Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

AI in Security Operations

Most autonomous SOC pitches don't survive a real alert stream

The autonomous SOC demo cleared 40 curated alerts in under two minutes. Four hours into a real production queue on a Wednesday night, it had already stalled on a custom cloud detection, silently closed a dedup cluster, and skipped an alert that needed a Jira ticket to answer.

MKMarta K. · Jun 5, 2026
Detection Engineering

What we got wrong in our first 100 detections

We shipped a hundred detections and the ATT&CK heatmap stayed green through fourteen broken rules, week-stale IOCs, and a log pipeline that had stopped exporting months earlier. Every failure traced to the same root: we treated detection engineering as rule writing and skipped the maintenance.

MKMarta K. · Jun 5, 2026
MDR

What an MDR renewal conversation actually sounds like

Most MDR vendors arrive at renewal with a polished QBR deck. Most customers arrive with nothing to push back with. That asymmetry is the whole game — and it's why flat escalation rates, unaudited closed verdicts, and a 2 AM analyst who knows nothing about your environment survive contract after contract. This piece is the counter-metric.

MKMarta K. · Jun 5, 2026
Detection Engineering

Sigma rules are essential, and also overrated

Sigma solved detection portability but not tuning, conversion fidelity, or cloud coverage. Where the format still delivers value and where teams over-rely on it.

MKMarta K. · Jun 3, 2026
Competitive Content

Top MDR providers in 2026: an operator's read

An operator's take on MDR provider archetypes, response authority, automation depth, and breach warranties in 2026.

DCDaniel C. · Jun 3, 2026
Cloud Security Operations

What cloud security monitoring actually looks like in a mid-market SOC

Cloud security monitoring for 3-5 person SOC teams: four pillars, co-managed MDR, telemetry strategy, and where most stacks fail.

MKMarta K. · Jun 2, 2026
AI in Security Operations

Agentic security: What the term should mean in practice

Agentic security means two things. Practitioners need both. Here's the definitional work.

DCDaniel C. · Jun 2, 2026
AI in Security Operations

Auditability is the AI SOC question buyers aren't asking (yet)

Explainability wins the demo. Auditability survives the audit. The three questions AI SOC buyers should add to their vendor scorecard.

THTheo H. · Jun 2, 2026
Threat Intelligence

Most threat intelligence sits unread

Most threat intelligence never reaches a detection rule. The cause is structural: a format mismatch between TI delivery and detection workflows.

THTheo H. · May 26, 2026
Detection Engineering

Snort rules in 2026: still useful, still awkward

Learn where Snort still earns its rack space in 2026, where it's gone blind, and the keep/replace/de-scope call.

DCDaniel C. · May 26, 2026
SecOps Leadership & Strategy

What 'CISO' means in 2026, beyond the job description

The CISO title in 2026 covers four distinct jobs: technical security, board risk translation, regulatory compliance, and AI governance.

THTheo H. · May 25, 2026