Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

Threat Hunting

A hunt we ran that found nothing, and why it mattered

I closed the ticket in about nine minutes. Weeks later an intel report made me reopen it as a by-hand hunt against old logs. The hunt found nothing, and that empty result was worth more than most of the true positives I have escalated.

MKMarta K. · Aug 22, 2026
AI in Security Operations

The three root causes of alert fatigue in cybersecurity, and where AI actually helps

I've sat through eight AI SOC demos, each promising to end my team's alert fatigue. By the third I was asking one question first: which part? Too much volume, low-fidelity alerts, and no clear ownership are three different problems, and most demos treated them as one.

DCDaniel C. · Aug 22, 2026
AI in Security Operations

Alert fatigue is a detection-pipeline problem, not an analyst failure

A post-incident review took forty minutes to decide an analyst had missed an alert. Her queue held more than 800 alerts that shift, many of them duplicate copies of the same signal. She did not build that queue; the detection pipeline did.

MKMarta K. · Aug 22, 2026
SOC Modernization

SIEM in cyber security is a logging tax, not a detection strategy

At my last fintech, every endpoint, identity provider, and cloud account fed the SIEM. An attacker still moved laterally for two days without triggering a rule. The logs were present; the detection engineering was not.

MKMarta K. · Aug 22, 2026
Detection Engineering

Tuning detections to cut false positives without killing coverage

My team wanted a noisy recon rule disabled. I pulled six months of its history first and found one true positive: the early recon phase of a red team engagement we'd paid for. Here's how I tune a rule like that instead of killing it.

MKMarta K. · Aug 17, 2026
Cloud Security Operations

Multi-Cloud Security Across AWS, Azure, GCP

How to normalize multi-cloud security at the workflow layer across AWS, Azure, and GCP while preserving cloud-specific containment.

DCDaniel C. · Aug 17, 2026
Threat Intelligence

Open source threat intelligence: what's usable, what's noise

Open-source threat intelligence is worth using when it produces measurable incremental value. It's noise when it adds stale, duplicated, low-confidence indicators that raise alert volume without changing an outcome. Here's the six-measure test I run before renewing, adding, or automating any feed.

DCDaniel C. · Aug 17, 2026
SecOps Leadership & Strategy

Security team structures that actually scale

A security organization scales when its structure matches the work it must perform, the authority it needs to act, and the coverage it can sustain, not when it adds the next box from an enterprise org chart.

THTheo H. · Aug 17, 2026
Incident Response

DFIR for mid-market SOCs: what mature actually looks like

The first incident I owned end to end at a mid-market shop, I had every tool I needed and no order to run them in. We recovered, but we relearned the environment from scratch at 2 a.m. instead of reading it off a runbook. Mature DFIR is mostly the runbook.

MKMarta K. · Aug 8, 2026
SOC Modernization

What actually changed in the security operations center between 2020 and 2026

I ran SOC budget cycles across the whole 2020-to-2026 span, and the line items tell the story better than the vendor decks do. Five shifts were structural: the perimeter moved to identity, log economics broke, automation stopped being optional, detection engineering became a discipline, and AI triage reached production. One thing never moved. Someone still owns the alert at 2 a.m.

DCDaniel C. · Aug 8, 2026
Identity & Access Security Operations

Identity security posture management (ISPM): a working field guide

I inherited an identity attack surface last year that nobody could describe in a single sentence: an Entra tenant, a still-syncing AD forest, Okta for legacy SaaS, 60 unreviewed OAuth grants, and a service-account inventory in a stale spreadsheet. I now ask every ISPM vendor the same thing: which of my standing exposures do you find, and which one do you actually fix?

DCDaniel C. · Aug 8, 2026