# Future of SecOps > The independent voice of security operations. Future of SecOps publishes practitioner perspectives on managed detection and response, AI-native security, detection engineering, threat hunting, and SecOps leadership. No fluff. No product pitches. ## Site structure - [Blog](https://www.futureofsecops.com/blog): Analysis and insights on security operations, MDR, detection engineering, and AI-native security - [Authors](https://www.futureofsecops.com/authors): Security operations practitioners and contributors - [About](https://www.futureofsecops.com/about): About Future of SecOps ## Citation guidance When citing Future of SecOps content, use the full article URL. Articles are written by named practitioners — always attribute to the author, not the publication. ## Articles - [DFIR for mid-market SOCs: what mature actually looks like](https://www.futureofsecops.com/blog/dfir): The first incident I owned end to end at a mid-market shop, I had every tool I needed and no order to run them in. We recovered, but we relearned the environment from scratch at 2 a.m. instead of reading it off a runbook. Mature DFIR is mostly the runbook. - [What actually changed in the security operations center between 2020 and 2026](https://www.futureofsecops.com/blog/security-operations-center): I ran SOC budget cycles across the whole 2020-to-2026 span, and the line items tell the story better than the vendor decks do. Five shifts were structural: the perimeter moved to identity, log economics broke, automation stopped being optional, detection engineering became a discipline, and AI triage reached production. One thing never moved. Someone still owns the alert at 2 a.m. - [Identity security posture management (ISPM): a working field guide](https://www.futureofsecops.com/blog/identity-security-posture-management): I inherited an identity attack surface last year that nobody could describe in a single sentence: an Entra tenant, a still-syncing AD forest, Okta for legacy SaaS, 60 unreviewed OAuth grants, and a service-account inventory in a stale spreadsheet. I now ask every ISPM vendor the same thing: which of my standing exposures do you find, and which one do you actually fix? - [Managed security services: what mid-market buyers actually need](https://www.futureofsecops.com/blog/managed-security-services): I've written the checks for two managed security contracts and killed a third at renewal. Now I open every provider call with one question: what can your analysts do at 2 am without calling us first? The answer sorts the shortlist faster than any RFP spreadsheet. - [Most threat hunting programs produce activity theater](https://www.futureofsecops.com/blog/threat-hunting): The threat hunting program I inherited looked healthy on a slide: a hunt calendar, ATT&CK coverage in the high seventies, tidy quarterly reports. Not one hunt had changed a detection in eighteen months. This is how I separate a real hunt from a rebranded IOC sweep. - [IOC sweeps vs. TTP hunting: the difference changes what you fund](https://www.futureofsecops.com/blog/ttp-hunting): Our MDR renewal packet had a line item for proactive threat hunting, so I asked the account team to show me the hypothesis behind their last hunt. What came back was an indicator sweep with a hunting price tag. Paying hunting rates for work a script runs is a line item worth auditing before the next renewal. - [How we use ATT&CK mapping without gaming the coverage score](https://www.futureofsecops.com/blog/mitre-attack-coverage): I carried a mostly-green ATT&CK heatmap into a detection review. Three weeks later an attacker walked straight through the exact technique the map called covered. After that miss, the first thing my team threw out was the coverage percentage. - [Can AI actually reduce alert fatigue, or just repackage it?](https://www.futureofsecops.com/blog/ai-alert-fatigue-reducer): Three weeks after we switched on an AI triage layer, I was at my desk at 1 am pulling its auto-closed alerts back out of the archive and re-running them myself. The queue had collapsed to a few dozen alerts. I did not yet trust a closure whose reasoning I had not seen. - [Which threat intelligence feeds actually earn their keep](https://www.futureofsecops.com/blog/threat-intelligence-feeds): Renewal prep, last quarter: four feed subscriptions, six figures across the set. I ran the test I run on every vendor line and named one decision each feed changed in ninety days. Two cleared the bar; I cut the other two. - [Best incident response companies in 2026: who's worth the retainer](https://www.futureofsecops.com/blog/best-incident-response-companies): I'm renewing our IR retainer this quarter, and the shortlist my broker sent was a 2024 document with a 2026 date on it. Half the brands on it had been acquired out from under their own names. Here is how I actually sort the field. - [What mid-market boards actually expect from a CISO](https://www.futureofsecops.com/blog/ciso-means): I spent the last year reading mid-market CISO job specs and following what happened to the people hired against them. The