Daniel Carter

Daniel C.

Head of Security Operations

Daniel C. is a security operations leader with over a decade of experience building and scaling SOC capabilities for cloud-native companies. He has led security teams through multiple stages of growth — from early-stage environments with minimal tooling to mature organizations operating 24/7 security operations with distributed teams. His experience includes designing SOC architectures, evaluating and managing MDR providers, and building internal detection and response capabilities. Daniel has been responsible for vendor selection across SIEM, EDR, and XDR platforms, as well as defining SLAs, response models, and escalation frameworks. He has also worked closely with executive leadership on budgeting, board reporting, and aligning security operations with broader business risk. He writes about the practical decisions security leaders face — including build vs buy tradeoffs, how to evaluate security vendors, and what it actually takes to run an effective security operations function at scale

Articles

Competitive Content

MDR vs SIEM: why you probably still need both

Every MDR deck I've sat through this year implies the SIEM is optional, but it isn't even the same kind of purchase: one is a staffed service, the other a data-and-detection platform. You can consolidate some of it, but only after you know who owns the logs, who owns the detections, and what survives when the provider leaves.

Sep 12, 2026

Cloud Security Operations

Container runtime security: what actually gets caught at runtime

A clean image scan and a compromised container aren't a contradiction: the scan reports the known risks in the image at build time, while runtime security reports what the workload is doing right now. That second question is the one attackers live in, and it's the one I make every vendor answer before I sign.

Sep 12, 2026

Identity & Access Security Operations

MFA fatigue: what the SOC actually sees before the click

In my evaluations, the teams that catch MFA fatigue early aren't watching the push flood. They've already seen the infostealer hit, the credential-validation spike, the login from an unfamiliar IP days before the first prompt. The flood is the last stage worth catching, not the first.

Sep 12, 2026

Compliance and Risk

Mapping ISO 27001 to your SOC without double work

The ISO 27001-to-SOC crosswalk takes an afternoon. The decision that actually costs you is whether audit evidence gets generated by your production systems as a byproduct, or reconstructed by an analyst every audit cycle. I build for the first, so the evidence is a record of operations, not a second job.

Sep 12, 2026

Cloud Security Operations

Kubernetes security from the SOC seat

Three SecOps directors have told me the same story this year: the platform team ran Kubernetes for years, an auditor asked who was monitoring it, and it became the SOC's problem overnight. I've had that handoff myself. The SOC's Kubernetes job is narrower than the hardening checklists that fill the search results, and it starts with visibility and response authority.

Aug 28, 2026

AI in Security Operations

A working taxonomy of AI in the SOC: wrappers, workflows, and agents

I've sat through nine AI SOC demos since January, and every vendor said "agent." By my read, two actually were. The rest were an LLM summarization layer on a tool I already own, or a SOAR platform with a model wired into a few decision points. The architecture under the label is what you're really buying.

Aug 28, 2026

Detection Engineering

Sample Snort rules worth borrowing for a new SOC

Last year I priced network detection for a greenfield SOC and learned the buying part was easy. The Talos ruleset was $399 a sensor, ET Open was free, and the free set alone ran to tens of thousands of rules. Purchasing was the easy part; curation was the real job.

Aug 28, 2026

Compliance and Risk

ISO compliance mapping: from the SecOps seat

ISO 27001 mapping rarely begins with a missing SOC capability. The trigger is usually a customer request, a 93-control Annex A spreadsheet, and a harder question: can I prove what my SOC actually does? The answer lives in evidence, ownership, and an honest Statement of Applicability, not a SIEM screenshot.

Aug 28, 2026

Identity & Access Security Operations

Ping SSO logs the SOC can't afford to skip

I stopped treating Ping as one SSO log source after watching a PingOne feed look healthy while missing the one field a detection needed. PingOne and PingFederate use different collection paths, schemas, and defaults. Before I build any identity detection now, I validate the raw fields the rule depends on, starting with source IP.

Aug 28, 2026

Identity & Access Security Operations

Privileged access in 2026: from the investigation seat

I've led the review after every serious incident my teams handled in a decade. The board always asks how it got this bad, and the answer is rarely the initial phish; it's the next step, when the attacker gains the authority to reset MFA, change roles, and export data.

Aug 22, 2026

AI in Security Operations

The three root causes of alert fatigue in cybersecurity, and where AI actually helps

I've sat through eight AI SOC demos, each promising to end my team's alert fatigue. By the third I was asking one question first: which part? Too much volume, low-fidelity alerts, and no clear ownership are three different problems, and most demos treated them as one.

