Figma's AI Agents Resolve Threats 70% Faster

TL;DR: Figma is using custom AI agents to automate its security incident response. The system helps analysts resolve security alerts 70% faster, providing a practical model for other tech companies to improve their own security operations.
Key facts
- Category
- AI
- Impact
- High
- Published
- Source
- CIO.com
Full summary
Figma's security team built AI agents to automate incident response, cutting resolution times for security alerts by a remarkable 70%.
While many organizations are still cautiously exploring how to deploy AI safely, design software company Figma has implemented a powerful and practical solution within its security team. According to reporting from CIO.com, Figma has developed custom AI agents that are dramatically speeding up its response to security threats. These agents have reduced the mean time to resolution for specific types of security alerts by an impressive 70%. This isn't a theoretical exercise; it's a real-world application of AI that directly enhances the company's security posture. By automating the initial, time-consuming stages of incident investigation, Figma is providing a compelling case study for how AI can serve as a powerful force multiplier for overburdened security teams, turning a flood of data into actionable intelligence much more quickly.
The system works by deploying specialized AI agents to handle the repetitive, data-gathering work that typically consumes a security analyst's day. When a security tool generates an alert, an AI agent is automatically triggered to begin the investigation. Instead of a human analyst having to manually pivot between different systems, the agent programmatically collects relevant context. It can query activity logs, check user permissions, analyze network traffic data, and cross-reference information with external threat intelligence feeds. The agent then synthesizes all of this disparate information into a concise, human-readable summary that highlights the key findings and potential risks. This summary is then handed off to a human analyst, who can make a final decision with a complete picture already assembled for them, allowing them to bypass hours of manual toil.
This matters deeply for any organization with a dedicated security function, from startups to large enterprises. Security Operations Centers (SOCs) are chronically plagued by the problem of “alert fatigue,” where analysts are overwhelmed by the sheer volume of alerts, many of which are false positives. This constant noise makes it difficult to spot genuine threats in a timely manner. Figma’s approach directly tackles this issue. The AI agents act as an intelligent filter and assistant, handling the high-volume, low-complexity triage and allowing human experts to focus their cognitive energy on complex, novel, and genuinely critical threats. This not only leads to faster response times, which can be crucial in containing a breach, but also improves job satisfaction for security analysts by offloading the most monotonous aspects of their work.
The business impact of this strategy is significant and provides a clear blueprint for other technology leaders. The 70% efficiency gain represents a massive return on investment, allowing a security team to scale its capabilities and effectively monitor a growing infrastructure without needing to proportionally increase headcount. This case study moves the conversation about AI in security beyond simple threat detection models and into the realm of active response and automation. For founders and CTOs, the practical takeaway is that this technology is becoming increasingly accessible. Using existing large language model APIs and open-source frameworks, even smaller teams can begin to build their own specialized agents to automate well-defined, repetitive tasks. Starting with a narrow use case, like Figma did, is the key to building confidence and demonstrating value quickly.
Looking ahead, the capabilities of these AI security agents are set to expand rapidly. The next logical step is to grant them more autonomy, allowing them to move from investigation to taking direct containment actions, such as isolating a compromised device from the network or temporarily disabling a user account. This evolution, however, brings the challenge of governance and safety into sharp focus. As agents become more powerful, the potential for error increases, making robust testing, oversight, and human-in-the-loop safeguards absolutely critical. The industry will need to balance the immense efficiency gains with the risks of over-automation, ensuring that these powerful tools remain under firm human control as they become an integral part of modern cybersecurity.
Why it matters
Figma's success provides a concrete blueprint for how AI can alleviate the chronic issue of alert fatigue in security teams. By automating initial investigations, it allows human analysts to focus on critical threats, drastically reducing response times and overall risk.
Business impact
This case study demonstrates a clear and compelling ROI for investing in AI for security operations. A 70% efficiency gain allows security teams to scale their capabilities without a proportional increase in headcount, directly improving a company's security posture.
Tags
Related on Notifire
Related stories
Primary source: CIO.com