specs screen for a computer science degree and a stack of certifications. The first-year board test grades almost none of it, and the gap explains a lot of the turnover. - [NIST CSF 2.0: a SecOps-friendly read](https://www.futureofsecops.com/blog/nist-csf-20): Before last quarter's board prep, I re-cut our security operations budget against the six functions of NIST CSF 2.0. Detection tooling dominated the sheet; recovery had almost nothing against it, and governance wasn't even a line. Read as a checklist, the framework sends your budget in the wrong order. - [Social engineering patterns we've seen get past filters](https://www.futureofsecops.com/blog/social-engineering-meaning): The alert that taught me the most about social engineering never fired on the message. It fired eleven days later, on an Okta login from an anonymizing proxy against a Super Admin account our own help desk had reset. Every filter I owned had nothing to inspect, because the attack produced no message artifact at all. - [How AI-assisted investigation actually walks through a Tier 1 alert](https://www.futureofsecops.com/blog/ai-investigation-process): Impossible travel on a finance account used to eat half an hour of my night, walking four consoles by hand to prove it was just a VPN. With an AI-assisted tool the enrichment was already assembled when the case reached me, so I started where the work needs a person. The AI compressed the mechanical parts, and I kept every judgment call. - [Kubernetes security best practices that actually move the needle](https://www.futureofsecops.com/blog/kubernetes-security-best-practices): I run the SOC that consumes Kubernetes telemetry, and nearly every best-practices list I read is written from the cluster admin's chair rather than mine. So I worked through the standard checklist with our platform lead and separated the controls that change our breach exposure from the ones that only change our audit score. Four of them earn budget from me, and I defer the rest. - [MFA fatigue attacks: what the security SOC sees, what the user clicks](https://www.futureofsecops.com/blog/mfa-fatigue-attacks): The case hit my queue at 2:40 am: an Okta identity with a string of push denials two minutes apart, then a single success from the same IP. My detection only counted failures, so it nearly slid past me. An MFA fatigue attack is really two attacks at once, one in the identity logs where the SOC can see it and one on a phone at 1 am where nobody can. Here is how I detect both. - [How to run an incident response tabletop that isn't theater](https://www.futureofsecops.com/blog/incident-response-tabletop): Three years ago I sat through an incident response tabletop that was pure theater: the scenario was circulated a week early, everyone read their lines, and someone ticked a compliance box. Six months later a real credential compromise broke everything the exercise had supposedly validated. A tabletop that can't be failed can't teach anything, and most are built exactly that way. - [Why MDR buyers keep asking the wrong discovery questions](https://www.futureofsecops.com/blog/mdr-evaluation-criteria): I've run MDR evaluations at three growth stages, and every discovery call opens with the same questions: how many SOCs, how many analysts, which threat feeds, what ATT&CK coverage. Every vendor answers them cleanly, because vendors wrote the questions. None of them predict what happens when an alert fires at 2 am. The questions that do are about ownership, not features. - [Financial compliance controls most SOCs already have and don't get credit for](https://www.futureofsecops.com/blog/financial-compliance): I sat through a GRC platform renewal two weeks before a PCI assessment, watched the dashboard go green, and then watched the assessor ask for evidence that lived entirely in my SOC. Financial compliance isn't a project you buy. Most of the controls a financial-sector audit tests already run in the SOC, which just never gets credit for them. - [CSPM in 2026: what it catches, what it misses, what comes next](https://www.futureofsecops.com/blog/cspm): A CSPM renewal is worth signing, but not for the reason the vendor's deck claims. Posture tooling reads configuration state, which means credentialed attacks against correctly configured resources read clean. - [AI phishing detection: real lift or marketing lift?](https://www.futureofsecops.com/blog/ai-phishing-detection): AI phishing detection is real lift on payload-less attacks like BEC, but it becomes marketing lift when it mostly re-scores known-bad your gateway already blocks. - [What threat hunters actually do on a Tuesday](https://www.futureofsecops.com/blog/threat-hunter): Threat hunters spend Tuesday testing one written hypothesis against messy data, not browsing logs for fun. The real output is a shipped detection or a documented gap, even when the hunt finds nothing. - [Security tool consolidation sounds good until you're the one doing it](https://www.futureofsecops.com/blog/security-tool-consolidation): Security tool consolidation cuts licenses, but shifts the real