-
How to Build an Insider-Risk Programme That Actually Catches the Bad Cases
Most insider-risk programmes are aimed at the wrong target. The detection engineering is theatre. The behavioural analytics are noise. The case management is a black hole. Here is how to build a programme that finds the cases that actually matter
-
How to Hire a Detection Engineer When You Have Never Hired One Before
Most detection engineer hiring fails because the job description is wrong. Here is what to actually look for, what to test in the interview, and the most common mistakes programmes make on the first hire
-
Tabletop Exercises That Actually Prepare You for an Incident
Most tabletops are theatre. A senior person reads a scenario, the room talks through what they would do, nobody changes anything, and the postmortem is a one-pager that says 'we are well prepared.' Here is how to run one that is not theatre
-
The Six-Month Build: What a Real Detection Engineering Programme Looks Like
Most 'detection engineering programmes' are not programmes. They are a person with a Sigma rule and a prayer. Here is what a real six-month build looks like, in order, and what each phase actually costs
-
What a Good Detection Engineer Actually Does All Day
The job description for a detection engineer reads like a software engineer with a security focus. The actual job is more like an editor at a small newspaper. Here is what the work looks like when the title is right and the work is also right
-
Building a Detection Baseline: The Work Nobody Wants to Do
Every detection engineer has been told to build a baseline. Almost nobody has been given a clear answer about what a baseline actually is, what data it needs, or how it connects to the rules the SOC actually runs. Here is the honest version of the work
-
How to Write a Purple Team Report That Actually Gets Read
You ran a three-week purple team exercise. Your team worked hard. The red team executed a realistic adversary emulation. Your blue team detected some of it, missed most of it, and the gaps are clear. The debrief went…
-
Living Off the Land: Why the Best Attackers Don't Look Like Attackers
Volt Typhoon maintained access to critical infrastructure networks in the United States for at least five years. Microsoft, Mandiant, and the Five Eyes governments published the technical details in 2024. The…