How Securaa investigated a phishing alert in 47 seconds

At 10:42 on a Wednesday morning, an employee in accounts payable forwarded an email to the security inbox with a one-line note. This looks off. The email claimed to be from the company’s bank, warned of a hold on an outgoing wire, and asked her to confirm account details through a link. She didn’t click […]
On-prem AI agents: same intelligence, zero cloud dependency

There’s a conversation that plays out in a lot of security teams the moment AI comes up. Someone has seen a demo of an AI agent that triages alerts, writes up cases, and clears the queue overnight. They want it. Then the question gets asked that ends the excitement in about four seconds. Where does […]
Insider threat investigation: building the identity chain from alert to verdict

An alert comes in on a Thursday afternoon. A sales account manager downloaded the regional customer list, about 400 records, to her laptop. The alert is low severity. Employees pull customer lists all the time. She has legitimate access. Nothing about the download itself looks wrong. Two weeks later, HR flags that she resigned. Her […]
Black-Box AI in the SOC Is Professionally Negligent

If your AI agent makes decisions your analysts cannot explain, you do not have automation. You have liability. A SOC analyst closes a case. The AI agent told them it was a false positive. They click confirm and move on. They do not know why the agent reached that verdict. The agent does not tell […]
The Detection Engineering Feedback Loop:

How Your SOC Gets Smarter Every Day Good detections are not written once. They are grown through a continuous cycle of measurement, failure analysis, and refinement that most SOCs never formalize. Every SOC has that one Sigma rule someone wrote 18 months ago. It fires 300 times a day. Nobody remembers why. Analysts auto-close the […]
How to Measure Your AI Agents’ Performance

(The Metrics That Actually Matter) Most teams track the wrong numbers. Here is what separates useful AI agent metrics from expensive vanity dashboards. You deployed AI agents in your SOC. The vendor told you they would reduce alert fatigue, accelerate investigations, and free your analysts to focus on real threats. Six months in, your CISO […]
The anatomy of a risk score: TP confidence, history, and AI analysis

In any SOC, the first thing an analyst does with an alert is look at the number next to it. Maybe it says 87. Maybe it’s a red dot, or the word HIGH in a colored box. Whatever form it takes, that number is the single most important thing the platform tells the analyst about […]
Shadow AI: Your Employees Are Deploying AI Agents You Don’t Know About

The next shadow IT crisis is already here. It runs on API keys, not VPNs. Remember when employees started spinning up their own AWS instances because IT took six weeks to provision a server? That was shadow IT. We spent a decade building policies, approval workflows, and detection tooling around it. Then we mostly got […]
From alert processor to AI supervisor: the new SOC career path

A friend of mine runs a 12-person SOC at a financial services firm in Dubai. Last year he promoted his best Tier-1 analyst to a role that didn’t exist six months earlier. The title on the offer letter was “SOC AI Operations Lead.” The salary was 40% higher than her previous role. Her job, roughly, […]
82:1 — when machine identities outnumber your humans, who’s watching the machines?

CyberArk published a number last year that I keep coming back to. In the average organization, there are 82 machine identities for every human. Eighty-two. Service accounts, API keys, OAuth tokens, workload identities, certificates, bot accounts, CI/CD pipeline credentials. For every employee who logs in with a password and passes MFA, there are 82 non-human […]