Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

MDR & Managed Security Services

Managed security services: what mid-market buyers actually need

I've written the checks for two managed security contracts and killed a third at renewal. Now I open every provider call with one question: what can your analysts do at 2 am without calling us first? The answer sorts the shortlist faster than any RFP spreadsheet.

DCDaniel C. · Aug 7, 2026
Threat Hunting

Most threat hunting programs produce activity theater

The threat hunting program I inherited looked healthy on a slide: a hunt calendar, ATT&CK coverage in the high seventies, tidy quarterly reports. Not one hunt had changed a detection in eighteen months. This is how I separate a real hunt from a rebranded IOC sweep.

MKMarta K. · Aug 7, 2026
Threat Hunting

IOC sweeps vs. TTP hunting: the difference changes what you fund

Our MDR renewal packet had a line item for proactive threat hunting, so I asked the account team to show me the hypothesis behind their last hunt. What came back was an indicator sweep with a hunting price tag. Paying hunting rates for work a script runs is a line item worth auditing before the next renewal.

DCDaniel C. · Aug 3, 2026
Detection Engineering

How we use ATT&CK mapping without gaming the coverage score

I carried a mostly-green ATT&CK heatmap into a detection review. Three weeks later an attacker walked straight through the exact technique the map called covered. After that miss, the first thing my team threw out was the coverage percentage.

MKMarta K. · Aug 3, 2026
AI in Security Operations

Can AI actually reduce alert fatigue, or just repackage it?

Three weeks after we switched on an AI triage layer, I was at my desk at 1 am pulling its auto-closed alerts back out of the archive and re-running them myself. The queue had collapsed to a few dozen alerts. I did not yet trust a closure whose reasoning I had not seen.

MKMarta K. · Aug 3, 2026
Threat Intelligence

Which threat intelligence feeds actually earn their keep

Renewal prep, last quarter: four feed subscriptions, six figures across the set. I ran the test I run on every vendor line and named one decision each feed changed in ninety days. Two cleared the bar; I cut the other two.

DCDaniel C. · Aug 3, 2026
Competitive Content

Best incident response companies in 2026: who's worth the retainer

I'm renewing our IR retainer this quarter, and the shortlist my broker sent was a 2024 document with a 2026 date on it. Half the brands on it had been acquired out from under their own names. Here is how I actually sort the field.

DCDaniel C. · Aug 3, 2026
SecOps Leadership & Strategy

What mid-market boards actually expect from a CISO

I spent the last year reading mid-market CISO job specs and following what happened to the people hired against them. The specs screen for a computer science degree and a stack of certifications. The first-year board test grades almost none of it, and the gap explains a lot of the turnover.

THTheo H. · Jul 25, 2026
Compliance and Risk

NIST CSF 2.0: a SecOps-friendly read

Before last quarter's board prep, I re-cut our security operations budget against the six functions of NIST CSF 2.0. Detection tooling dominated the sheet; recovery had almost nothing against it, and governance wasn't even a line. Read as a checklist, the framework sends your budget in the wrong order.

DCDaniel C. · Jul 25, 2026
Phishing & Social Engineering Defense

Social engineering patterns we've seen get past filters

The alert that taught me the most about social engineering never fired on the message. It fired eleven days later, on an Okta login from an anonymizing proxy against a Super Admin account our own help desk had reset. Every filter I owned had nothing to inspect, because the attack produced no message artifact at all.

MKMarta K. · Jul 25, 2026
AI in Security Operations

How AI-assisted investigation actually walks through a Tier 1 alert

Impossible travel on a finance account used to eat half an hour of my night, walking four consoles by hand to prove it was just a VPN. With an AI-assisted tool the enrichment was already assembled when the case reached me, so I started where the work needs a person. The AI compressed the mechanical parts, and I kept every judgment call.

MKMarta K. · Jul 25, 2026