Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Latest

Cloud Security Operations

Container runtime security: what actually gets caught at runtime

A clean image scan and a compromised container aren't a contradiction: the scan reports the known risks in the image at build time, while runtime security reports what the workload is doing right now. That second question is the one attackers live in, and it's the one I make every vendor answer before I sign.

DCDaniel C. · Sep 12, 2026
Identity & Access Security Operations

MFA fatigue: what the SOC actually sees before the click

In my evaluations, the teams that catch MFA fatigue early aren't watching the push flood. They've already seen the infostealer hit, the credential-validation spike, the login from an unfamiliar IP days before the first prompt. The flood is the last stage worth catching, not the first.

DCDaniel C. · Sep 12, 2026
Compliance and Risk

Mapping ISO 27001 to your SOC without double work

The ISO 27001-to-SOC crosswalk takes an afternoon. The decision that actually costs you is whether audit evidence gets generated by your production systems as a byproduct, or reconstructed by an analyst every audit cycle. I build for the first, so the evidence is a record of operations, not a second job.

DCDaniel C. · Sep 12, 2026
Cloud Security Operations

Kubernetes security from the SOC seat

Three SecOps directors have told me the same story this year: the platform team ran Kubernetes for years, an auditor asked who was monitoring it, and it became the SOC's problem overnight. I've had that handoff myself. The SOC's Kubernetes job is narrower than the hardening checklists that fill the search results, and it starts with visibility and response authority.

DCDaniel C. · Aug 28, 2026
AI in Security Operations

A working taxonomy of AI in the SOC: wrappers, workflows, and agents

I've sat through nine AI SOC demos since January, and every vendor said "agent." By my read, two actually were. The rest were an LLM summarization layer on a tool I already own, or a SOAR platform with a model wired into a few decision points. The architecture under the label is what you're really buying.

DCDaniel C. · Aug 28, 2026
Detection Engineering

Sample Snort rules worth borrowing for a new SOC

Last year I priced network detection for a greenfield SOC and learned the buying part was easy. The Talos ruleset was $399 a sensor, ET Open was free, and the free set alone ran to tens of thousands of rules. Purchasing was the easy part; curation was the real job.

DCDaniel C. · Aug 28, 2026
Compliance and Risk

ISO compliance mapping: from the SecOps seat

ISO 27001 mapping rarely begins with a missing SOC capability. The trigger is usually a customer request, a 93-control Annex A spreadsheet, and a harder question: can I prove what my SOC actually does? The answer lives in evidence, ownership, and an honest Statement of Applicability, not a SIEM screenshot.

DCDaniel C. · Aug 28, 2026
Identity & Access Security Operations

Ping SSO logs the SOC can't afford to skip

I stopped treating Ping as one SSO log source after watching a PingOne feed look healthy while missing the one field a detection needed. PingOne and PingFederate use different collection paths, schemas, and defaults. Before I build any identity detection now, I validate the raw fields the rule depends on, starting with source IP.

DCDaniel C. · Aug 28, 2026
Identity & Access Security Operations

Privileged access in 2026: from the investigation seat

I've led the review after every serious incident my teams handled in a decade. The board always asks how it got this bad, and the answer is rarely the initial phish; it's the next step, when the attacker gains the authority to reset MFA, change roles, and export data.

DCDaniel C. · Aug 22, 2026