respond?

Speaker B: Um, I think that technology within the last couple of years is almost not even thinking about the mean time to detect because it's accurate and instant. So we are less about detecting a problem as a part of our concern and more about what uh, is our ability to respond or triage. And then the agent of the idea gives the team a specialized worker on every aspect of the solution. So I have a guy who can do the soar, I have a guy who can take care of the tactics and techniques. I can have a guy that will write a summary for me. Right? That's all great. We're still not getting to like the resolution of the problem, but like, it's, it's making me all more um, impactful as to when I find that resolution, how faster I can elevate that to an executive or give somebody else that information or to move on to it in order to take action. Whereas these things would have taken longer if I were to try to do it on my own. Um, so I think the 10 minute window that index gives us when we identify where the issue is on um, responding to a situation and triaging that situation, uh, a lot easier to work through. And it's by knowing that I have all these other agenda AI workers that I'm able to work as a team, as a single person, uh, leveraging those products.

Speaker A: No, that's a great point. And again being able to span back from that 10 window and look across other IPs. Right. Some examples I saw being used over and over again. So that's a great point. As more investigations or as more investigative and triage tasks become more automated, where do you think the human analysts stand still provide the most value with an agentic AI driven soc?

Speaker B: Um, I think the human element is definitely here to stay.

Speaker A: I hope so.

Speaker B: I mean it has to be, I think at least on things that happen with these type of alerts because there's humans in the interaction that create the problem. So you gotta think like a human. You have to hopefully be a human in order to understand how they did that. Um, and for a machine to figure that out is probably going to be hopefully years from now. Um, and I think that the um, agentic AI SOC just makes the um, alerting and response quicker and it's accurate to its true positive findings, which is, you know, what we're looking for. We want to make sure that when I am thinking like a human that I'm doing it on work that is useful, uh, or that is something that actually happened and not a false positive.

Speaker A: Right? No, that's a great example. And I remember working that one specific alarm with Barry that we ran through the AI um engine specifically and it just validated it was not, it was basically a false positive. The alarm was real, but there was no malicious activity within it because we could run it through and we could analyze the traffic quicker. I think you're spot on there. Um, how have your SOC Playbooks or your workflows evolved with the introduction of AI agents? Uh, and complemented with packet data. What best practices would you recommend for teams looking to mature or elevate their SOC to this type of model?

Speaker B: Um, this model, um, that leverages the Playbooks is great, but if I was talking at a new team I would really emphasize that they look at a service level agreement on all the alert types that come through those systems. Um, because you want to understand what's the fatigue of you as a business or as a person or as a staff and whether or not you can get within those timeframes in order to get uh, solve those issues.

Speaker A: Okay.

Speaker B: Some companies even uh, provide like partners that go out of those time values that they're not able to work on those type of issues as an, as an added on service. Um, but you want to make sure that you can uh, uh, hopefully allow for the uh, data to be responded to without human involvement. And that's where you automate that task. Once you have the service level agreement in place, then you're able to then transition uh, to a model where you have better accuracy leveraging the agentic AI. Um, and then from there you can then walk or manually respond to the incident. Once you've manually responded to the incident, then you know the outcome, you know it works, you understand what's the effect of an action and then you can automate that response. So then we call that like running with it. So you're running the command, right? You're running whatever the automation is, you're using that workflow to move forward. Um, and then that repetition makes it so that way um, the triage is seeing less of the signal of something new because that's been automated. And then the things that bubble up are um, either more involved or have a ah, deeper connection uh, to a newer alert that they haven't seen before. Um, and uh, NDIS's full packet capture helps out with that finer detail whenever we need to figure out what's going on with the incident itself.

Speaker A: That's a great example. Um, I always like in these interviews to ask my guests to uh, put on their prognosticator hat and look ahead, uh, look into the future. About what does a fully optimized Gentic AI SoC look like to you and what key steps should organizations be thinking about or take, uh, to move forward uh, to that level of operational efficiency?

Speaker B: That's a good question.

Speaker A: Um,

Speaker B: when I'm working in the SoC, I think of the TV show Law and Order.

Speaker A: I love Law and Order.

Speaker B: Okay. Uh, so I think about the future and the agentic AI SoC. The uh, tools are better and the problems are going to be harder. But fundamentally the fingerprints uh, will not change. Right. So we uh, have fingerprints, we have digital fingerprints and I think N days records all of those in each of their deployments. So you're able to then see all the fingerprints. You're able to detect exactly what's going on and it makes it easier to accomplish that problem.

Speaker A: That's a great analogy. I'm going to have to start using that one. Uh, the Law and Order, uh, comparison uh, there so. Well Eric, I appreciate you taking time out of your busy day. Uh, I know you've got a lot going on um, so I thank you for sharing your insights um, on how to better improve uh, security operations, uh, agentic AI workflow. We'd ask our listeners to tune in next time for another episode of N Days Packet Forensic Files. And for more information about N Days network packet capture platform and their integrations with the portfolio of Cisco Security Solutions, please go to n days.com Eric, thanks again for taking the time with us. Really appreciate it and uh, thanks for joining.

Speaker B: Thank you Michael. Appreciate it.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Can responsible AI beat hallucinations?The ITPro Podcast · on Agentic AI95 / 100
  • Why your research needs a “thinking cave” with Sarah KlingThe Curiosity Current: A Market Research Podcast · on Agentic AI89 / 100
  • AI Didn't Change the Rules, It Raised the Stakes (ep.13)Practical Cybersecurity with Jen Stone · on Agentic AI85 / 100
  • Media Briefs: Terrapinn’s Sharon Roessen on boosting event registration and attendance with agentic AIThe Publisher Podcast by Media Voices · on Agentic AI82 / 100
  • Elizabeth Wooliston, Chief of Markets: Artificial: Why the London Market is ready for intelligent automation (413)InsTech · on Agentic AI81 / 100
  • The Judgment Void: How AI Is Dismantling the One Human Capability It Cannot Replace, with Larry DurhamHuman Capital Leadership · on Agentic AI80 / 100

More from Secure Networks: Endace Packet Forensics Files

All episodes →
  • Episode 65: Cody Spooner, Senior Sales Engineer and IR expert, Corelight58 / 100
  • Episode 65: Andrew Cook, CTO Recon InfoSec
  • Episode 64: Steve Fink, CTO and CISO at Secure Yeti
  • Episode 63: Jack Chan, VP of Product and Field CTO at Fortinet
  • Episode 62: Jessica (Bair) Oppenheimer, Cisco's Director of Security Operations
Explore the best B2B Engineering & DevTools podcasts →
All Secure Networks: Endace Packet Forensics Files episodes →