Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Latest

Phishing & Social Engineering Defense

Social engineering patterns we've seen get past filters

The alert that taught me the most about social engineering never fired on the message. It fired eleven days later, on an Okta login from an anonymizing proxy against a Super Admin account our own help desk had reset. Every filter I owned had nothing to inspect, because the attack produced no message artifact at all.

MKMarta K. · Jul 25, 2026
AI in Security Operations

How AI-assisted investigation actually walks through a Tier 1 alert

Impossible travel on a finance account used to eat half an hour of my night, walking four consoles by hand to prove it was just a VPN. With an AI-assisted tool the enrichment was already assembled when the case reached me, so I started where the work needs a person. The AI compressed the mechanical parts, and I kept every judgment call.

MKMarta K. · Jul 25, 2026
Cloud Security Operations

Kubernetes security best practices that actually move the needle

I run the SOC that consumes Kubernetes telemetry, and nearly every best-practices list I read is written from the cluster admin's chair rather than mine. So I worked through the standard checklist with our platform lead and separated the controls that change our breach exposure from the ones that only change our audit score. Four of them earn budget from me, and I defer the rest.

DCDaniel C. · Jul 25, 2026
Identity & Access Security Operations

MFA fatigue attacks: what the security SOC sees, what the user clicks

The case hit my queue at 2:40 am: an Okta identity with a string of push denials two minutes apart, then a single success from the same IP. My detection only counted failures, so it nearly slid past me. An MFA fatigue attack is really two attacks at once, one in the identity logs where the SOC can see it and one on a phone at 1 am where nobody can. Here is how I detect both.

MKMarta K. · Jul 17, 2026
Incident Response

How to run an incident response tabletop that isn't theater

Three years ago I sat through an incident response tabletop that was pure theater: the scenario was circulated a week early, everyone read their lines, and someone ticked a compliance box. Six months later a real credential compromise broke everything the exercise had supposedly validated. A tabletop that can't be failed can't teach anything, and most are built exactly that way.

MKMarta K. · Jul 17, 2026
MDR & Managed Security Services

Why MDR buyers keep asking the wrong discovery questions

I've run MDR evaluations at three growth stages, and every discovery call opens with the same questions: how many SOCs, how many analysts, which threat feeds, what ATT&CK coverage. Every vendor answers them cleanly, because vendors wrote the questions. None of them predict what happens when an alert fires at 2 am. The questions that do are about ownership, not features.

DCDaniel C. · Jul 17, 2026
Compliance and Risk

Financial compliance controls most SOCs already have and don't get credit for

I sat through a GRC platform renewal two weeks before a PCI assessment, watched the dashboard go green, and then watched the assessor ask for evidence that lived entirely in my SOC. Financial compliance isn't a project you buy. Most of the controls a financial-sector audit tests already run in the SOC, which just never gets credit for them.

DCDaniel C. · Jul 17, 2026
Cloud Security Operations

CSPM in 2026: what it catches, what it misses, what comes next

A CSPM renewal is worth signing, but not for the reason the vendor's deck claims. Posture tooling reads configuration state, which means credentialed attacks against correctly configured resources read clean.

DCDaniel C. · Jul 17, 2026
Phishing & Social Engineering Defense

AI phishing detection: real lift or marketing lift?

AI phishing detection is real lift on payload-less attacks like BEC, but it becomes marketing lift when it mostly re-scores known-bad your gateway already blocks.

DCDaniel C. · Jul 11, 2026