Writing

Blog

Thoughts on building things, breaking things, and the occasional rabbit hole.

Filter
Aug 28, 2026SOCmateAI SOCTelemetryData Engineering
Why Your SOC Isn’t Ready for AI (And What to Build First)

AI is being hailed as the silver bullet that will rescue your SOC or MSSP. It won't - not without groundwork. The real question isn't whether the technology works, it's whether your team and your telemetry are actually ready for it.

Aug 8, 2026SOCmateAPI ManagementLeast PrivilegeBlast RadiusSOC
The God Key Problem: Scoping API Credentials in a SOC

Generating an admin-level API key is the path of least resistance when wiring up a new SIEM, EDR, or SOAR integration. But in a SOC, that credential doesn't stay in a sandbox - it lives in cron jobs and automation playbooks. Scoping by action, gating destructive operations behind approval, and failing cleanly on vendor outages isn't compliance theater, it's operational armor. Part 2 of a series on SOC API management.

Aug 1, 2026SOCmateAPI ManagementSchema ValidationSOC
Schema Drift: The Silent Bug

A vendor renames one field in their payload and your enrichment pipeline goes silently blind for weeks. Why schema drift is the norm, not the edge case - and how to make integrations fail loud instead of failing quiet. Part 1 of a series on SOC API management.

Jul 28, 2026SOCmateComplianceEU AI ActAI SecurityMarketing
The Rift Between Compliance and Marketing: Why We Love Magic

Why do we fall for Black Box AI pitches? A look at the dissonance between the EU AI Act, ACN's push for resilience, and marketing that sells AI-powered unicorns.

Jun 23, 2026SOCmateSOC OperationsSOARAI SOCAutomation
The 6-Month Delusion: Why Your SOC Automation Is Already Obsolete and Why You Should Be Wary of 'AI SOC'

The average eCrime breakout time is 29 minutes. Yet the legacy SOAR pitch still demands 6–12 months before a single playbook runs. Here's why the 'AI SOC' magic act is the next trap - and what measuring accountability actually looks like.

Apr 1, 2026LinkedInSOCDataSIEM
Why Normalization is a "Bummer"

Normalization is every SOC Manager's dream. As a developer, I love a clean schema. But real life is less about 'tada' moments and more about APIs with data structures that seem designed specifically to give devs a headache.

Mar 1, 2026LinkedInAIAutomation
AI Doesn't Reduce Work - It Intensifies It

Researchers spent eight months inside a 200-person tech company watching what happened when employees got access to generative AI. Workers consistently worked faster, took on more, and stretched into more hours - entirely on their own initiative. Because AI made 'doing more' feel possible. That's the trap.

Jan 29, 2026SOCmateWazuhMSSPSIEMAutomation
Automating Multi-Tenant Wazuh: A Practical Guide

How to provision isolated customer environments on a shared Wazuh SIEM in minutes - step-by-step manual walkthrough, then a single-command automation tool.

Dec 19, 2025MediumAICreativity
Are You Really as Original as You Think?

25 state-of-the-art AI models. 1,250 responses to the same question. Two unique answers. The NeurIPS 2025 Best Paper proves AI is creating a thought monoculture - and what that means for your business differentiation.

Dec 15, 2025SOCmateSOCCybersecurity
The SOC Hero Problem

Every SOC has one. The analyst who builds the integrations nobody else understands, writes the scripts that hold everything together, and quietly becomes a single point of failure. The dark side nobody talks about.

Dec 2, 2025SOCmateSOCAlert FatigueAI
Alert Fatigue - An Inevitable Base Rate Problem

Even with 99% accurate detection, when threats are rare the math guarantees a flood of false positives. Alert fatigue is not an operations failure - it is a base rate problem. The question is how to manage it intelligently.

No sales pitch.

Direct work with SOC teams who want their AI to be accountable - not just deployed.

Get in touch