Automation

SoftBank Automates SOC Triaging With Cisco's Open-Source AI Model

The telecom giant deployed Foundation-sec-1.1-8B-Instruct on-premises to categorize suspicious software across 17 categories, achieving 90% workflow accuracy.

Omega Editorial· June 22, 2026· 3 min read

SoftBank Automates SOC Triaging With Cisco's Open-Source AI Model

SoftBank Corp. has automated a critical security operations workflow by deploying Cisco Foundation AI's open-source large language model on-premises, eliminating manual software categorization that previously consumed analyst time. The implementation demonstrates how organizations can achieve end-to-end automation in security operations while maintaining data privacy requirements.

Why it matters

Security teams face mounting alert volumes that strain analyst capacity. This deployment shows that specialized, compact AI models can automate complex categorization tasks without cloud dependencies or extensive retraining—a practical blueprint for enterprises balancing automation benefits against data sovereignty concerns.

The Workflow Challenge

SoftBank's Security Operations Center previously required analysts to manually categorize detected software, verify policies, and execute responses—a time-intensive process that diverted attention from high-priority investigations. While automation frameworks could handle policy checks and actions, software categorization remained stubbornly manual due to overlapping functionalities and organization-specific rules across thousands of potential applications.

The Foundation-sec-1.1-8B-Instruct model became the missing piece. SoftBank needed an on-premises solution due to data privacy requirements, ruling out cloud-based LLMs. The model's security-specific pre-training and compact 8-billion-parameter size offered operational cost advantages while outperforming general-purpose open-source alternatives on security tasks, according to details first reported by Cisco.

Achieving 90% Accuracy Through Prompt Engineering

The deployment required solving three technical challenges. First, output formatting: Cisco's team used few-shot examples in prompts to ensure the model returned only valid category names from the 17-option taxonomy, combined with validation loops that retry inference on malformed outputs.

Second, category disambiguation: The team embedded analyst logic into prompts to resolve overlaps. For instance, cloud storage like OneDrive should trigger "Forbidden Internet Service" policies rather than "File Sharing" despite sharing functionality. The prompt includes decision trees—"Does it output vulnerability reports? → Yes: Vulnerability Scanning"—to guide the model through ambiguous cases.

Third, handling edge cases: A catch-all "Undetermined" category exists for software outside the 16 defined types. The model initially over-assigned specific categories to avoid this label, creating false positives. SoftBank implemented preprocessing whitelists and postprocessing filters to catch organization-specific misclassifications.

The Foundation-sec-1.1-8B-Instruct model alone achieved 80.75% accuracy on a dataset of historical detections and manually verified labels—matching cloud LLM performance on the same task. Combined with rule-based systems and the new filtering steps, overall workflow accuracy reached 90%.

Beyond File Detection

SoftBank plans to extend this approach to intrusion detection system response automation. The model's on-premises deployment and security focus align with handling sensitive network data in these expanded workflows.

Hajime Uematsu, Director of Security Verification at SoftBank Corp., confirmed the model achieved over 85% accuracy at the workflow-action level during proof-of-value testing, with further improvement expected through preprocessing and policy controls.

These details were first reported by Cisco on the Automation Watch blog.

#security operations#llm deployment#cisco foundation ai#soc automation#on-premises ai#software categorization

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Automation

Automation· 2 min read

314e's Dexit Achieves 90% Accuracy on Healthcare EOB Automation

New module tackles one of revenue cycle management's most inconsistent document types with purpose-built extraction across 30+ data attributes.

Via Automation Watch · Aug 6, 2026
Automation· 4 min read

U.S. Job Cuts Drop 46% as AI-Driven Tech Layoffs Continue

July marked the lowest monthly layoff total in two years, while hiring plans jumped 25% year-over-year despite ongoing workforce restructuring.

Via AI Watch · Aug 6, 2026
Automation· 4 min read

AI Workflows Transform Plant Floors From Rule Followers to Decision Makers

Intelligent automation layers machine learning and agentic reasoning onto industrial systems, enabling real-time adaptation that traditional programmable controllers cannot match.

Via Automation Watch · Aug 6, 2026