Black-Box AI in the SOC Is Professionally Negligent

If your AI agent makes decisions your analysts cannot explain, you do not have automation. You have liability. A SOC analyst closes a case. The AI agent told them it was a false positive. They click confirm and move on. They do not know why the agent reached that verdict. The agent does not tell […]
The Detection Engineering Feedback Loop:

How Your SOC Gets Smarter Every Day Good detections are not written once. They are grown through a continuous cycle of measurement, failure analysis, and refinement that most SOCs never formalize. Every SOC has that one Sigma rule someone wrote 18 months ago. It fires 300 times a day. Nobody remembers why. Analysts auto-close the […]
How to Measure Your AI Agents’ Performance

(The Metrics That Actually Matter) Most teams track the wrong numbers. Here is what separates useful AI agent metrics from expensive vanity dashboards. You deployed AI agents in your SOC. The vendor told you they would reduce alert fatigue, accelerate investigations, and free your analysts to focus on real threats. Six months in, your CISO […]
The anatomy of a risk score: TP confidence, history, and AI analysis

In any SOC, the first thing an analyst does with an alert is look at the number next to it. Maybe it says 87. Maybe it’s a red dot, or the word HIGH in a colored box. Whatever form it takes, that number is the single most important thing the platform tells the analyst about […]
Shadow AI: Your Employees Are Deploying AI Agents You Don’t Know About

The next shadow IT crisis is already here. It runs on API keys, not VPNs. Remember when employees started spinning up their own AWS instances because IT took six weeks to provision a server? That was shadow IT. We spent a decade building policies, approval workflows, and detection tooling around it. Then we mostly got […]
From alert processor to AI supervisor: the new SOC career path

A friend of mine runs a 12-person SOC at a financial services firm in Dubai. Last year he promoted his best Tier-1 analyst to a role that didn’t exist six months earlier. The title on the offer letter was “SOC AI Operations Lead.” The salary was 40% higher than her previous role. Her job, roughly, […]
82:1 — when machine identities outnumber your humans, who’s watching the machines?

CyberArk published a number last year that I keep coming back to. In the average organization, there are 82 machine identities for every human. Eighty-two. Service accounts, API keys, OAuth tokens, workload identities, certificates, bot accounts, CI/CD pipeline credentials. For every employee who logs in with a password and passes MFA, there are 82 non-human […]
How embedding-based case similarity finds threats that rules miss

Every SOC has a folder somewhere. A shared drive, a Confluence page, a Notion workspace, a senior analyst’s brain. It’s full of incidents from the last two years. Phishing campaigns that almost worked. The week somebody’s service account started behaving strangely on a Thursday afternoon. The lateral movement attempt that got caught by an alert […]
Why your best Tier-1 analyst is about to become your best agent engineer

Your best Tier-1 analyst is the one who already knows things the AI doesn’t. She knows that the encoded PowerShell alert that fires every Tuesday at 2:14 AM on the backup server is a scheduled job that’s been running for seven months. She knows that the marketing team’s VPN connects from a different country every […]
Identity is the new perimeter, and your SOAR platform doesn’t know it yet

Last quarter, Expel published their annual threat report. The number that stuck with me: 68.6% of the incidents their SOC handled in 2025 were identity-based attacks. Not malware. Not exploits. Not zero-days. Stolen credentials, hijacked sessions, OAuth abuse, and MFA bypass. More than two-thirds of all incidents started with somebody using a valid identity to […]