Future of
SecOps

Opinionated analysis, guides, and expert takes from security operations practitioners.

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Latest

Cloud Security Operations

What cloud security monitoring actually looks like in a mid-market SOC

Cloud security monitoring for 3-5 person SOC teams: four pillars, co-managed MDR, telemetry strategy, and where most stacks fail.

MKMarta K. · Jun 2, 2026
AI in Security Operations

Agentic security: What the term should mean in practice

Agentic security means two things. Practitioners need both. Here's the definitional work.

DCDaniel C. · Jun 2, 2026
AI in Security Operations

Auditability is the AI SOC question buyers aren't asking (yet)

Explainability wins the demo. Auditability survives the audit. The three questions AI SOC buyers should add to their vendor scorecard.

THTheo H. · Jun 2, 2026
Threat Intelligence

Most threat intelligence sits unread

Most threat intelligence never reaches a detection rule. The cause is structural: a format mismatch between TI delivery and detection workflows.

THTheo H. · May 26, 2026
Detection Engineering

Snort rules in 2026: still useful, still awkward

Learn where Snort still earns its rack space in 2026, where it's gone blind, and the keep/replace/de-scope call.

DCDaniel C. · May 26, 2026
SecOps Leadership & Strategy

What 'CISO' means in 2026, beyond the job description

The CISO title in 2026 covers four distinct jobs: technical security, board risk translation, regulatory compliance, and AI governance.

THTheo H. · May 25, 2026
Identity & Access Security Operations

Identity threat detection and response in plain English

ITDR isn't a new product category. It's the detection layer your EDR, SIEM, and NDR each see pieces of, and the gap is narrower than vendors imply.

DCDaniel C. · May 25, 2026
Detection Engineering

What we got wrong about purple teaming in our first year

Year one of our purple program produced slide decks, not detections. Here's the structural diagnosis and the pipeline model that fixed it.

MKMarta K. · May 25, 2026
SecOps Leadership & Strategy

What Security Culture Means When You're the One Building It

Security culture is behavior under pressure, not a values doc. Here's how to build it from scratch before it builds itself into something you'll spend years fixing.

THTheo H. · May 15, 2026