• The SIEM Dilemma: Why Modern SOCs Are Drowning in Data and Starved for Context

    The SIEM Dilemma: Why Modern SOCs Are Drowning in Data and Starved for Context

    For over two decades, the SIEM (Security Information and Event Management) system has served as the heart of the SOC (Security Operations Center) – and why not? It promised to aggregate logs from every server, firewall, router and app into a central repository that you could easily search and gain visibility into enterprise risk. Unfortunately, for many, it failed to fulfill its prophecy, let’s look into why!

    -> EXAMINE_LOG
  • Shadow AI: The New Perimeter No One is Guarding

    Shadow AI: The New Perimeter No One is Guarding

    If there’s one thing my years in operational IT taught me, it’s that when security gets in the way of productivity, users will always find a workaround. Right now, Shadow AI is the ultimate example of that friction. Developers aren’t pasting proprietary code into LLM prompts to breach the company; they’re doing it at 2:00 AM because they just want to ship their sprint on time. Blocking AI entirely is…

    -> EXAMINE_LOG
  • Case #003: The Key to the Kingdom

    Target: Microsoft Date: January 2024 Threat Actor: Storm-0558 / Midnight Blizzard (Russian SVR) Attack Vector: Stolen Signing Key & Non-Human Identity Exploitation Impact: Widespread geopolitical fallout, severe reputational damage and…

  • Case #002: Trojan Supply Chain Attack

    Target: SolarWinds (and ~18,000 downstream customers) Date: December 2020 Threat Actor: APT29 / Cosy Bear / Nobelium (Russian SVR) Attack Vector: Software Supply Chain Compromise (Code Build Injection) Impact: Estimated…

  • Case #001: The $100 Million Phone Call

    Target: MGM Resorts International Date: September 2023 Threat Actor: Scattered Spider / ALPHV Attack Vector: Voice Phishing (Vishing) & MFA Bypass Impact: $100m+ operational loss

Scroll to Top