Research & field notes
Practical thinking for
security leaders.
Original analysis on SOC transformation, Microsoft security, detection engineering and human-governed AI.

01 / NewsletterAugust 6, 2026
From AI SOC Analyst to Everyday Workflows: Building Secure AI Skills for Real Work
Useful agents need narrow skills, bounded access, evidence, approval gates and an operating model suited to the data they handle.Read insight
02 / Field noteAugust 6, 2026
Every Closed Incident Should Improve the Detection System
A closed incident that teaches nothing is a missed detection-engineering opportunity.Read insight
03 / Field noteAugust 4, 2026
Free Code, Real Responsibility
Open-source security cannot depend on exhausted maintainers, and using free software does not transfer accountability for its risk.Read insight
04 / Field noteJuly 28, 2026
The Next Major Security Incident May Begin With an AI Agent
AI agents can access data, call APIs and execute actions. Security leaders must govern their identities, tools and autonomy before an incident tests the boundaries.Read insight
05 / Field noteJuly 27, 2026
Treat Every AI Agent as a Non-Human Identity
AI agents are becoming digital employees, but many organisations grant them access before establishing identity, observability and governance.Read insight
06 / NewsletterJuly 26, 2026
How Agentic AI Can Transform Security Incident Investigations
A practical architecture for moving from alert enrichment to adaptive investigation, contextual risk scoring, governed remediation and measurable SOC outcomes.Read insight
07 / NewsletterJuly 16, 2026
Why Traditional SOC Operations Are No Longer Enough
Four operational use cases and a phased blueprint for combining better detections, reliable automation, Agentic AI and human expertise.Read insightContinue the conversation