Modern agentic systems that plan, reason, invoke tools, and self-reflect offer a promising path to autonomous cyber defense and SOC analyst augmentation. Yet this same autonomy introduces novel failure modes and attack surfaces absent from traditional security pipelines. Despite rapid adoption, prior surveys remain fragmented: addressing agentic safety domain-agnostically, focusing on offensive use, or examining pre-agentic LLM-based defense in isolation, leaving the field without a structured, defense-focused framework integrating failure characterization, operational lifecycle mapping, and compliance alignment. This survey closes that gap through four analytical artefacts: a four-category failure taxonomy (natural, system, adversarial, compliance) spanning 22 subcategories and 94 failure modes with mitigations; a decomposition of defensive cybersecurity into 13 tasks classified by autonomy level, oversight regime, and failure exposure; a review of 22 research systems and 10 commercial offerings across five operational categories; and a catalogue of 20 governance gaps mapped to GDPR, EU AI Act, NIST AI RMF, ISO 42001, and sector-specific frameworks. We argue the autonomy ceiling is bounded asymmetrically, not by reasoning capability but by action irreversibility, mitigation maturity, and compliance envelope, and consolidate open challenges into eight research directions.
Mitra et al. (Thu,) studied this question.