Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Latest

AI in Security Operations

Can AI actually reduce alert fatigue, or just repackage it?

Three weeks after we switched on an AI triage layer, I was at my desk at 1 am pulling its auto-closed alerts back out of the archive and re-running them myself. The queue had collapsed to a few dozen alerts. I did not yet trust a closure whose reasoning I had not seen.

MKMarta K. · Aug 3, 2026
Threat Intelligence

Which threat intelligence feeds actually earn their keep

Renewal prep, last quarter: four feed subscriptions, six figures across the set. I ran the test I run on every vendor line and named one decision each feed changed in ninety days. Two cleared the bar; I cut the other two.

DCDaniel C. · Aug 3, 2026
Competitive Content

Best incident response companies in 2026: who's worth the retainer

I'm renewing our IR retainer this quarter, and the shortlist my broker sent was a 2024 document with a 2026 date on it. Half the brands on it had been acquired out from under their own names. Here is how I actually sort the field.

DCDaniel C. · Aug 3, 2026
SecOps Leadership & Strategy

What mid-market boards actually expect from a CISO

I spent the last year reading mid-market CISO job specs and following what happened to the people hired against them. The specs screen for a computer science degree and a stack of certifications. The first-year board test grades almost none of it, and the gap explains a lot of the turnover.

THTheo H. · Jul 25, 2026
Compliance and Risk

NIST CSF 2.0: a SecOps-friendly read

Before last quarter's board prep, I re-cut our security operations budget against the six functions of NIST CSF 2.0. Detection tooling dominated the sheet; recovery had almost nothing against it, and governance wasn't even a line. Read as a checklist, the framework sends your budget in the wrong order.

DCDaniel C. · Jul 25, 2026
Phishing & Social Engineering Defense

Social engineering patterns we've seen get past filters

The alert that taught me the most about social engineering never fired on the message. It fired eleven days later, on an Okta login from an anonymizing proxy against a Super Admin account our own help desk had reset. Every filter I owned had nothing to inspect, because the attack produced no message artifact at all.

MKMarta K. · Jul 25, 2026
AI in Security Operations

How AI-assisted investigation actually walks through a Tier 1 alert

Impossible travel on a finance account used to eat half an hour of my night, walking four consoles by hand to prove it was just a VPN. With an AI-assisted tool the enrichment was already assembled when the case reached me, so I started where the work needs a person. The AI compressed the mechanical parts, and I kept every judgment call.

MKMarta K. · Jul 25, 2026
Cloud Security Operations

Kubernetes security best practices that actually move the needle

I run the SOC that consumes Kubernetes telemetry, and nearly every best-practices list I read is written from the cluster admin's chair rather than mine. So I worked through the standard checklist with our platform lead and separated the controls that change our breach exposure from the ones that only change our audit score. Four of them earn budget from me, and I defer the rest.

DCDaniel C. · Jul 25, 2026
Identity & Access Security Operations

MFA fatigue attacks: what the security SOC sees, what the user clicks

The case hit my queue at 2:40 am: an Okta identity with a string of push denials two minutes apart, then a single success from the same IP. My detection only counted failures, so it nearly slid past me. An MFA fatigue attack is really two attacks at once, one in the identity logs where the SOC can see it and one on a phone at 1 am where nobody can. Here is how I detect both.

MKMarta K. · Jul 17, 2026