Brian Sims
Editor

e2e-assure’s Cumulo SOC platform safeguards IT and OT environments

SECURITY OPERATIONS Centre (SOC)-as-a-Service provider e2e-assure has announced the launch of the updated Cumulo, the UK’s only sovereign, Artificial Intelligence (AI)-first, IT/operational technology (OT) connected SOC platform designed to help organisations defend against a new generation of AI-driven threats.

The UK-owned and developed proprietary platform answers the recent call by GCHQ director Anne Keast-Butler for “a new national cyber defence capability that will hardwire cutting-edge agentic AI into machine-speed cyber defence” by creating a truly sovereign solution for e2e-assure’s SOC services.  

With AI natively integrated throughout the platform, the technology can build context continuously as security data is generated, taking detection and response “to new levels” and facilitating “groundbreaking” defence capabilities. The SIEM remains the system of truth. A deterministic, evidence-grade record of every event, while AI runs as a parallel capability on top of it.

Cumulo introduces the ‘Zero Day’ SOC, meaning that live/new threat intelligence can be applied immediately as detection rules, thereby eliminating the risk from emerging threats. It combines predictive modelling capability with sovereign local AI models and expert human oversight for millisecond detection of known and emerging indicators of compromise. This is performed while ensuring security teams remain at the core of every decision and maintaining a ‘human in the loop’ structure to avoid AI autonomy.

AI-first operating system

“Cumulo represents a shift away from traditional SOC and SIEM environments that are largely human-centric and reactive because they rely on sequential alert triage and retrospective investigation,” said Rob Demain, CEO of e2e-assure. “Instead, Cumulo uses an AI-first security operating system.”

Demain continued: “Threats are now moving faster than human-led workflows can keep pace with, leaving security teams struggling. At the same time, many AI approaches in security remain constrained by legacy architectures that force them to rebuild context after the fact. We built Cumulo to change that narrative by continuously building understanding as data is generated, while in parallel keeping expert analysts at the centre of decision-making.”

The Cumulo platform provides a continuously maintained digital twin of each customer environment via passive discovery across IT and operational technology systems, enabling safe attack simulation, risk identification before exploitation and immutable preservation of analytical integrity. This is particularly valuable within operational technology and critical infrastructure environments where live testing is often impractical or otherwise carries unacceptable operational risk.

The customer-dedicated local large language models are deployed within sovereign environments and trained on each organisation’s specific environment to enable accurate and context-aware reasoning that reflects the realities of each customer estate.

Given that inference occurs within customer-controlled infrastructure, organisations retain full sovereignty over sensitive security data and reduce the reliance on external cloud AI services. This sovereignty is not only a compliance consideration, but for industries such as Critical National Infrastructure (CNI), it’s an operational necessity.

Defensive AI capabilities that depend on third party infrastructure can be subject to disruption or access restrictions beyond an organisation’s control. By keeping models local, organisations ensure their defensive capability remains available regardless of external circumstances.

Defence in a crisis 

“In terms of those organisations responsible for CNI and essential services such as energy, water, transport, telecommunications and Government operations,” continued Rob Demain, “resilience isn’t just about identifying threats faster. It’s also about ensuring the ability to defend remains intact during a crisis.”

Further, Demain explained: “As more security capabilities move into the cloud, questions around sovereignty, dependency and operational continuity continue to mount. For organisations operating in regulated or high-dependence environments, reliance on external AI infrastructure can introduce risks around data residency, transparency and continued access to critical defensive capabilities. Cumulo addresses these challenges by keeping sensitive operational knowledge within customer-controlled environments, reducing exposure to external disruption and helping organisations to maintain visibility and cyber defence capability even during major incidents, connectivity outages or wider infrastructure disruption.”

Importantly, Cumulo also introduces a layered AI architecture that separates sensitive operational reasoning from broader intelligence and research capability. A local model layer handles environment-specific detection and analysis, a security intelligence layer aggregates and correlates threat data at scale and a frontier model layer is used for non-sensitive enrichment and broader analytical tasks. This structure ensures that sensitive data remains contained, while still enabling advanced AI capability where appropriate, duly supporting both compliance and performance requirements.

In order to address the growing volume of security data, Cumulo uses multiple AI models that cross-check every investigation from different perspectives, building an auditable view of each alert. This is known as the Cumulo Analyst Helper (CAH). An anti-hallucination layer validates findings against threat intelligence and deterministic detection engines before results reach an analyst.

The customer’s own security and operations experts, who understand their estate and risk appetite, remain in the loop throughout. The platform carries the volume such that individuals are free for the high-value judgement.

Multi-tier product model 

Cumulo is being introduced through a multi-tier product model designed to support different stages of security maturity and organisational need.

Standard delivers a proactive SOC capability, providing AI-driven investigation and autonomous threat hunting that detects by behaviour rather than signature alone, alongside threat intelligence, centralised reporting and compliance dashboards.

Enterprise extends the platform into a predictive SOC, adding unified IT and OT monitoring, digital twin capability, live compliance dashboards and advanced cross-environment correlation for complex environments requiring deeper operational insight. This predictive model continually stress-tests an evidence-accurate twin of the estate, ranks and costs the fixes and closes the gaps before a real attacker arrives.

*Further information is available online at www.e2e-assure.com/cumulo

Company Info

Western Business Media Limited

Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM

Login / Sign up