Lenovo's Security Operations Center analyzes more than 15 billion computing events daily across its global network. The team must filter those events down to roughly 25 critical issues that demand expert attention-a task made harder as the company's threat surface doubled in five years while attacks grew faster and more complex.
The SOC protects 140,000 devices used by 80,000 people across 150 countries. Analysts previously had to manually review device status, file hashes, and network information for each alert. Fragmented workflows across security tools slowed investigations and increased the risk of human error.
Putting its own AI to the test
Through its Lenovo Powers Lenovo program, the company turned its global SOC into a proving ground for a new AI-powered security model. The objective was straightforward: cut manual alert review while giving analysts better context to spot and respond to real threats.
An intelligent data-ingestion platform now consolidates signals from across Lenovo's security environment and reduces noise before alerts reach analysts. AI agents triage incoming alerts, resolve lower-level incidents, and enrich cases that need human attention with relevant context and suggested next steps. The model does not replace cybersecurity experts. It directs their time toward incidents where their judgment matters most.
"If AI is essential to keeping pace with the threat landscape, then customers rightly expect us to use our own AI capabilities to protect Lenovo before we ask them to trust us with their own enterprise," said Thirumalai Seshadri Krishnakumar, Director of Advanced Service Delivery at Lenovo.
Iterating with the people who do the work
Lenovo did not deploy the model all at once. Over several months, the team worked iteratively with SOC analysts and cybersecurity partners to test and refine AI outputs for different alert types. As accuracy improved and analyst confidence grew, the new workflows moved into day-to-day operations. Alert-specific playbooks guided consistent AI-supported decisions and created a foundation for extending the approach to additional security processes.
Real-world deployment required changes beyond technology. Lenovo upskilled and cross-skilled employees, adapted existing processes, and integrated AI capabilities into the SOC's operating environment. Strict controls were established to segregate, mask, and log data, helping protect sensitive information throughout AI-supported workflows. The result is a model shaped by the people who use it-the AI learns from Lenovo's cybersecurity expertise while analysts retain responsibility for complex decisions.
Faster detection, lower costs
Information that once took an analyst 45 to 60 minutes to investigate can now be assembled in seconds. Lenovo reduced mean time to detect an attack by 87.5%, from four hours to 30 minutes, while improving malware and attack identification accuracy by 20 times. More than 80% of low-level incidents are now resolved without analyst intervention.
"By leveraging AI to shift SOC processes from reactive to proactive, our mean time to resolution has been reduced from 96 hours to just 24 minutes," said Rakshit Ghura, Vice President and General Manager, Digital Workplace Solutions at Lenovo. "It also gives Lenovo a more resilient, scalable security model for a threat landscape that will continue to evolve."
The changes helped reduce cybersecurity total cost of ownership by 60%. Lenovo is also using insights from alerts and reports to identify patterns, refine policies, and improve security operations over time. The company is now extending AI-powered workflows to additional threats, including phishing and brute-force login attempts.
By acting as customer zero, Lenovo gained firsthand experience building, governing, and operating AI-supported security at global scale. Those lessons inform the company's AI-enhanced cybersecurity services, combining technology, processes, and expert oversight. The experience also contributes to the Lenovo AI Library and Lenovo Hybrid AI Advantage, helping other organizations move from experimentation to measurable outcomes. For operations teams evaluating AI for Operations, the SOC transformation offers a concrete reference point for what scaled deployment can look like. Security-focused professionals can explore related skill pathways through the AI for Cybersecurity Analysts learning path.
Why this matters for operations professionals
Lenovo's results show a measurable shift from reactive triage to proactive threat resolution. For operations leaders, the numbers are specific: 87.5% faster detection, 20x accuracy improvement, and a 60% reduction in total cost of ownership. The rollout also demonstrates that deploying AI in security operations requires iterative testing with the analysts who will use it, not just a technology swap. Upskilling staff, adapting processes, and building strict data controls were all part of making the model work at scale-a pattern that applies to any operations function adopting AI-supported workflows.
Your membership also unlocks: