From Triage Grind to Strategic Operator: The New AI SOC Career Path

AI is absorbing the volume work that makes up the fundamental architecture of the Security Operations Center (SOC) tier system. While the tiers and the work aren’t going away, a junior and senior analyst’s day-to-day is changing fast. At some point in the last week, every analyst on your team made the same call. Close […]

From Triage Grind to Strategic Operator: The New AI SOC Career Path Read More »

The Agentic SOC: Transforming Data into Defensive Velocity

Security Operations Centers (SOCs) are currently confronting scalability challenges on two fronts: structural and cognitive. The day-to-day reality of modern defensive operations is stark: an analyst frequently begins a shift facing a queue deeply saturated with unvetted alerts. To process a single event, the analyst must open the alert, pivot to a secondary console to

The Agentic SOC: Transforming Data into Defensive Velocity Read More »

The Good, the Bad and the Ugly in Cybersecurity – Week 29

The Good | Authorities Sanction Cybercriminals & Dismantle Russian Bulletproof Hosting Infrastructure The EU and the United Kingdom have jointly sanctioned multiple Russian individuals and entities for targeting government networks and critical infrastructure across Europe. The sanctions specifically target senior Russia military intelligence (GRU) officers and operators, as well as four entities linked to the

The Good, the Bad and the Ugly in Cybersecurity – Week 29 Read More »

The Good, the Bad and the Ugly in Cybersecurity – Week 28

The Good | Authorities Apprehend Pro-Russian Hacktivist & Dismantle Global Fraud Networks Spanish authorities, acting on intelligence provided by the FBI, have apprehended a suspected core member of the pro-Russian hacktivist syndicates CyberArmy of Russia Reborn (CARR) and Z-Pentest. While masquerading as ideologically motivated collectives, these groups have actively executed disruptive cyberattacks against critical infrastructure,

The Good, the Bad and the Ugly in Cybersecurity – Week 28 Read More »

HPC AI Workloads Need Runtime Security. The Architecture Already Exists.

The US Federal Government is committing $600 million to build one of the world’s most advanced AI infrastructure systems. Executive Order 14363, the Genesis Mission, connects national laboratory supercomputers across nuclear simulation, biodefense, energy grid modeling, and every major scientific domain. Fifty-one organizations signed on, including NVIDIA, OpenAI, IBM, Microsoft, AWS, Google, and Oracle. The

HPC AI Workloads Need Runtime Security. The Architecture Already Exists. Read More »

The Good, the Bad and the Ugly in Cybersecurity – Week 27

The Good | Authorities Apprehend Iranian Cybercriminal & Extradite UNC3944 Hacker Montenegrin law enforcement, alongside the FBI, have apprehended a 39-year-old dual Iranian and Turkish citizen wanted by the U.S. government for several cybercrime offenses. Arrested in Kotor, the suspect faces charges in the Southern District Court of New York for conspiracy to commit computer

The Good, the Bad and the Ugly in Cybersecurity – Week 27 Read More »

The Autonomous SOC, Revisited: What 18 Months on the Road Has Taught Us

This post revisits SentinelOne’s Autonomous SOC maturity model, first introduced in “Autonomous SOC Is a Journey, Not a Destination” (December 2024). When SentinelOne® introduced the Autonomous SOC maturity model, we made a deliberate choice: describe a journey, not promise a destination. The industry had no shortage of vendors declaring that AI would transform security operations.

The Autonomous SOC, Revisited: What 18 Months on the Road Has Taught Us Read More »

The Good, the Bad and the Ugly in Cybersecurity – Week 26

The Good | Authorities Dismantle Malware Networks and Seize Cambodian Scam Infrastructure Following the seizure of a major Phishing-as-a-Service last week, the latest move, part of Operation Endgame, dismantled operational infrastructure supporting the Amadey and StealC malware families. The joint effort by Europol and private sector partners successfully took 326 servers and 142 malicious domains

The Good, the Bad and the Ugly in Cybersecurity – Week 26 Read More »

The Good, the Bad and the Ugly in Cybersecurity – Week 25

The Good | Authorities Dismantle PhaaS Network & Clean Sites Infected with SocGholish A coordinated action between government and the private sector led by the FBI has led to the dismantling of Outsider Enterprise, a Chinese Phishing-as-a-Service (PhaaS) operation. Operating since 2023, the syndicate combined AI and distributed phishing kits to impersonate trusted brands across

The Good, the Bad and the Ugly in Cybersecurity – Week 25 Read More »

The Agentic SOC: Solving Security’s Investigation Capacity Crisis in the Frontier AI Era

The security industry spent the last decade solving detection. Endpoint. Cloud Workloads. Identities. AI. We built better models. We moved beyond signatures. We reduced false positives. We got the alert into the right queue. Then, we discovered the harder problem had been waiting behind it. The constraint in every SOC today is not detection. It’s

The Agentic SOC: Solving Security’s Investigation Capacity Crisis in the Frontier AI Era Read More »