Figma's AI Agents Transform Security Operations and Efficiency
Figma's innovative use of AI agents for security operations showcases a pivotal shift in how tech companies are leveraging artificial intelligence to tackle cybersecurity challenges, achieving remarkable efficiency gains.
Key Facts
- Figma's AI agents cut alert resolution time by 70%, enhancing operational efficiency significantly.
- Discovery of 100+ vulnerabilities highlights gaps in traditional security tools, exposing market risks.
- 20% reduction in on-call pages indicates improved resource allocation and employee satisfaction potential.
- Achieving 80% precision in code review within a month suggests strong competitive advantage in security.
- Strategic focus on precision over recall may redefine industry standards for security effectiveness.
Summary
Summary
Figma, a software company, faced challenges in efficiently investigating security alerts and managing incidents. They implemented AI agents to assist their security team, which resulted in a 70% reduction in resolution time for complex alerts and a 20% decrease in on-call pages.
Background
Figma operates in the software industry and has a robust engineering team focused on security. Before deploying AI agents, their security team struggled with the volume of alerts and the time-consuming nature of incident investigations, which hindered their ability to respond effectively.
Challenge
The primary challenge was the lengthy resolution times for complex security alerts, which placed a strain on the security team and led to increased on-call pages. The team sought to streamline the investigation process and improve their response efficiency.
Solution
Figma developed AI agents that leverage a security system built on Panther SIEM. These agents investigate alerts, check audit logs across multiple platforms (including AWS, Okta, GitHub, and GCP), and prepare code fixes. They utilize a model like Claude Opus and incorporate memory types that enhance their investigative capabilities over time. The agents also ensure safety controls are in place, such as defaulting agent-created pull requests to draft status.
Results
The implementation of AI agents led to a 70% reduction in resolution time for complex alerts and a 20% decrease in on-call pages by lowering the severity of some alerts. The agents identified over 100 previously unknown vulnerabilities, including two critical flaws, and improved the detection of known bugs by about 30%. Additionally, there was a reported 50% reduction in certain coding errors due to automated guidance.
Key Insights
One key takeaway is the importance of improving precision before recall when deploying AI solutions. This approach may seem counterintuitive, but focusing on precision first can lead to more effective outcomes. Additionally, the balance between automation and human oversight remains crucial as AI agents take on more responsibilities.
Customer Testimonial
"The specifics depend on your company size, the risks you face, and the feedback loops you already run. But one main lesson is to improve precision before recall." — Matthew Sullivan, formerly a security engineer at Figma and now at Nition.
Entities Mentioned
Companies
Products
Technologies
People
Key Concepts
Definitions
- AI agents
- Automated systems that assist in security tasks by learning from past incidents and reducing manual workload.
- Panther SIEM
- A security information and event management system used to investigate alerts and check audit logs.
- osquery
- An open-source tool that allows querying of computers for security and system information using SQL.
- alert triage
- The process of investigating and prioritizing security alerts to determine their severity and necessary actions.
- memory types
- Different categories of memory used by AI agents to improve their effectiveness in investigations over time.
Use Cases
- →Investigating security alerts
- →Searching past incidents
- →Preparing code fixes
- →Reducing resolution time for complex alerts
- →Detecting vulnerabilities
- →Improving coding precision
Frequently Asked Questions
How do AI agents improve security investigations?
AI agents learn from previous investigations, which helps reduce repetitive work and allows engineers to resolve complex alerts significantly faster.
What role does human oversight play in using AI agents?
While AI agents automate many tasks, human review and strict controls are essential to ensure safety and accuracy in security operations.
What technologies does Figma use for its AI agents?
Figma's AI agents utilize technologies such as Panther SIEM, AWS Bedrock, Amazon Kendra, and osquery to enhance their investigative capabilities.
What are the benefits of using AI agents in security?
AI agents can significantly reduce resolution times for alerts, improve detection of vulnerabilities, and lower the number of on-call pages for engineers.
What challenges do AI agents face?
AI agents are not perfect and can be tricked by malicious inputs, highlighting the need for ongoing human oversight and the evolution of their roles.