Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

Compliance and Risk

Financial services compliance from the SOC seat

I've run security operations at two companies with financial services compliance obligations. The regulatory frameworks were different, but the SOC's experience was consistent: we were the team that produced the evidence everyone else attested to, on timelines nobody had briefed us on before the audit.

DCDaniel C. · Jul 4, 2026
AI in Security Operations

Reducing AppSec alert fatigue without buying another platform

AppSec scanners generate more findings than any development team can act on. The standard response is a better aggregation platform. The response that actually works is fixing the ownership model, context injection, and feedback loop that make most AppSec findings feel like background radiation before they reach a developer's queue.

THTheo H. · Jul 4, 2026
MDR

Managed detection and response: the working definition most vendor pages skip

The MDR definition vendor pages give is accurate and useless: 24/7 monitoring, machine-learning-backed detection, expert analysts on call. The working definition a buyer needs covers who owns detection logic for your environment, what response means at 2 AM when something real fires, and why most contracts blur the line between alert forwarding and managed response.

DCDaniel C. · Jul 4, 2026
Phishing & Social Engineering Defense

Smishing in 2026: where the attacks are actually landing

Smishing hasn't stayed in the consumer fraud category it started in. The SMS attacks showing up in enterprise queues in 2026 are multi-stage credential harvesting campaigns: IT helpdesk impersonation, MFA code interception, RCS delivery that bypasses carrier filters. Most SOC tooling wasn't built to catch any of it.

MKMarta K. · Jul 4, 2026
Detection Engineering

What detection engineers actually do (job description vs. reality)

The detection engineer job description says: write detection rules, map to ATT&CK, tune false positives. Most of what the role actually requires (debugging broken log pipelines, maintaining exclusion lists nobody documented, writing the investigation context that keeps a detection actionable months after it ships) never makes it into the posting.

MKMarta K. · Jul 4, 2026
AI in Security Operations

Where AI SOC automation helps and where it breaks

AI SOC automation earns its keep on alert triage at volume and enrichment of known alerts, but breaks where business context or data quality matters most. Track false negative rate, not the auto-close numbers vendors put on a demo dashboard.

DCDaniel C. · Jun 26, 2026
SecOps Leadership & Strategy

CISO-to-CISO: Why the role grinds leaders down

CISO burnout gets treated as a wellness problem, but the cause is structural: accountability for risks the CISO has no authority to remediate, now with personal legal exposure attached. Budget language and board trust decide how much room a leader actually has to act.

THTheo H. · Jun 26, 2026
Phishing & Social Engineering Defense

What a phishing investigation actually looks like in 2026

A user-reported phish looked dead on arrival: clean sandbox, benign PDF, expired URL. The real compromise was already live in the identity plane as a replayed session token and an attacker-created OAuth grant, three hours before the runbook caught up.

MKMarta K. · Jun 26, 2026
Cloud Security Operations

Container security: SOC practitioner’s guide

Most container security programs invest in image scanning and call it done, leaving the runtime layer where active threats actually execute underbuilt and unowned. This is the four-layer split, the ownership seams where incidents fall through, and what to press vendors on before you buy.

DCDaniel C. · Jun 26, 2026
Threat Intelligence

Dark Web monitoring: A definition for SOC teams

Dark web monitoring sounds like one capability but bundles three: credential monitoring, forum crawling, and actor tracking, each sourced and operated differently. Buyers conflate them, then discover they bought a credential feed when they expected adversary context.

THTheo H. · Jun 26, 2026
Compliance and Risk

Security questionnaires: A working shortcut for SOCs

The first security questionnaire is a research project; every one after that should be a lookup. Build a reusable evidence library once, route each section to its real owner, and stop answering the same encryption question from scratch every quarter.

DCDaniel C. · Jun 19, 2026