Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Ep 7: SOAR Loser: Does the O in SOAR stand for obsolete?

SOAR might sound like a superhero for security teams, but is it actually flying too close to the sun? In this episode, Adam and David unpack why security orchestration, automation, and response have been helpful… but might be headed for retirement, thanks to AI shaking up the game. They also dig into the headaches of managing clunky SOAR systems and why it’s time to rethink workflows and case management before you get left in the dust.

The New CISO Podcast Ep.133 - Steve Lodin | Teachable Moments: How to Learn from Career Challenges

In this episode of The New CISO, host Steve Moore speaks with Steve Lodin, VP of Information Security at Sallie Mae, about the career challenges that shaped his leadership style and the lessons he’s learned across decades in cybersecurity.

Building effective threat hunting and detection rules in Elastic Security

Learn to create custom detection rules in Elastic Security following real detection use cases. This blog will guide you through creating custom detection rules in Elastic Security, equipping you with best practices for using Elasticsearch Query Language (ES|QL) and Elastic AI Assistant to refine threat detection logic and add crucial context for analysts. You’ll learn how to effectively preview, test, and enhance your rules, ultimately strengthening your security operations.

Ep 6: Security haven or horror story: from SIEMs to lakes to lakehouses

Between SIEMs, data lakes, and data lakehouses, the buzzwords alone could fill a glossary. In this episode, Adam and David break down the real differences between data lakes and SIEM systems and why effectively managing all that data is crucial for staying visible and secure. They also dive into how AI is shaking up the game and why picking the right tools can mean the difference between being overwhelmed and being in control.

Advanced Persistent Threat: What They Are and Why They Matter

Nearly everyone has had “that cold,” the one where most symptoms have resolved except that lingering cough. The cough can continue for weeks or months, all while you feel mostly well across the board. In cybersecurity, an advanced persistent threat (APT) is your IT environment’s lingering cough, albeit a much more damaging one. An APT stealthily gains initial access to your company’s systems and networks, then hides within them to complete objectives.

Elastic joins AWS Zero Trust Accelerator for Government (ZTAG) program

Strategic collaboration to advance security information and event management (SIEM) integration specifically tailored for the US federal government's Zero Trust architecture Elastic is proud to be officially recognized as an AWS Zero Trust for Government partner and for onboarding into the AWS Zero Trust Accelerator for Government (ZTAG) program in the US.

Defending Against SCATTERED SPIDER with Falcon Next-Gen SIEM

SCATTERED SPIDER is a prolific eCrime adversary that has conducted a range of financially motivated activities beginning in early 2022. Since surfacing, this adversary continues to compromise organizations around the world, deploying ransomware and exfiltrating sensitive files.

SIEM isn't dead. It's reborn and finally worth using.

The question isn’t whether security information and event management (SIEM) is dead. The real question is whether the traditional model of SIEM still serves today’s defenders. Spoiler alert: it doesn’t. Born from compliance needs and static rules, first-generation SIEMs provided log collection and correlation but not context. They buried analysts in noise and left threat detection slow, brittle, and expensive. But that’s changing.

Understanding Network Vulnerabilities and Mitigating Their Risks

Driving along on a dark highway late at night, you feel a jolt and hear a metallic crushing sound as your car hits an unknown object in the road. You nervously continue on your journey, until you see a bright light flashing on your dashboard. Your oil pressure is low because your car has been leaking oil since you hit that unknown object on the highway. Much like an unknown object in the road that leads to a slow leak, a network vulnerability can lead to a devastating data leakage or breach.

Exabeam Demo: AI-Driven Behavioral Analytics for Smarter SOC Decisions

Designed for cybersecurity leaders and SOC decision makers, this walkthrough highlights how the Exabeam New-Scale Security Operations Platform transforms threat detection, investigation, and response. Key capabilities featured: Threat Center Workbench: Monitor high-value users and entities with real-time insights. Behavioral Risk Scoring: Combine statistical rarity with business context for smarter triage.

