Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • Threat Intelligence

CrowdStrike and IBM Expand Collaboration for Agentic SOC Transformation


CrowdStrike and IBM Expand Collaboration for Agentic SOC Transformation
  • by: Source Logo
  • |
  • March 26, 2026

CrowdStrike and IBM have expanded their strategic collaboration to advance agentic SOC transformation.

Quick Intel

  • CrowdStrike and IBM integrate Charlotte AI with IBM ATOM for coordinated machine-speed investigation and containment
  • Falcon platform now extends into IBM Consulting’s managed Threat Detection and Response services
  • Collaboration includes immersive cyber crisis simulations via IBM X-Force Cyber Range
  • Addresses shrinking defender response windows with average eCrime breakout time at 29 minutes
  • Combines AI capabilities to analyze detections across endpoint, identity, and cloud environments
  • Enables streamlined investigation, reduced manual handoffs, and faster coordinated response

Integrating AI for Machine-Speed Threat Response

The expanded collaboration integrates CrowdStrike Charlotte AI with IBM’s Autonomous Threat Operations Machine (ATOM). This integration enables coordinated, machine-speed investigation and containment by analyzing detections across endpoint, identity, and cloud environments while applying enterprise context to execute containment decisions. The joint solution reduces manual handoffs and helps security teams act before threats spread.

Extending Falcon Platform into Managed Services

The CrowdStrike Falcon platform is now integrated into IBM Consulting’s managed Threat Detection and Response services. Organizations will also benefit from joint offerings in IBM’s global X-Force Cyber Range, where the companies will deliver immersive cyber crisis simulations to prepare for emerging threats.

Responding to Accelerated Threat Landscape

AI is accelerating adversary operations and shrinking the defender’s window to respond. According to the CrowdStrike 2026 Global Threat Report and IBM’s 2026 X-Force Threat Intelligence Index, the average eCrime breakout time has dropped to 29 minutes, with the fastest observed in just 27 seconds, while attacks targeting public-facing applications are up 44% from the prior year. As threats move faster across cloud environments, security teams require coordinated detection and containment at machine speed.

“Enterprises trust IBM to advance their security programs,” said Daniel Bernard, chief business officer, CrowdStrike. “With Charlotte AI helping to deliver investigation, containment, and operational response, IBM’s autonomous threat operations machine (ATOM) and cyber threat management services are battle-ready to defend against modern threats.”

“Organizations are under pressure to accelerate response without increasing complexity,” said Dave McGinnis, Vice President, Global Managed Security Services, IBM. “By combining IBM ATOM with CrowdStrike’s Charlotte AI and delivering managed Threat Detection and Response services and Cyber Range validation with the Falcon platform, we’re helping enterprises operationalize coordinated, AI-driven response in real-world environments.”

Together, CrowdStrike and IBM are leading agentic SOC transformation with a unified execution model for modern enterprises. The collaboration provides a comprehensive approach that combines advanced AI orchestration, managed security expertise, and practical simulation-based preparedness.

About CrowdStrike

CrowdStrike, a global cybersecurity leader, has redefined modern security with the world’s most advanced cloud-native platform for protecting critical areas of enterprise risk – endpoints and cloud workloads, identity and data. Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon® platform leverages real-time indicators of attack, threat intelligence, evolving adversary tradecraft and enriched telemetry from across the enterprise to deliver hyper-accurate detections, automated protection and remediation, elite threat hunting and prioritized observability of vulnerabilities. Purpose-built in the cloud with a single lightweight-agent architecture, the Falcon platform delivers rapid and scalable deployment, superior protection and performance, reduced complexity and immediate time-to-value. CrowdStrike: We stop breaches.

About IBM

IBM is a leading global hybrid cloud and AI, and business services provider, helping clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs and gain the competitive edge in their industries. Thousands of governments and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM's hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently and securely. IBM's breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and business services deliver open and flexible options to our clients. All of this is backed by IBM's legendary commitment to trust, transparency, responsibility, inclusivity and service.

  • Agentic SOCCybersecurityThreat DetectionAI Security
News Disclaimer
  • Share