Case study access

This case study is password protected.

Enter the password to continue.

← Back to work Case Study 01 · Design Thinking · Product Strategy · Business Value · AI Workflow Design

Agentic SOC, watsonx AI Agents for Threat Triage & Intelligence

HTX's 24/7 Security Operations Centre was fielding up to 1,000 alerts a day, a number headed for 60,000 a month, while triage and threat intelligence work still moved by hand between QRadar and IBM Resilient. This is how a discovery workshop, a set of watsonx AI agents, and a business value model gave HTX a phased, fundable roadmap to scale the SOC without scaling headcount.

ClientHTX, Singapore
RoleLead UX Designer, Design Thinking, Product Strategy, Business Value
PartnersIBM watsonx · QRadar & Resilient (SOAR)
StageDiscovery workshop to Business Value Review
Three watsonx agents, Triage, Investigate and Threat Intel, overview
The problem

18 analysts, 1,000 alerts a day, and a 2.5x wave coming.

HTX runs Home Team's 24/7 Security Operations Centre on IBM QRadar (SIEM) and IBM Resilient (SOAR), 12 analysts and 6 SOC managers, working in teams of two analysts and one manager across a 2-on/2-off, 12-hour shift rotation.

QRadar was already generating around 1,000 offenses a day, 20,000 to 30,000 a month, and heading toward 60,000 a month. Every offense still moved through the same manual chain: cluster into parent/child cases, decide high or low risk, email or raise a ticket, wait on validation, close the case.

A single high-priority case took up to 35 minutes to triage. Low-priority cases were reviewed in a weekly batch that ran to 8 hours. Reading a threat advisory and turning it into a research report, extracting IOCs, mapping MITRE ATT&CK techniques, checking detection coverage, took up to 6 hours.

The real pressure was ahead of them: offense volume was projected to grow 2.5x by 2027, pushing total triage and investigation hours from 3,300 a year to 6,200, the equivalent of needing two more analysts just to hold the line.

Alert triage automation Threat intelligence SOC workflow design watsonx Agentic AI
My role

Facilitator, workflow designer, and the numbers behind the pitch.

Design thinking facilitator, ran the discovery workshop with HTX's Threat Management Team, working stage by stage through a threat hunt to surface five needs statements and the capabilities each one pointed to.

Product strategist, shaped the phased roadmap: a Triage Agent scoped and demoed for Phase 1, with an Investigation Agent and Threat Intel Agent designed and sequenced for future phases once TIP integration was ready.

AI workflow designer, mapped the as-is and to-be process for every agent, tracing each manual QRadar/Resilient step to the point where watsonx could take over, and where a human still needed to stay in the loop.

Business value lead, built the workload and financial model that translated minutes saved per case into SGD productivity, risk-reduction and operational value, iterating it directly against stakeholder feedback.

I worked closely with a cross-functional team throughout, as I do on every engagement, AI engineers on what watsonx could reliably automate, Sales on how the business value model needed to land with HTX's leadership, IBM technology leaders on scope and sequencing, and project managers on keeping the discovery-to-demo timeline on track.

The process

From a whiteboard of pain points to a funded roadmap.

01

Discovery Workshop

Facilitated a stage-by-stage session with HTX's Threat Management Team, capturing five needs statements and their to-be capabilities.

02

As-Is Mapping

Traced the existing QRadar → Resilient triage and threat intel workflows end to end, timing every manual step.

03

Agent Design

Designed three watsonx agents, Triage, Investigate, Threat Intel, and where each one replaces or augments a manual step.

04

Business Value Modeling

Built the workload and financial model translating time saved into SGD productivity, risk and operational value.

05

Demo & BV Review

Presented the watsonx demonstration and Business Value Review to HTX's SOC managers and technology leadership.

Research

Five needs statements, one throughline.

Every stage of the workshop circled back to the same need: HTX's Threat Management Team needs a way to automate repetitive data collection, query building and initial anomaly screening, so they can free up threat hunter time from manual triage, combat alert fatigue, and run more frequent, deeper proactive hunts.

Coming up with plausible hypotheses from limited info
Identifying attack patterns across large log databases
Designing accurate rules is manual and needs constant tuning
Hard to simulate an attacker to test new rules
Queries take too long to run over long time periods
Presenting results to technical vs. non-technical stakeholders
Triage Agent

From an inbox and a spreadsheet to an autonomous first pass.

The Triage Agent absorbed the case that ate the most analyst time: reading an offense, deciding if it was noise, and either closing it or escalating it. watsonx now clusters related offenses into parent/child cases, classifies each one against HTX's own risk checklist plus QRadar's magnitude score, and writes the report explaining why.

Threat Intel & Investigation Agent

Turning a threat advisory into "are we affected?" in minutes.

Designed for Phase 2, pending threat intelligence platform integration, these agents take a raw advisory, PDF, email, STIX, free text, and automatically extract IOCs and CVEs, run the AQL query across 90 days of QRadar logs, map attacker TTPs to MITRE ATT&CK, flag detection coverage gaps, and generate the research report analysts used to write by hand.

Business value

Turning minutes saved into a number HTX's leadership could act on.

Productivity. High-priority triage dropped from up to 35 minutes to as little as 8–15, and low-priority batch review from 8 hours a week to around 4. IOC extraction fell from up to 30 minutes to 3–5, and threat research reports from 6 hours to 3.

Modelled across HTX's 2026 case volume, that recovers roughly 3,700–5,000 analyst hours a year, worth an estimated SGD 180,000–210,000; at 2027's projected 2.5x volume, it scales to over 7,000 hours a year and roughly SGD 310,000–440,000, without adding headcount.

Risk & operations. Faster, more consistent triage also lowers dwell time and the odds of a missed detection. I modelled this at roughly SGD 775,000 in single-event risk value across breach, dwell-time, regulatory and reputational exposure, alongside real gains in detection coverage and faster ramp-up time for junior analysts.

I built this model in close partnership with Sales, revising the assumptions, shift structure, overtime, manager hours freed, each time HTX or IBM stakeholders challenged a number, so the business case held up under scrutiny.

75%
Faster high-priority triage, up to 35 minutes down to 8–15
80%
Faster IOC extraction from a threat advisory, up to 30 minutes down to 3–5
50%
Faster threat research report generation, 6 hours down to 3
1,851
Analyst hours recovered per year at 2026 volume, without adding headcount

Figures are best-effort estimates modelled from HTX's stated workload and synthetic data in a controlled demonstration environment; actual results depend on production volumes, data quality and analyst adoption.

Outcome

What HTX walked away with.

01
A demoed, working Triage Agent, auto-clustering, risk classification and bulk-closure with an audit-ready report, built on watsonx over live QRadar/Resilient workflows
02
A phased roadmap, Investigation and Threat Intel agents scoped for Phase 2, covering AQL generation, MITRE ATT&CK mapping and automated advisory parsing
03
A Business Value Review, a workload and financial model HTX's leadership could use to weigh automation against the cost of standing still
Next case study

Figma Asset Library, Agent Assistant & Content Summarisation →