Figma Uses AI Agents to Resolve Threats 70% Faster

TL;DR: Figma is now using custom AI agents to automate parts of its security operations, leading to a 70% faster resolution time for incidents. The move provides a powerful, real-world case study for other tech companies.
Key facts
- Category
- AI
- Impact
- High
- Published
- Source
- Hacker News
Full summary
Figma is using AI agents to resolve security threats 70% faster, offering a new playbook for security teams everywhere.
Design software giant Figma has successfully integrated artificial intelligence agents into its security operations, achieving a remarkable 70% reduction in the time it takes to resolve security incidents. This initiative serves as one of the first high-profile, real-world examples of AI agents delivering significant, measurable efficiency gains in a critical business function. By automating key parts of its threat detection and response workflow, Figma has created a powerful model for how modern technology companies can leverage AI to strengthen their security posture while managing ever-increasing alert volumes. The success of this program moves the conversation around AI in security from theoretical potential to practical application, providing a concrete benchmark for the rest of the industry.
The core of Figma's new system involves using AI agents as a first line of defense. When a potential security alert is triggered by one of their monitoring systems, an AI agent automatically begins the initial investigation. This process, known as triage, typically involves gathering context, enriching the alert with data from other internal and external sources, and performing preliminary analysis to determine the alert's credibility and severity. The agent can sift through logs, cross-reference IP addresses with threat intelligence feeds, and analyze user behavior patterns far faster than a human analyst. Once its initial investigation is complete, the agent presents a concise summary with recommended actions to a human security engineer, who can then focus their expertise on complex decision-making and remediation rather than on repetitive data collection.
This development is highly relevant for a wide range of technology leaders and practitioners. For Chief Technology Officers and security executives, Figma's 70% improvement metric provides a compelling business case for investing in AI-driven security automation. It demonstrates a clear path to improving a team's capacity and effectiveness without a proportional increase in headcount. For security teams on the front lines, this approach offers a solution to the pervasive problem of alert fatigue, where analysts are too overwhelmed by the sheer volume of alerts to investigate each one thoroughly. By filtering out the noise and accelerating triage, AI agents allow human experts to focus their limited time on the most critical threats, reducing the risk of a serious incident being missed.
The broader business impact of this case study is significant. It signals a major shift in the cybersecurity landscape, moving from human-centric security operations centers (SOCs) to a hybrid model where humans and AI agents collaborate. This will likely accelerate the adoption of AI-native security tools and put pressure on companies that rely on traditional, manual processes to modernize their approach. As more organizations follow Figma's lead, we can expect to see a new competitive front open up, where a company's security posture is increasingly defined by its ability to effectively deploy automation. This trend will also reshape the cybersecurity job market, increasing the demand for professionals who can build, manage, and oversee these sophisticated AI systems.
Why it matters
Figma's success provides a concrete, high-profile case study demonstrating that AI agents can dramatically improve security operations efficiency. For security teams, it offers a new playbook for tackling alert fatigue and reducing response times.
Business impact
This sets a new industry benchmark for AI-driven security, pressuring other companies to adopt similar technologies to remain competitive in risk management. It signals a shift from manual security processes to automated, AI-native operations.
Tags
Related on Notifire
Related stories
Primary source: Hacker News