Compliance and Risk

Articles about compliance and risk from security operations practitioners.

Compliance and Risk

NIST CSF 2.0: a SecOps-friendly read

Before last quarter's board prep, I re-cut our security operations budget against the six functions of NIST CSF 2.0. Detection tooling dominated the sheet; recovery had almost nothing against it, and governance wasn't even a line. Read as a checklist, the framework sends your budget in the wrong order.

DCDaniel C. · Jul 25, 2026
Compliance and Risk

Financial compliance controls most SOCs already have and don't get credit for

I sat through a GRC platform renewal two weeks before a PCI assessment, watched the dashboard go green, and then watched the assessor ask for evidence that lived entirely in my SOC. Financial compliance isn't a project you buy. Most of the controls a financial-sector audit tests already run in the SOC, which just never gets credit for them.

DCDaniel C. · Jul 17, 2026
Compliance and Risk

Financial services compliance from the SOC seat

I've run security operations at two companies with financial services compliance obligations. The regulatory frameworks were different, but the SOC's experience was consistent: we were the team that produced the evidence everyone else attested to, on timelines nobody had briefed us on before the audit.

DCDaniel C. · Jul 4, 2026
Compliance and Risk

Security questionnaires: A working shortcut for SOCs

The first security questionnaire is a research project; every one after that should be a lookup. Build a reusable evidence library once, route each section to its real owner, and stop answering the same encryption question from scratch every quarter.

DCDaniel C. · Jun 19, 2026

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Compliance and Risk | Future of SecOps