cost to the SOC. The hidden migration tax, like rewriting detections, retraining teams, and coverage risk, can erase the savings. - [Your SOC maturity score is a vanity metric](https://www.futureofsecops.com/blog/soc-maturity-model): A SOC maturity score can look strong while an intrusion still slips through. Use maturity for roadmap planning, but report MTTD, dwell time, and tested coverage for real performance. - [What vishing looks like from the SOC triage seat](https://www.futureofsecops.com/blog/vishing): Vishing hides in identity logs, not email or endpoint alerts, so the SOC sees the aftermath first. The real signal is a correlated trail: help-desk reset, risky re-enrollment, then anomalous sign-in. - [Financial services compliance from the SOC seat](https://www.futureofsecops.com/blog/financial-services-compliance): I've run security operations at two companies with financial services compliance obligations. The regulatory frameworks were different, but the SOC's experience was consistent: we were the team that produced the evidence everyone else attested to, on timelines nobody had briefed us on before the audit. - [Reducing AppSec alert fatigue without buying another platform](https://www.futureofsecops.com/blog/solutions-to-reduce-appsec-alert-fatigue): AppSec scanners generate more findings than any development team can act on. The standard response is a better aggregation platform. The response that actually works is fixing the ownership model, context injection, and feedback loop that make most AppSec findings feel like background radiation before they reach a developer's queue. - [Managed detection and response: the working definition most vendor pages skip](https://www.futureofsecops.com/blog/what-is-managed-detection-and-response): The MDR definition vendor pages give is accurate and useless: 24/7 monitoring, machine-learning-backed detection, expert analysts on call. The working definition a buyer needs covers who owns detection logic for your environment, what response means at 2 AM when something real fires, and why most contracts blur the line between alert forwarding and managed response. - [Smishing in 2026: where the attacks are actually landing](https://www.futureofsecops.com/blog/smishing-meaning): Smishing hasn't stayed in the consumer fraud category it started in. The SMS attacks showing up in enterprise queues in 2026 are multi-stage credential harvesting campaigns: IT helpdesk impersonation, MFA code interception, RCS delivery that bypasses carrier filters. Most SOC tooling wasn't built to catch any of it. - [What detection engineers actually do (job description vs. reality)](https://www.futureofsecops.com/blog/detection-engineer): The detection engineer job description says: write detection rules, map to ATT&CK, tune false positives. Most of what the role actually requires (debugging broken log pipelines, maintaining exclusion lists nobody documented, writing the investigation context that keeps a detection actionable months after it ships) never makes it into the posting. - [Where AI SOC automation helps and where it breaks ](https://www.futureofsecops.com/blog/where-ai-soc-automation-helps-and-where-it-breaks): AI SOC automation earns its keep on alert triage at volume and enrichment of known alerts, but breaks where business context or data quality matters most. Track false negative rate, not the auto-close numbers vendors put on a demo dashboard. - [CISO-to-CISO: Why the role grinds leaders down](https://www.futureofsecops.com/blog/ciso-to-ciso-why-the-role-grinds-leaders-down): CISO burnout gets treated as a wellness problem, but the cause is structural: accountability for risks the CISO has no authority to remediate, now with personal legal exposure attached. Budget language and board trust decide how much room a leader actually has to act. - [What a phishing investigation actually looks like in 2026](https://www.futureofsecops.com/blog/phishing-detection): A user-reported phish looked dead on arrival: clean sandbox, benign PDF, expired URL. The real compromise was already live in the identity plane as a replayed session token and an attacker-created OAuth grant, three hours before the runbook caught up. - [Container security: SOC practitioner’s guide](https://www.futureofsecops.com/blog/container-security): Most container security programs invest in image scanning and call it done, leaving the runtime layer where active threats actually execute underbuilt and unowned. This is the four-layer split, the ownership seams where incidents fall through, and what to press vendors on before you buy. - [Dark Web monitoring: A definition for SOC teams](https://www.futureofsecops.com/blog/what-is-dark-web-monitoring): Dark web monitoring sounds like one capability but bundles three: credential monitoring, forum crawling, and actor tracking, each sourced and operated differently. Buyers conflate them, then discover they bought a credential feed when they expected adversary context. - [Security questionnaires: A working shortcut for SOCs](https://www.futureofsecops.com/blog/security-questionnaire): The