Buy vs. Build AI Security: Why Box.com CISO is Creating their Own Agentic SOC

Buy vs. Build AI Security: Why Box.com CISO is Creating their Own Agentic SOC

🎙 AI Security Podcast 👥 20K 📅 April 22, 2026 ⏱ 46 min 👁 10K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

AI SOCbuy vs buildCISOagentic AIsecurity transformation

Summary

In this episode of the AI Security Podcast, hosts Ashish and Caleb interview Heather Ceylan, CISO at Box.com, about her approach to AI-driven security transformation. Heather discusses the distinction between acceleration (making existing processes faster) and true transformation (eliminating entire classes of work). She details Box’s journey in building an AI SOC, achieving a 38% automated triage rate for Tier 1 alerts, and emphasizes the importance of treating prompts as policy engines to control hallucinations. The conversation covers the buy vs. build dilemma, with Heather explaining why she prefers building custom AI solutions until vendors can out-innovate her team. She outlines Box’s five strategic AI bets: AI SOC, threat intelligence and detection engineering, vulnerability management, security architecture, and third-party risk management. Heather stresses the need for security architecture to be machine-consumable as AI agents increasingly write code. She also discusses the challenges of third-party risk management, the importance of continuous pen testing, and the rise of shadow AI. The episode concludes with personal insights into her leadership style and the importance of fostering a developer-first culture.

176 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for practitioners, as it provides real-world insights from a CISO actively implementing AI in security. Heather’s emphasis on measurable outcomes (e.g., 38% triage rate) and the distinction between acceleration and transformation offers a pragmatic framework. The argumentation is solid, grounded in specific examples and lessons learned, such as the need for deterministic prompts and the iterative trust-building process with AI agents. The hosts ask relevant, probing questions that draw out practical details, enhancing the credibility of the discussion.

Scientific Rigor, Source Quality, Title Accuracy

The podcast demonstrates reasonable scientific rigor for an expert opinion format. Heather references her own experience and Box’s internal data, but does not cite external studies or peer-reviewed sources. The title accurately reflects the content, focusing on the buy vs. build decision and the agentic SOC. The discussion is well-structured, but the lack of external references limits its generalizability. The hosts do not provide additional sources or citations, relying on the guest’s expertise.

173 words

Title / Content Match

The title accurately reflects the core discussion: the buy vs. build decision for AI security, specifically Box's CISO's approach to building an agentic SOC. The content directly addresses this topic.

Quality & Reliability

7/10

The podcast features a practicing CISO (Heather Ceylan) sharing concrete, real-world experiences and metrics (e.g., 38% automated triage rate) from Box's AI security transformation. The discussion is grounded in practical implementation rather than theoretical claims, and the hosts ask probing questions. However, the content is primarily anecdotal and based on a single organization's experience, with limited external verification or peer-reviewed sources.

Chapters

Cited Sources

Concurring Sources

Contribution & Novelties

The podcast provides a unique perspective from a CISO actively building AI security solutions, offering practical insights into the buy vs. build decision, the importance of treating prompts as policy engines, and the need for security architecture to be machine-consumable. It highlights the concept of ’eliminating classes of work’ as a key metric for AI transformation, which is a valuable framework for security leaders.

Pour aller plus loin :

116 words

Radar Profile

The radar profile shows high scores in quantity of information and fiabilité globale, indicating a content-rich and reliable discussion. The niveau technique is moderate, reflecting the practical, non-academic nature of the conversation. The overall balance suggests a valuable resource for security professionals seeking real-world insights.

Reliability 7/10

💬 No comments were provided for analysis.