Welcome.AIWelcome.AI
    Skip to content
    AI Agents

    Figma's AI Agents Transform Security Operations and Efficiency

    Figma's innovative use of AI agents for security operations showcases a pivotal shift in how tech companies are leveraging artificial intelligence to tackle cybersecurity challenges, achieving remarkable efficiency gains.

    infoq.comSeptember 6, 20262 min read

    Key Facts

    • Figma's AI agents cut alert resolution time by 70%, enhancing operational efficiency significantly.
    • Discovery of 100+ vulnerabilities highlights gaps in traditional security tools, exposing market risks.
    • 20% reduction in on-call pages indicates improved resource allocation and employee satisfaction potential.
    • Achieving 80% precision in code review within a month suggests strong competitive advantage in security.
    • Strategic focus on precision over recall may redefine industry standards for security effectiveness.

    Summary

    Summary

    Figma, a software company, faced challenges in efficiently investigating security alerts and managing incidents. They implemented AI agents to assist their security team, which resulted in a 70% reduction in resolution time for complex alerts and a 20% decrease in on-call pages.

    Background

    Figma operates in the software industry and has a robust engineering team focused on security. Before deploying AI agents, their security team struggled with the volume of alerts and the time-consuming nature of incident investigations, which hindered their ability to respond effectively.

    Challenge

    The primary challenge was the lengthy resolution times for complex security alerts, which placed a strain on the security team and led to increased on-call pages. The team sought to streamline the investigation process and improve their response efficiency.

    Solution

    Figma developed AI agents that leverage a security system built on Panther SIEM. These agents investigate alerts, check audit logs across multiple platforms (including AWS, Okta, GitHub, and GCP), and prepare code fixes. They utilize a model like Claude Opus and incorporate memory types that enhance their investigative capabilities over time. The agents also ensure safety controls are in place, such as defaulting agent-created pull requests to draft status.

    Results

    The implementation of AI agents led to a 70% reduction in resolution time for complex alerts and a 20% decrease in on-call pages by lowering the severity of some alerts. The agents identified over 100 previously unknown vulnerabilities, including two critical flaws, and improved the detection of known bugs by about 30%. Additionally, there was a reported 50% reduction in certain coding errors due to automated guidance.

    Key Insights

    One key takeaway is the importance of improving precision before recall when deploying AI solutions. This approach may seem counterintuitive, but focusing on precision first can lead to more effective outcomes. Additionally, the balance between automation and human oversight remains crucial as AI agents take on more responsibilities.

    Customer Testimonial

    "The specifics depend on your company size, the risks you face, and the feedback loops you already run. But one main lesson is to improve precision before recall." — Matthew Sullivan, formerly a security engineer at Figma and now at Nition.

    Entities Mentioned

    Companies

    Figma
    Nition
    Wiz
    OpenAI

    Products

    Panther SIEM
    AWS Bedrock
    Amazon Kendra
    Tines
    Snowflake

    Technologies

    AI agents
    osquery
    Slack
    SQL

    People

    Matthew Sullivan
    Brad Girardeau

    Key Concepts

    AI agents
    security investigations
    alert triage
    memory types
    vulnerability detection
    human oversight
    automation
    precision vs recall

    Definitions

    AI agents
    Automated systems that assist in security tasks by learning from past incidents and reducing manual workload.
    Panther SIEM
    A security information and event management system used to investigate alerts and check audit logs.
    osquery
    An open-source tool that allows querying of computers for security and system information using SQL.
    alert triage
    The process of investigating and prioritizing security alerts to determine their severity and necessary actions.
    memory types
    Different categories of memory used by AI agents to improve their effectiveness in investigations over time.

    Use Cases

    • Investigating security alerts
    • Searching past incidents
    • Preparing code fixes
    • Reducing resolution time for complex alerts
    • Detecting vulnerabilities
    • Improving coding precision

    Frequently Asked Questions

    How do AI agents improve security investigations?

    AI agents learn from previous investigations, which helps reduce repetitive work and allows engineers to resolve complex alerts significantly faster.

    What role does human oversight play in using AI agents?

    While AI agents automate many tasks, human review and strict controls are essential to ensure safety and accuracy in security operations.

    What technologies does Figma use for its AI agents?

    Figma's AI agents utilize technologies such as Panther SIEM, AWS Bedrock, Amazon Kendra, and osquery to enhance their investigative capabilities.

    What are the benefits of using AI agents in security?

    AI agents can significantly reduce resolution times for alerts, improve detection of vulnerabilities, and lower the number of on-call pages for engineers.

    What challenges do AI agents face?

    AI agents are not perfect and can be tricked by malicious inputs, highlighting the need for ongoing human oversight and the evolution of their roles.

    Where AI Leaders Stay Informed

    The latest AI intelligence, case studies, and research — delivered to your inbox every week.

    Free to read. Unsubscribe anytime.