Beyond Co-Managed SIEM: Duck Creek's Blueprint for a Modern, Scalable SOC
How Duck Creek replaced Tier 1 triage with AI agents and freed its analysts for higher-value work.
The CISO
Trained to find the inefficiency
Benjamin Dulieu came to the CIO role by an unusual route, starting his career as a Marine. The traits that defined him then carry through to how he leads security now: agility, flexibility, and an instinct for spotting inefficiency and acting on it. The military gave him a career full of moments where he surprised himself with what he could do. AI is the latest.
Starting in his personal life, Benjamin began experimenting with how AI could increase his efficiency. From helping to plan his wife’s birthday to a personal trainer agent tracking his progress, AI was becoming the tool he reached for by default. It enabled him to consume information much faster and leave behind manual work that, frankly, he didn’t care to do anyway.
The Challenge
This is a fundamentally different type of architecture
He clearly saw how AI could change the way security operations ran at Duck Creek. Duck Creek’s software backs insurance companies, so they are processing enormous data volumes across disparate systems. They work solely in the cloud, so cost management sits at the center of every engineering decision. The cost of the SIEM was going up, but the reward of risk mitigation wasn’t matching these rising costs. There was too much manual oversight and limited scalability.
Not only were the monetary resources strained, but the SOC analysts were feeling the pressure as well. Something had to be done, and with AI coming on the scene, Benjamin knew that this was the train they had to board, or risk being left behind. Their team needed to move away from a centralized SOC to free the analysts from the benign alerts that they were processing daily.
The Approach
Agents as the connective tissue
Benjamin’s goal with integrating AI was to create a modern, scalable SOC that can evolve with the business and the threat landscape. He wanted to replace repetitive Tier 1 work with intelligent automation and AI insight for faster detection, clearer visibility, lower costs. Most importantly, he wanted to free his analysts for threat hunting, engineering, and strategy, the work that they came to security to do. Instead, agents would report to other agents as points of connection, pushing the low-value alerts (password resets, brute force) to agents and cutting logging costs.
One of the obstacles he faced as he pushed the organization to lean into AI was that he overestimated everyone else’s usage. He realized that this would not only be a technological shift but a cultural shift as well. The goal shifted to include educating his people on how to flex the AI and showing them how powerful this tool could be, giving others moments of clarity.
Start with the basics, and they become believers
Start with the basics, show people, and they all become believers.
That belief shaped how he brought the rest of the company along. He invested in training, dozens of hours of it, and pushed his people to put the tools to work rather than admire them from a distance. He kept humans on the loop throughout, reserving them for the emotion, creativity, and strategy that agents cannot replicate, and framing every rollout around the why. When his own employees started arriving with their own ideas, he counted it as the real win.
"I don't feel like anything I said was utterly mind-blowing, but it just simplified it. Starting small."
For Benjamin, that is the whole game. The leaders who wield AI will define the next era of security, and the people who learn to wield it will define their own careers.
Your job won't be replaced by AI, but your job will be replaced by people who know how to use AI.
What comes next
Destroy the old ways, and build the new
The same technology reshaping Benjamin’s SOC is reshaping the other side of the fight. Adversaries are having their own moments of clarity, and the malicious uses of AI are arriving just as fast as the defensive ones. That raised the stakes on a change he already believed in.
The old security model was reactive, a team of incident responders waiting for something to break. Agents make a different approach possible: proactive, real-time, and capable of acting on what they see.
Getting there meant a harder decision than most transformations require. His instinct was to replace the old way outright and build something new in its place. This work is uncomfortable; it stresses people, and it asks a lot of a team. The return on that discomfort, measured in time and in dollars, is what makes it worth doing.
The conviction traces straight back to where he started his career. A Marine who learned to spot an inefficiency and act on it is now doing the same thing daily with AI, and pulling his team forward with him. The leadership job is not to do all the work, but to educate, inspire, and bring people along.
When asked what he would do with a magic wand and 25% of his time back, he would spend it making memories with his family and breaking the systems that need breaking.
Making memories and breaking systems.
See for yourself
Hear the full conversation
Benjamin Dulieu joined 7AI's Nate Burke and Lior Div to talk through moving away from a centralized SOC, freeing analysts from around-the-clock toil, and the leadership mindset shift behind rethinking security operations.