
/Customer2 min read
How Bell Cyber Cut SOC Response Time by 83% With Tavily
Threat actors stopped working manually. So, Bell Cyber's security operations center (SOC) set up automations that cut response time from 30 minutes to under 5, across 100,000 monthly alerts, without adding a single analyst.
Meet Bell Cyber
Jawed Ahmad said, “You have to move to automation to fight automation,” then went and did it.
He’s Chief Technology and AI Officer at Bell Cyber, Canada’s leading security operations provider, and author of Augmented Security Operations. His SOC handles 80,000 to 100,000 alerts a month. Today, the investigation is often finished before an analyst opens the ticket, but it wasn’t always that fast.
Detection was never the problem
Bell Cyber could catch the threats. The bottleneck was everything that came after.
Before an analyst could send a case to a customer, they had to research it manually across vulnerability databases, threat intelligence platforms, vendor documentation, and historical incidents. Each investigation took 30 minutes, and customer follow-ups sent analysts back through the same loop.
“When there’s so many incidents coming in, the analyst can’t keep up,” Ahmad said.
Unfortunately, the threat actors were already using automation, so adding more analysts wasn’t enough to fight back with. The answer was to move faster.
“The threat actors are not doing it manually anymore,” Ahmad said. “They’re also using automations and have access to the latest and greatest models.”
Why Tavily
Bell Cyber already had the agent framework and guardrails in place, but it needed a research layer that could keep up. After testing numerous providers, the team chose Tavily for three reasons:
- Built for agents. Its output went directly into Bell Cyber’s agents without translation, parsing, or extra glue code. Ahmad said Tavily “gave us an output that was easily consumable by our AI agents.”
- Citations by default. In cybersecurity, an answer needs to show its work. Tavily gave every finding a source, making automated investigations traceable and auditable.
- Fast enough to disappear. Tavily returned the context the agent needed without becoming another bottleneck. “It was instantaneous,” Ahmad said.
Bell Cyber put Tavily through its live daily incident volume, which easily integrated into its existing framework through an API key.
The outcome
30 minutes became under 5.
Investigations that once took 30 minutes now close in under 5, cutting at least 25 minutes from the detect-to-contain cycle. The agent can research across hundreds of sources, with citations attached to its findings, and give analysts the context they need without jumping between systems.
The biggest win for Bell Cyber analysts was implementing effective AI workflows into what were once manual processes.
Even without adding headcount, analysts can now spend more time on threat hunting, malware analysis, reverse engineering, and validating the decisions that require human expertise. The agent gathers and cites, while the analyst validates and teaches.
Automation that works with the analyst
For Bell Cyber, AI is elevating the capacity of the security experts by removing the research bottleneck that kept them buried.
“The AI agent is only as good as the information that it has. And I believe Tavily is that tool that gives you that information, which is reliable, contextual, and traceable.”
Jawed Ahmad, Chief Technology and AI Officer, Bell Cyber
Curious how Tavily’s real-time web access can help your product? Talk to our team.