Aug 22, 2026

Cloud Security Operations

Multi-Cloud Security Across AWS, Azure, GCP

How to normalize multi-cloud security at the workflow layer across AWS, Azure, and GCP while preserving cloud-specific containment.

Aug 17, 2026

Threat Intelligence

Open source threat intelligence: what's usable, what's noise

Open-source threat intelligence is worth using when it produces measurable incremental value. It's noise when it adds stale, duplicated, low-confidence indicators that raise alert volume without changing an outcome. Here's the six-measure test I run before renewing, adding, or automating any feed.

Aug 17, 2026

SOC Modernization

What actually changed in the security operations center between 2020 and 2026

I ran SOC budget cycles across the whole 2020-to-2026 span, and the line items tell the story better than the vendor decks do. Five shifts were structural: the perimeter moved to identity, log economics broke, automation stopped being optional, detection engineering became a discipline, and AI triage reached production. One thing never moved. Someone still owns the alert at 2 a.m.

Aug 8, 2026

Identity & Access Security Operations

Identity security posture management (ISPM): a working field guide

I inherited an identity attack surface last year that nobody could describe in a single sentence: an Entra tenant, a still-syncing AD forest, Okta for legacy SaaS, 60 unreviewed OAuth grants, and a service-account inventory in a stale spreadsheet. I now ask every ISPM vendor the same thing: which of my standing exposures do you find, and which one do you actually fix?

Aug 8, 2026

MDR & Managed Security Services

Managed security services: what mid-market buyers actually need

I've written the checks for two managed security contracts and killed a third at renewal. Now I open every provider call with one question: what can your analysts do at 2 am without calling us first? The answer sorts the shortlist faster than any RFP spreadsheet.

Aug 7, 2026

Threat Hunting

IOC sweeps vs. TTP hunting: the difference changes what you fund

Our MDR renewal packet had a line item for proactive threat hunting, so I asked the account team to show me the hypothesis behind their last hunt. What came back was an indicator sweep with a hunting price tag. Paying hunting rates for work a script runs is a line item worth auditing before the next renewal.

Aug 3, 2026

Threat Intelligence

Which threat intelligence feeds actually earn their keep

Renewal prep, last quarter: four feed subscriptions, six figures across the set. I ran the test I run on every vendor line and named one decision each feed changed in ninety days. Two cleared the bar; I cut the other two.

Aug 3, 2026

Competitive Content

Best incident response companies in 2026: who's worth the retainer

I'm renewing our IR retainer this quarter, and the shortlist my broker sent was a 2024 document with a 2026 date on it. Half the brands on it had been acquired out from under their own names. Here is how I actually sort the field.

Aug 3, 2026

Compliance and Risk

NIST CSF 2.0: a SecOps-friendly read

Before last quarter's board prep, I re-cut our security operations budget against the six functions of NIST CSF 2.0. Detection tooling dominated the sheet; recovery had almost nothing against it, and governance wasn't even a line. Read as a checklist, the framework sends your budget in the wrong order.

Jul 25, 2026

Cloud Security Operations

Kubernetes security best practices that actually move the needle

I run the SOC that consumes Kubernetes telemetry, and nearly every best-practices list I read is written from the cluster admin's chair rather than mine. So I worked through the standard checklist with our platform lead and separated the controls that change our breach exposure from the ones that only change our audit score. Four of them earn budget from me, and I defer the rest.

Jul 25, 2026

MDR & Managed Security Services

Why MDR buyers keep asking the wrong discovery questions

I've run MDR evaluations at three growth stages, and every discovery call opens with the same questions: how many SOCs, how many analysts, which threat feeds, what ATT&CK coverage. Every vendor answers them cleanly, because vendors wrote the questions. None of them predict what happens when an alert fires at 2 am. The questions that do are about ownership, not features.

Jul 17, 2026

Compliance and Risk

Financial compliance controls most SOCs already have and don't get credit for

I sat through a GRC platform renewal two weeks before a PCI assessment, watched the dashboard go green, and then watched the assessor ask for evidence that lived entirely in my SOC. Financial compliance isn't a project you buy. Most of the controls a financial-sector audit tests already run in the SOC, which just never gets credit for them.

Jul 17, 2026

Cloud Security Operations

CSPM in 2026: what it catches, what it misses, what comes next

A CSPM renewal is worth signing, but not for the reason the vendor's deck claims. Posture tooling reads configuration state, which means credentialed attacks against correctly configured resources read clean.

Jul 17, 2026

Phishing & Social Engineering Defense

AI phishing detection: real lift or marketing lift?

AI phishing detection is real lift on payload-less attacks like BEC, but it becomes marketing lift when it mostly re-scores known-bad your gateway already blocks.

