Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

MDR

Managed detection and response: the working definition most vendor pages skip

The MDR definition vendor pages give is accurate and useless: 24/7 monitoring, machine-learning-backed detection, expert analysts on call. The working definition a buyer needs covers who owns detection logic for your environment, what response means at 2 AM when something real fires, and why most contracts blur the line between alert forwarding and managed response.

DCDaniel C. · Jul 4, 2026
Phishing & Social Engineering Defense

Smishing in 2026: where the attacks are actually landing

Smishing hasn't stayed in the consumer fraud category it started in. The SMS attacks showing up in enterprise queues in 2026 are multi-stage credential harvesting campaigns: IT helpdesk impersonation, MFA code interception, RCS delivery that bypasses carrier filters. Most SOC tooling wasn't built to catch any of it.

MKMarta K. · Jul 4, 2026
Detection Engineering

What detection engineers actually do (job description vs. reality)

The detection engineer job description says: write detection rules, map to ATT&CK, tune false positives. Most of what the role actually requires (debugging broken log pipelines, maintaining exclusion lists nobody documented, writing the investigation context that keeps a detection actionable months after it ships) never makes it into the posting.

MKMarta K. · Jul 4, 2026
AI in Security Operations

Where AI SOC automation helps and where it breaks

AI SOC automation earns its keep on alert triage at volume and enrichment of known alerts, but breaks where business context or data quality matters most. Track false negative rate, not the auto-close numbers vendors put on a demo dashboard.

DCDaniel C. · Jun 26, 2026
SecOps Leadership & Strategy

CISO-to-CISO: Why the role grinds leaders down

CISO burnout gets treated as a wellness problem, but the cause is structural: accountability for risks the CISO has no authority to remediate, now with personal legal exposure attached. Budget language and board trust decide how much room a leader actually has to act.

THTheo H. · Jun 26, 2026
Phishing & Social Engineering Defense

What a phishing investigation actually looks like in 2026

A user-reported phish looked dead on arrival: clean sandbox, benign PDF, expired URL. The real compromise was already live in the identity plane as a replayed session token and an attacker-created OAuth grant, three hours before the runbook caught up.

MKMarta K. · Jun 26, 2026
Cloud Security Operations

Container security: SOC practitioner’s guide

Most container security programs invest in image scanning and call it done, leaving the runtime layer where active threats actually execute underbuilt and unowned. This is the four-layer split, the ownership seams where incidents fall through, and what to press vendors on before you buy.

DCDaniel C. · Jun 26, 2026
Threat Intelligence

Dark Web monitoring: A definition for SOC teams

Dark web monitoring sounds like one capability but bundles three: credential monitoring, forum crawling, and actor tracking, each sourced and operated differently. Buyers conflate them, then discover they bought a credential feed when they expected adversary context.

THTheo H. · Jun 26, 2026
Compliance and Risk

Security questionnaires: A working shortcut for SOCs

The first security questionnaire is a research project; every one after that should be a lookup. Build a reusable evidence library once, route each section to its real owner, and stop answering the same encryption question from scratch every quarter.

DCDaniel C. · Jun 19, 2026
Cloud Security Operations

What CNAPP is, and what the category actually delivers

CNAPP bundles four components at very different maturity levels, and the detection piece, CDR, is the one that consistently disappoints. This breaks down what CSPM, CIEM, CWPP, and CDR actually deliver, plus the three questions that expose a weak CDR before you sign.

DCDaniel C. · Jun 19, 2026
Threat Intelligence

Cyber threat intelligence analysts: What the role should cover

Most CTI programs quietly collapse into IOC feed management with a weekly report attached, running one of the role's three horizons and calling it the whole function. Scope the analyst across tactical, operational, and strategic work, and judge it on whether it changes a detection or a decision inside the SOC.

THTheo H. · Jun 19, 2026