Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Latest

Identity & Access Security Operations

Identity security posture management (ISPM): a working field guide

I inherited an identity attack surface last year that nobody could describe in a single sentence: an Entra tenant, a still-syncing AD forest, Okta for legacy SaaS, 60 unreviewed OAuth grants, and a service-account inventory in a stale spreadsheet. I now ask every ISPM vendor the same thing: which of my standing exposures do you find, and which one do you actually fix?

DCDaniel C. · Aug 8, 2026
MDR & Managed Security Services

Managed security services: what mid-market buyers actually need

I've written the checks for two managed security contracts and killed a third at renewal. Now I open every provider call with one question: what can your analysts do at 2 am without calling us first? The answer sorts the shortlist faster than any RFP spreadsheet.

DCDaniel C. · Aug 7, 2026
Threat Hunting

Most threat hunting programs produce activity theater

The threat hunting program I inherited looked healthy on a slide: a hunt calendar, ATT&CK coverage in the high seventies, tidy quarterly reports. Not one hunt had changed a detection in eighteen months. This is how I separate a real hunt from a rebranded IOC sweep.

MKMarta K. · Aug 7, 2026
Threat Hunting

IOC sweeps vs. TTP hunting: the difference changes what you fund

Our MDR renewal packet had a line item for proactive threat hunting, so I asked the account team to show me the hypothesis behind their last hunt. What came back was an indicator sweep with a hunting price tag. Paying hunting rates for work a script runs is a line item worth auditing before the next renewal.

DCDaniel C. · Aug 3, 2026
Detection Engineering

How we use ATT&CK mapping without gaming the coverage score

I carried a mostly-green ATT&CK heatmap into a detection review. Three weeks later an attacker walked straight through the exact technique the map called covered. After that miss, the first thing my team threw out was the coverage percentage.

MKMarta K. · Aug 3, 2026
AI in Security Operations

Can AI actually reduce alert fatigue, or just repackage it?

Three weeks after we switched on an AI triage layer, I was at my desk at 1 am pulling its auto-closed alerts back out of the archive and re-running them myself. The queue had collapsed to a few dozen alerts. I did not yet trust a closure whose reasoning I had not seen.

MKMarta K. · Aug 3, 2026
Threat Intelligence

Which threat intelligence feeds actually earn their keep

Renewal prep, last quarter: four feed subscriptions, six figures across the set. I ran the test I run on every vendor line and named one decision each feed changed in ninety days. Two cleared the bar; I cut the other two.

DCDaniel C. · Aug 3, 2026
Competitive Content

Best incident response companies in 2026: who's worth the retainer

I'm renewing our IR retainer this quarter, and the shortlist my broker sent was a 2024 document with a 2026 date on it. Half the brands on it had been acquired out from under their own names. Here is how I actually sort the field.

DCDaniel C. · Aug 3, 2026
SecOps Leadership & Strategy

What mid-market boards actually expect from a CISO

I spent the last year reading mid-market CISO job specs and following what happened to the people hired against them. The specs screen for a computer science degree and a stack of certifications. The first-year board test grades almost none of it, and the gap explains a lot of the turnover.

THTheo H. · Jul 25, 2026