Jul 11, 2026

Modernization

Your SOC maturity score is a vanity metric

A SOC maturity score can look strong while an intrusion still slips through. Use maturity for roadmap planning, but report MTTD, dwell time, and tested coverage for real performance.

Jul 10, 2026

Compliance and Risk

Financial services compliance from the SOC seat

I've run security operations at two companies with financial services compliance obligations. The regulatory frameworks were different, but the SOC's experience was consistent: we were the team that produced the evidence everyone else attested to, on timelines nobody had briefed us on before the audit.

Jul 4, 2026

MDR

Managed detection and response: the working definition most vendor pages skip

The MDR definition vendor pages give is accurate and useless: 24/7 monitoring, machine-learning-backed detection, expert analysts on call. The working definition a buyer needs covers who owns detection logic for your environment, what response means at 2 AM when something real fires, and why most contracts blur the line between alert forwarding and managed response.

Jul 4, 2026

AI in Security Operations

Where AI SOC automation helps and where it breaks

AI SOC automation earns its keep on alert triage at volume and enrichment of known alerts, but breaks where business context or data quality matters most. Track false negative rate, not the auto-close numbers vendors put on a demo dashboard.

Jun 26, 2026

Cloud Security Operations

Container security: SOC practitioner’s guide

Most container security programs invest in image scanning and call it done, leaving the runtime layer where active threats actually execute underbuilt and unowned. This is the four-layer split, the ownership seams where incidents fall through, and what to press vendors on before you buy.

Jun 26, 2026

Compliance and Risk

Security questionnaires: A working shortcut for SOCs

The first security questionnaire is a research project; every one after that should be a lookup. Build a reusable evidence library once, route each section to its real owner, and stop answering the same encryption question from scratch every quarter.

Jun 19, 2026

Cloud Security Operations

What CNAPP is, and what the category actually delivers

CNAPP bundles four components at very different maturity levels, and the detection piece, CDR, is the one that consistently disappoints. This breaks down what CSPM, CIEM, CWPP, and CDR actually deliver, plus the three questions that expose a weak CDR before you sign.

Jun 19, 2026

Competitive Content

Mandiant reviewed: the engagement practitioners buy

Most IR retainer buyers get the first contract wrong. The SLA looks clear, the fund pool looks flexible, and the sizing feels obvious — until an incident lands and the math stops working. Daniel Carter has run a Mandiant retainer through one live breach and two renewal cycles. This is his honest take on what the engagement actually delivers, where the DFIR bench earns its cost, and which two buyer profiles should save the budget for something else.

Jun 15, 2026

Cloud Security Operations

Multi-cloud security without a mountain of tooling

At some point, the security stack stops being a solution and starts being a liability. Daniel Carter counted eleven tools spread across AWS, GCP, and Azure — none retired, all justified at purchase, none obviously redundant until you saw them together. This piece covers the consolidation principle he built from that exercise, and why coverage depth usually beats tool count.

Jun 15, 2026

Identity & Access Security Operations

Privileged access management from the SOC seat

I inherited a CyberArk rollout eighteen months in, vault live and compliance satisfied. When I asked what detection rules the team had built against the PAM logs in the SIEM, the answer was zero.

Jun 5, 2026

Cloud Security Operations

Runtime security is where cloud attacks actually get caught

The CNAPP dashboard stayed green while an attacker with a stolen access key moved through three AWS accounts and touched 19 IAM principals. Prevention had nothing to flag because the login was legitimate, the permissions were real, and the only signal was runtime behavior.

Jun 5, 2026

Competitive Content

Top MDR providers in 2026: an operator's read

An operator's take on MDR provider archetypes, response authority, automation depth, and breach warranties in 2026.

Jun 3, 2026

AI in Security Operations

Agentic security: What the term should mean in practice

Agentic security means two things. Practitioners need both. Here's the definitional work.

Jun 2, 2026

Detection Engineering

Snort rules in 2026: still useful, still awkward

Learn where Snort still earns its rack space in 2026, where it's gone blind, and the keep/replace/de-scope call.

May 26, 2026

Identity & Access Security Operations

Identity threat detection and response in plain English

ITDR isn't a new product category. It's the detection layer your EDR, SIEM, and NDR each see pieces of, and the gap is narrower than vendors imply.

May 25, 2026

Cloud Security Operations

Most Cloud-Native Security Is Rebadged Cloud Hygiene

Most CNAPPs and CSPMs are sold as cloud-native security but deliver cloud hygiene. Here's the structural gap and how to spot it in a vendor demo.

May 14, 2026

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Daniel C. | Future of SecOps