Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

AI in Security Operations

What an AI SOC agent actually does on a Tier 1 alert

An AI SOC agent closed an impossible-travel alert with a full evidence chain in under four minutes. It also recommended isolating a production server over clean traffic the same week. Marta Kowalska walks one real Entra ID alert through the agent's full investigation chain — and shows exactly where the reasoning broke on a different alert class.

MKMarta K. · Jun 15, 2026
AI in Security Operations

The AI SOC Analyst: Augmentation or Replacement?

Every AI SOC vendor says the technology augments analysts. Their own ROI math says something different. Theo Hartley breaks down why "augmentation" is doing commercial work rather than describing the product — and what the broken entry-level hiring pipeline tells you about where Tier 1 is actually headed.

THTheo H. · Jun 14, 2026
Identity & Access Security Operations

Privileged access management from the SOC seat

I inherited a CyberArk rollout eighteen months in, vault live and compliance satisfied. When I asked what detection rules the team had built against the PAM logs in the SIEM, the answer was zero.

DCDaniel C. · Jun 5, 2026
Cloud Security Operations

Runtime security is where cloud attacks actually get caught

The CNAPP dashboard stayed green while an attacker with a stolen access key moved through three AWS accounts and touched 19 IAM principals. Prevention had nothing to flag because the login was legitimate, the permissions were real, and the only signal was runtime behavior.

DCDaniel C. · Jun 5, 2026
AI in Security Operations

Most autonomous SOC pitches don't survive a real alert stream

The autonomous SOC demo cleared 40 curated alerts in under two minutes. Four hours into a real production queue on a Wednesday night, it had already stalled on a custom cloud detection, silently closed a dedup cluster, and skipped an alert that needed a Jira ticket to answer.

MKMarta K. · Jun 5, 2026
Detection Engineering

What we got wrong in our first 100 detections

We shipped a hundred detections and the ATT&CK heatmap stayed green through fourteen broken rules, week-stale IOCs, and a log pipeline that had stopped exporting months earlier. Every failure traced to the same root: we treated detection engineering as rule writing and skipped the maintenance.

MKMarta K. · Jun 5, 2026
MDR

What an MDR renewal conversation actually sounds like

Most MDR vendors arrive at renewal with a polished QBR deck. Most customers arrive with nothing to push back with. That asymmetry is the whole game — and it's why flat escalation rates, unaudited closed verdicts, and a 2 AM analyst who knows nothing about your environment survive contract after contract. This piece is the counter-metric.

MKMarta K. · Jun 5, 2026
Detection Engineering

Sigma rules are essential, and also overrated

Sigma solved detection portability but not tuning, conversion fidelity, or cloud coverage. Where the format still delivers value and where teams over-rely on it.

MKMarta K. · Jun 3, 2026
Competitive Content

Top MDR providers in 2026: an operator's read

An operator's take on MDR provider archetypes, response authority, automation depth, and breach warranties in 2026.

DCDaniel C. · Jun 3, 2026
Cloud Security Operations

What cloud security monitoring actually looks like in a mid-market SOC

Cloud security monitoring for 3-5 person SOC teams: four pillars, co-managed MDR, telemetry strategy, and where most stacks fail.

MKMarta K. · Jun 2, 2026
AI in Security Operations

Agentic security: What the term should mean in practice

Agentic security means two things. Practitioners need both. Here's the definitional work.

DCDaniel C. · Jun 2, 2026