Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

Cloud Security Operations

Kubernetes security best practices that actually move the needle

I run the SOC that consumes Kubernetes telemetry, and nearly every best-practices list I read is written from the cluster admin's chair rather than mine. So I worked through the standard checklist with our platform lead and separated the controls that change our breach exposure from the ones that only change our audit score. Four of them earn budget from me, and I defer the rest.

DCDaniel C. · Jul 25, 2026
Identity & Access Security Operations

MFA fatigue attacks: what the security SOC sees, what the user clicks

The case hit my queue at 2:40 am: an Okta identity with a string of push denials two minutes apart, then a single success from the same IP. My detection only counted failures, so it nearly slid past me. An MFA fatigue attack is really two attacks at once, one in the identity logs where the SOC can see it and one on a phone at 1 am where nobody can. Here is how I detect both.

MKMarta K. · Jul 17, 2026
Incident Response

How to run an incident response tabletop that isn't theater

Three years ago I sat through an incident response tabletop that was pure theater: the scenario was circulated a week early, everyone read their lines, and someone ticked a compliance box. Six months later a real credential compromise broke everything the exercise had supposedly validated. A tabletop that can't be failed can't teach anything, and most are built exactly that way.

MKMarta K. · Jul 17, 2026
MDR & Managed Security Services

Why MDR buyers keep asking the wrong discovery questions

I've run MDR evaluations at three growth stages, and every discovery call opens with the same questions: how many SOCs, how many analysts, which threat feeds, what ATT&CK coverage. Every vendor answers them cleanly, because vendors wrote the questions. None of them predict what happens when an alert fires at 2 am. The questions that do are about ownership, not features.

DCDaniel C. · Jul 17, 2026
Compliance and Risk

Financial compliance controls most SOCs already have and don't get credit for

I sat through a GRC platform renewal two weeks before a PCI assessment, watched the dashboard go green, and then watched the assessor ask for evidence that lived entirely in my SOC. Financial compliance isn't a project you buy. Most of the controls a financial-sector audit tests already run in the SOC, which just never gets credit for them.

DCDaniel C. · Jul 17, 2026
Cloud Security Operations

CSPM in 2026: what it catches, what it misses, what comes next

A CSPM renewal is worth signing, but not for the reason the vendor's deck claims. Posture tooling reads configuration state, which means credentialed attacks against correctly configured resources read clean.

DCDaniel C. · Jul 17, 2026
Phishing & Social Engineering Defense

AI phishing detection: real lift or marketing lift?

AI phishing detection is real lift on payload-less attacks like BEC, but it becomes marketing lift when it mostly re-scores known-bad your gateway already blocks.

DCDaniel C. · Jul 11, 2026
Threat Hunting

What threat hunters actually do on a Tuesday

Threat hunters spend Tuesday testing one written hypothesis against messy data, not browsing logs for fun. The real output is a shipped detection or a documented gap, even when the hunt finds nothing.

MKMarta K. · Jul 11, 2026
SecOps Leadership & Strategy

Security tool consolidation sounds good until you're the one doing it

Security tool consolidation cuts licenses, but shifts the real cost to the SOC. The hidden migration tax, like rewriting detections, retraining teams, and coverage risk, can erase the savings.

THTheo H. · Jul 11, 2026
Modernization

Your SOC maturity score is a vanity metric

A SOC maturity score can look strong while an intrusion still slips through. Use maturity for roadmap planning, but report MTTD, dwell time, and tested coverage for real performance.

DCDaniel C. · Jul 10, 2026
Phishing & Social Engineering Defense

What vishing looks like from the SOC triage seat

Vishing hides in identity logs, not email or endpoint alerts, so the SOC sees the aftermath first. The real signal is a correlated trail: help-desk reset, risky re-enrollment, then anomalous sign-in.

MKMarta K. · Jul 10, 2026