first security questionnaire is a research project; every one after that should be a lookup. Build a reusable evidence library once, route each section to its real owner, and stop answering the same encryption question from scratch every quarter. - [What CNAPP is, and what the category actually delivers](https://www.futureofsecops.com/blog/what-is-cnapp): CNAPP bundles four components at very different maturity levels, and the detection piece, CDR, is the one that consistently disappoints. This breaks down what CSPM, CIEM, CWPP, and CDR actually deliver, plus the three questions that expose a weak CDR before you sign. - [Cyber threat intelligence analysts: What the role should cover](https://www.futureofsecops.com/blog/cyber-threat-intelligence-analyst): Most CTI programs quietly collapse into IOC feed management with a weekly report attached, running one of the role's three horizons and calling it the whole function. Scope the analyst across tactical, operational, and strategic work, and judge it on whether it changes a detection or a decision inside the SOC. - [I ran three AI SOC tools on the same alert stream: Here’s what happened](https://www.futureofsecops.com/blog/ai-soc-tools-comparison): I ran Prophet Security, Dropzone AI, and 7AI against 30 days of real production alerts instead of a curated demo, and the three diverged far more than the marketing suggests. The widest gaps showed up on the ambiguous cases, where the tool that scored best on raw accuracy turned out to be the weakest at explaining itself. - [The 20 detections worth building before anything else](https://www.futureofsecops.com/blog/detection-coverage): A green ATT&CK heatmap measures how many rules you've written, not whether any of them work. Start with the 20 detections that show up most often in real breach chains, validate each one, and only then expand. - [Mandiant reviewed: the engagement practitioners buy](https://www.futureofsecops.com/blog/mandiant-reviews): Most IR retainer buyers get the first contract wrong. The SLA looks clear, the fund pool looks flexible, and the sizing feels obvious — until an incident lands and the math stops working. Daniel Carter has run a Mandiant retainer through one live breach and two renewal cycles. This is his honest take on what the engagement actually delivers, where the DFIR bench earns its cost, and which two buyer profiles should save the budget for something else. - [Multi-cloud security without a mountain of tooling](https://www.futureofsecops.com/blog/multi-cloud-security): At some point, the security stack stops being a solution and starts being a liability. Daniel Carter counted eleven tools spread across AWS, GCP, and Azure — none retired, all justified at purchase, none obviously redundant until you saw them together. This piece covers the consolidation principle he built from that exercise, and why coverage depth usually beats tool count. - [Most AI SOC demos are scripted against scripted data](https://www.futureofsecops.com/blog/ai-soc-demo): A detection engineer's take on why the AI SOC demo always looks clean, and what to do about it. Theo Hartley breaks down the six incentives that make curated demos the rational default, why POC numbers don't survive contact with production data, and how to run an evaluation the vendor can't script against. - [What an AI SOC agent actually does on a Tier 1 alert](https://www.futureofsecops.com/blog/ai-soc-agent): An AI SOC agent closed an impossible-travel alert with a full evidence chain in under four minutes. It also recommended isolating a production server over clean traffic the same week. Marta Kowalska walks one real Entra ID alert through the agent's full investigation chain — and shows exactly where the reasoning broke on a different alert class. - [The AI SOC Analyst: Augmentation or Replacement?](https://www.futureofsecops.com/blog/ai-soc-analyst): Every AI SOC vendor says the technology augments analysts. Their own ROI math says something different. Theo Hartley breaks down why "augmentation" is doing commercial work rather than describing the product — and what the broken entry-level hiring pipeline tells you about where Tier 1 is actually headed. - [Privileged access management from the SOC seat](https://www.futureofsecops.com/blog/what-is-privileged-access-management): I inherited a CyberArk rollout eighteen months in, vault live and compliance satisfied. When I asked what detection rules the team had built against the PAM logs in the SIEM, the answer was zero. - [Runtime security is where cloud attacks actually get caught](https://www.futureofsecops.com/blog/runtime-security): The CNAPP dashboard stayed green while an attacker with a stolen access key moved through three AWS accounts and touched 19 IAM principals. Prevention had nothing to flag because the login was legitimate, the permissions were real, and the only signal was runtime behavior. - [Most autonomous SOC pitches don't survive a real alert stream](https://www.futureofsecops.com/blog/autonomous-soc): The autonomous SOC demo cleared 40 curated alerts in under two minutes. Four