Figma Cuts Security Alert Time by 70% With AI

TL;DR: Figma is now using custom AI agents to investigate and resolve security alerts, cutting resolution time by 70%. The system automates tedious data collection, allowing security engineers to focus on critical decisions and real threats.
Key facts
- Category
- AI
- Impact
- High
- Published
- Source
- CSO Online
Full summary
Figma is using custom AI agents to investigate security alerts, cutting its incident response time by an impressive 70%.
Design software giant Figma has successfully deployed a custom system of AI agents to streamline its security operations, according to a report from CSO Online. The initiative has yielded a dramatic 70% reduction in the mean time to resolution (MTTR) for security alerts. This real-world application of AI moves beyond theoretical discussions and provides a concrete example of how targeted automation can significantly enhance a security team's efficiency and effectiveness. By automating the initial, data-intensive phases of incident response, Figma's security engineers can now bypass hours of manual work and focus their expertise on analysis and strategic decision-making. The company’s success serves as a powerful case study for other technology firms looking to leverage AI to combat the ever-increasing volume of security threats and alerts that modern enterprises face.
Figma's system is not a single, monolithic AI but rather a coordinated team of specialized AI agents. When a new security alert is generated, an orchestrator agent first assesses the alert and delegates it to the most appropriate specialist agent for the task. This specialist agent then autonomously queries a wide range of internal data sources, such as application logs, user directories, and device management systems, to gather all relevant context surrounding the potential incident. It synthesizes this disparate information into a concise, human-readable summary, identifies the key entities involved, and even suggests a preliminary course of action. This complete investigative package is then delivered to a human analyst in their security information and event management (SIEM) platform, transforming a process that once took hours of manual data collection into a task that takes just a few minutes.
This development is highly significant for security teams, which are almost universally understaffed and overwhelmed by alert fatigue. A large percentage of security alerts are ultimately benign, but each one must be investigated, leading to a massive drain on the time and attention of highly skilled analysts. Figma's AI-driven approach effectively automates the burdensome triage process, acting as a powerful force multiplier for its human team. This allows expensive engineering talent to be reallocated from repetitive, low-value investigation tasks to high-impact work like threat hunting, system hardening, and responding to genuine, complex incidents. For CTOs and engineering leaders, it provides a practical blueprint for using AI to improve operational efficiency and strengthen security posture simultaneously, demonstrating a clear return on investment.
From a broader industry perspective, Figma’s implementation signals a strategic shift in how enterprises are adopting AI. Instead of waiting for a perfect, all-in-one commercial AI security product, the company built a targeted solution that integrates deeply with its existing tools and workflows. This bespoke approach delivers tangible value much faster and de-risks AI adoption by focusing on a specific, high-friction business process. It highlights the move from general-purpose, chat-based AI assistants toward specialized, autonomous agents designed to execute complex tasks within an enterprise environment. This model of building small, focused AI agents to solve specific internal problems is likely to become a dominant pattern for corporate AI adoption, especially in critical functions like security, finance, and operations.
Looking ahead, the evolution of such systems will likely focus on increasing their autonomy and building deeper levels of trust. While Figma's agents currently prepare information for a human decision-maker, future iterations could be empowered to automatically resolve certain classes of low-risk, high-confidence alerts without human intervention. This would further reduce the burden on security teams and accelerate response times. As more companies follow this model, we can expect to see the emergence of new best practices, open-source frameworks, and commercial platforms designed to simplify the creation and management of these internal AI agent workforces. The primary challenge will be developing the robust safety mechanisms and transparent oversight required to confidently delegate more critical tasks to autonomous systems.
Why it matters
This approach automates the tedious and time-consuming process of security alert triage, a major bottleneck for most security teams. It frees up expensive engineering talent to focus on genuine threats instead of chasing false positives, providing a practical blueprint for improving security efficiency with AI.
Business impact
Figma's case study proves that custom, in-house AI agents can deliver significant ROI by targeting specific operational pain points. It signals a move away from general-purpose AI tools toward specialized agents that integrate with existing enterprise systems, offering a faster, more tangible path to value for companies looking to leverage AI.
Tags
Related on Notifire
Related stories
Primary source: CSO Online