Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

Cloud Security Operations

Container security: SOC practitioner’s guide

Most container security programs invest in image scanning and call it done, leaving the runtime layer where active threats actually execute underbuilt and unowned. This is the four-layer split, the ownership seams where incidents fall through, and what to press vendors on before you buy.

DCDaniel C. · Jun 26, 2026
Threat Intelligence

Dark Web monitoring: A definition for SOC teams

Dark web monitoring sounds like one capability but bundles three: credential monitoring, forum crawling, and actor tracking, each sourced and operated differently. Buyers conflate them, then discover they bought a credential feed when they expected adversary context.

THTheo H. · Jun 26, 2026
Compliance and Risk

Security questionnaires: A working shortcut for SOCs

The first security questionnaire is a research project; every one after that should be a lookup. Build a reusable evidence library once, route each section to its real owner, and stop answering the same encryption question from scratch every quarter.

DCDaniel C. · Jun 19, 2026
Cloud Security Operations

What CNAPP is, and what the category actually delivers

CNAPP bundles four components at very different maturity levels, and the detection piece, CDR, is the one that consistently disappoints. This breaks down what CSPM, CIEM, CWPP, and CDR actually deliver, plus the three questions that expose a weak CDR before you sign.

DCDaniel C. · Jun 19, 2026
Threat Intelligence

Cyber threat intelligence analysts: What the role should cover

Most CTI programs quietly collapse into IOC feed management with a weekly report attached, running one of the role's three horizons and calling it the whole function. Scope the analyst across tactical, operational, and strategic work, and judge it on whether it changes a detection or a decision inside the SOC.

THTheo H. · Jun 19, 2026
AI in Security Operations

I ran three AI SOC tools on the same alert stream: Here’s what happened

I ran Prophet Security, Dropzone AI, and 7AI against 30 days of real production alerts instead of a curated demo, and the three diverged far more than the marketing suggests. The widest gaps showed up on the ambiguous cases, where the tool that scored best on raw accuracy turned out to be the weakest at explaining itself.

MKMarta K. · Jun 19, 2026
Detection Engineering

The 20 detections worth building before anything else

A green ATT&CK heatmap measures how many rules you've written, not whether any of them work. Start with the 20 detections that show up most often in real breach chains, validate each one, and only then expand.

MKMarta K. · Jun 19, 2026
Competitive Content

Mandiant reviewed: the engagement practitioners buy

Most IR retainer buyers get the first contract wrong. The SLA looks clear, the fund pool looks flexible, and the sizing feels obvious — until an incident lands and the math stops working. Daniel Carter has run a Mandiant retainer through one live breach and two renewal cycles. This is his honest take on what the engagement actually delivers, where the DFIR bench earns its cost, and which two buyer profiles should save the budget for something else.

DCDaniel C. · Jun 15, 2026
Cloud Security Operations

Multi-cloud security without a mountain of tooling

At some point, the security stack stops being a solution and starts being a liability. Daniel Carter counted eleven tools spread across AWS, GCP, and Azure — none retired, all justified at purchase, none obviously redundant until you saw them together. This piece covers the consolidation principle he built from that exercise, and why coverage depth usually beats tool count.

DCDaniel C. · Jun 15, 2026
AI in Security Operations

Most AI SOC demos are scripted against scripted data

A detection engineer's take on why the AI SOC demo always looks clean, and what to do about it. Theo Hartley breaks down the six incentives that make curated demos the rational default, why POC numbers don't survive contact with production data, and how to run an evaluation the vendor can't script against.

THTheo H. · Jun 15, 2026
AI in Security Operations

What an AI SOC agent actually does on a Tier 1 alert

An AI SOC agent closed an impossible-travel alert with a full evidence chain in under four minutes. It also recommended isolating a production server over clean traffic the same week. Marta Kowalska walks one real Entra ID alert through the agent's full investigation chain — and shows exactly where the reasoning broke on a different alert class.

MKMarta K. · Jun 15, 2026