UPDATED 09:00 EDT / JUNE 10 2025

SECURITY

Ontinue brings agentic AI to Microsoft-focused MXDR investigations

Ontinue AG, a Swiss artificial intelligence-powered managed extended detection and response company, today announced the general availability of autonomous incident investigations in its ION MXDR platform, powered by agentic AI.

The new capability, first deployed in December 2024 and now live across Ontinue’s customer base, enables Tier 2-level investigations to be fully automated. A Tier 2-level investigation involves analyzing escalated security incidents that require deeper contextual understanding, correlation across multiple data sources and expert judgment to determine scope, impact and the appropriate response.

With the new offering, Ontinue claims, it’s the first Microsoft-focused MXDR provider to introduce agentic AI for autonomous investigations. The company says that dramatically accelerates detection and response while reducing the burden on in-house security operations teams.

Ontinue’s Agentic AI works by taking over escalated alerts and initiating a process that traditionally required a Tier 2 or Tier 3 analyst. The AI aggregates telemetry, formulates and tests hypotheses and conducts a contextual investigation. The output is a structured summary, including reasoning steps and recommended actions, which is passed to Ontinue’s human cyber defenders for validation and resolution.

According to the company, the result reduces the mean time to investigate incidents by up to 50% and resolves 99.5% of incidents without customer intervention.

“Agentic AI doesn’t just evolve how we do security — it redefines it,” said Chief Executive Geoff Haydon. “Unlike traditional automation tools that follow prescriptive rule-based scripts, the generative nature of Agentic AI allows it to learn, reason, test and adapt within the context of any given situation. It doesn’t just assist humans, it amplifies them.”

The level of autonomy provided by the new offering is focused on solving the longstanding scale limitations faced by managed detection and response providers. Ontinue’s strategy hinges on combining human expertise with intelligent automation as threat sophistication grows and cybersecurity talent remains scarce.

The Agentic AI offering provides near human-level reasoning at machine speed, allowing it to tackle complex, novel attacks that deterministic systems typically miss.

Ontinue’s ION MXDR platform already included automation for Tier 1 triage, but the addition of agentic AI pushes automation deeper into the incident lifecycle. The capability is powered by ION IQ, the core intelligence layer within Ontinue’s platform, which integrates contextual signals from logs, identities, endpoints and cloud systems to build and test investigative hypotheses in real time.

“We’ve always believed that AI is key to overcoming the scale and speed limitations that legacy MDRs can’t address,” said Chief Technology Officer Theus Hossmann. “Security automation has traditionally been limited to predictable ‘if x, then y’ patterns. But novel, multidimensional threats demand reasoning and creativity — things that were once exclusive to humans. Agentic AI flips that paradigm.”

Image: Ontinue

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.