Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

Incident Response

How to run an incident response tabletop that isn't theater

Three years ago I sat through an incident response tabletop that was pure theater: the scenario was circulated a week early, everyone read their lines, and someone ticked a compliance box. Six months later a real credential compromise broke everything the exercise had supposedly validated. A tabletop that can't be failed can't teach anything, and most are built exactly that way.

MKMarta K. · Jul 17, 2026
MDR & Managed Security Services

Why MDR buyers keep asking the wrong discovery questions

I've run MDR evaluations at three growth stages, and every discovery call opens with the same questions: how many SOCs, how many analysts, which threat feeds, what ATT&CK coverage. Every vendor answers them cleanly, because vendors wrote the questions. None of them predict what happens when an alert fires at 2 am. The questions that do are about ownership, not features.

DCDaniel C. · Jul 17, 2026
Compliance and Risk

Financial compliance controls most SOCs already have and don't get credit for

I sat through a GRC platform renewal two weeks before a PCI assessment, watched the dashboard go green, and then watched the assessor ask for evidence that lived entirely in my SOC. Financial compliance isn't a project you buy. Most of the controls a financial-sector audit tests already run in the SOC, which just never gets credit for them.

DCDaniel C. · Jul 17, 2026
Cloud Security Operations

CSPM in 2026: what it catches, what it misses, what comes next

A CSPM renewal is worth signing, but not for the reason the vendor's deck claims. Posture tooling reads configuration state, which means credentialed attacks against correctly configured resources read clean.

DCDaniel C. · Jul 17, 2026
Phishing & Social Engineering Defense

AI phishing detection: real lift or marketing lift?

AI phishing detection is real lift on payload-less attacks like BEC, but it becomes marketing lift when it mostly re-scores known-bad your gateway already blocks.

DCDaniel C. · Jul 11, 2026
Threat Hunting

What threat hunters actually do on a Tuesday

Threat hunters spend Tuesday testing one written hypothesis against messy data, not browsing logs for fun. The real output is a shipped detection or a documented gap, even when the hunt finds nothing.

MKMarta K. · Jul 11, 2026
SecOps Leadership & Strategy

Security tool consolidation sounds good until you're the one doing it

Security tool consolidation cuts licenses, but shifts the real cost to the SOC. The hidden migration tax, like rewriting detections, retraining teams, and coverage risk, can erase the savings.

THTheo H. · Jul 11, 2026
Modernization

Your SOC maturity score is a vanity metric

A SOC maturity score can look strong while an intrusion still slips through. Use maturity for roadmap planning, but report MTTD, dwell time, and tested coverage for real performance.

DCDaniel C. · Jul 10, 2026
Phishing & Social Engineering Defense

What vishing looks like from the SOC triage seat

Vishing hides in identity logs, not email or endpoint alerts, so the SOC sees the aftermath first. The real signal is a correlated trail: help-desk reset, risky re-enrollment, then anomalous sign-in.

MKMarta K. · Jul 10, 2026
Compliance and Risk

Financial services compliance from the SOC seat

I've run security operations at two companies with financial services compliance obligations. The regulatory frameworks were different, but the SOC's experience was consistent: we were the team that produced the evidence everyone else attested to, on timelines nobody had briefed us on before the audit.

DCDaniel C. · Jul 4, 2026
AI in Security Operations

Reducing AppSec alert fatigue without buying another platform

AppSec scanners generate more findings than any development team can act on. The standard response is a better aggregation platform. The response that actually works is fixing the ownership model, context injection, and feedback loop that make most AppSec findings feel like background radiation before they reach a developer's queue.

THTheo H. · Jul 4, 2026