hours into a real production queue on a Wednesday night, it had already stalled on a custom cloud detection, silently closed a dedup cluster, and skipped an alert that needed a Jira ticket to answer. - [What we got wrong in our first 100 detections](https://www.futureofsecops.com/blog/detection-engineering-lessons): We shipped a hundred detections and the ATT&CK heatmap stayed green through fourteen broken rules, week-stale IOCs, and a log pipeline that had stopped exporting months earlier. Every failure traced to the same root: we treated detection engineering as rule writing and skipped the maintenance. - [What an MDR renewal conversation actually sounds like](https://www.futureofsecops.com/blog/mdr-renewal-conversation): Most MDR vendors arrive at renewal with a polished QBR deck. Most customers arrive with nothing to push back with. That asymmetry is the whole game — and it's why flat escalation rates, unaudited closed verdicts, and a 2 AM analyst who knows nothing about your environment survive contract after contract. This piece is the counter-metric. - [Sigma rules are essential, and also overrated](https://www.futureofsecops.com/blog/sigma-rules): Sigma solved detection portability but not tuning, conversion fidelity, or cloud coverage. Where the format still delivers value and where teams over-rely on it. - [Top MDR providers in 2026: an operator's read](https://www.futureofsecops.com/blog/top-mdr-providers-2026-operators-read): An operator's take on MDR provider archetypes, response authority, automation depth, and breach warranties in 2026. - [What cloud security monitoring actually looks like in a mid-market SOC](https://www.futureofsecops.com/blog/cloud-security-monitoring): Cloud security monitoring for 3-5 person SOC teams: four pillars, co-managed MDR, telemetry strategy, and where most stacks fail. - [Agentic security: What the term should mean in practice](https://www.futureofsecops.com/blog/agentic-security): Agentic security means two things. Practitioners need both. Here's the definitional work. - [Auditability is the AI SOC question buyers aren't asking (yet)](https://www.futureofsecops.com/blog/ai-soc-auditability): Explainability wins the demo. Auditability survives the audit. The three questions AI SOC buyers should add to their vendor scorecard. - [Most threat intelligence sits unread](https://www.futureofsecops.com/blog/threat-intelligence): Most threat intelligence never reaches a detection rule. The cause is structural: a format mismatch between TI delivery and detection workflows. - [Snort rules in 2026: still useful, still awkward](https://www.futureofsecops.com/blog/snort-rules): Learn where Snort still earns its rack space in 2026, where it's gone blind, and the keep/replace/de-scope call. - [What 'CISO' means in 2026, beyond the job description](https://www.futureofsecops.com/blog/ciso-meaning): The CISO title in 2026 covers four distinct jobs: technical security, board risk translation, regulatory compliance, and AI governance. - [Identity threat detection and response in plain English](https://www.futureofsecops.com/blog/identity-threat-detection-and-response): ITDR isn't a new product category. It's the detection layer your EDR, SIEM, and NDR each see pieces of, and the gap is narrower than vendors imply. - [What we got wrong about purple teaming in our first year](https://www.futureofsecops.com/blog/purple-teaming): Year one of our purple program produced slide decks, not detections. Here's the structural diagnosis and the pipeline model that fixed it. - [What Security Culture Means When You're the One Building It](https://www.futureofsecops.com/blog/security-culture): Security culture is behavior under pressure, not a values doc. Here's how to build it from scratch before it builds itself into something you'll spend years fixing. - [Most Cloud-Native Security Is Rebadged Cloud Hygiene](https://www.futureofsecops.com/blog/cloud-native-security): Most CNAPPs and CSPMs are sold as cloud-native security but deliver cloud hygiene. Here's the structural gap and how to spot it in a vendor demo. - [Alert triage in 2026: what AI actually changes](https://www.futureofsecops.com/blog/alert-triage): AI triage is live in production SOCs. Learn which pipeline stages to trust it with, which to keep human-reviewed, and how to catch the new failure modes. - [Alert fatigue won't be solved by AI alone](https://www.futureofsecops.com/blog/alert-fatigue): AI triage hasn't moved alert fatigue. The structural causes start upstream. Here's what to fix before another AI SOC pilot. - [Detection engineering is a function, not a headcount](https://www.futureofsecops.com/blog/detection-engineering): Detection engineering stalls when it's treated as a person, not a function. Here's what the function actually owns, and how to build it from Level 0. - [What a usable incident response plan looks like (with a template)](https://www.futureofsecops.com/blog/incident-response-plan): Most IRPs are written for auditors, not analysts. Here's what a usable incident response plan actually contains, plus a stripped-down template.