Automated Threat Timelines in Minutes | Exabeam Nova vs. Manual Investigation

Manual timelines are history. Exabeam Nova uses machine learning and a patented session data model to automatically build complete threat timelines—saving analysts hours and boosting confidence. From hours to minutes Auto-correlated detections and entities Subscribe for more product demos and cybersecurity insights!

Open and Agnostic SIEM Platform | Exabeam vs. Locked Ecosystems

Escape the SIEM walled garden. The New-Scale Security Operations Platform by Exabeam is open and agnostic supporting over 600 pre-built integrations and flexible APIs to meet your unique stack and threat intelligence needs. Open ecosystem Cross-vendor automation Subscribe for more product demos and cybersecurity insights!

Search Your SIEM with Plain English | NLP in Exabeam Nova Makes It Easy

Search security data like you speak. Exabeam Nova enables natural language processing (NLP) for investigations so analysts can ask questions in plain English and instantly generate reports, dashboards, and queries. No query language needed Ask, analyze, act Subscribe for more product demos and cybersecurity insights!

Visualize MITRE ATT&CK Coverage with Outcomes Navigator | Improve Your Security Posture

Detection is just the start. Exabeam Outcomes Navigator maps your tools and data to real security outcomes — like MITRE ATT&CK coverage and top use cases — to help you identify strengths and close gaps. Real-time roadmap to stronger security Visualize outcome-based coverage Subscribe for more product demos and cybersecurity insights!

Fast, Code-Free SIEM Integrations with OpenAPI | Exabeam Automation Management

Sick of slow, expensive integrations? Exabeam is the first SIEM to support the OpenAPI standard—making it easy to connect to Jira, ServiceNow, CrowdStrike, and thousands of other tools with no custom code. Fast, flexible integrations Build and test automations in one place Subscribe for more product demos and cybersecurity insights!

Exabeam Nova Automates Investigations | AI-Generated Threat Summaries Explained

Can your SIEM generate a threat summary before the analyst even starts investigating? Meet Exabeam Nova — the industry’s first multi-agent AI platform that delivers proactive, clear, and actionable summaries to speed up investigations and reduce analyst burnout. AI-generated investigation summaries Boost SOC productivity and morale Real Intelligence. Real Security. Real Fast. Subscribe for more product demos and cybersecurity insights!

How Exabeam Builds Dynamic Threat Timelines with AI | Say Goodbye to Alert Fatigue

Over 100 vendors claim to have a SIEM. Most can't deliver. See how Exabeam Threat Center uses AI and behavioral analytics to automatically build dynamic threat timelines to reduce alert fatigue, false positives, and triage time. Prioritize threats by risk score Automate correlation across users, assets, and events Real Intelligence. Real Security. Real Fast. Subscribe for more product demos and cybersecurity insights!

How to reduce alert overload in defence SOCs

AI-powered triage, faster insights, and the headspace your analysts need If you’re a security leader or analyst within the defence space, you likely brace yourself for a daily battle with alert overload — and you’re not alone. Analysts face a relentless flood of notifications with the majority turning out to be false positives. Studies show that 71% of SOC personnel1 experience burnout and report feeling overwhelmed by alert volume.

From weeks to minutes: How Sumo Logic's historic baselining supercharges UEBA

Spotting threats fast and knowing whether they really matter is the name of the game in cybersecurity. That’s where user and entity behavior analytics (UEBA) comes in, and why Sumo Logic’s latest innovation, historic baselining, is a big deal. With this release, Sumo Logic has turned the old UEBA model on its head, delivering insights that used to take weeks of learning time in just minutes. Here’s how and why that’s a game changer.

Ep 4: Stop writing dumb AI security policies: use threat models, not fear

AI policy is not a yes/no question. Security isn’t here to be the morality police. Our job is to enable the business safely. Join security experts Adam White and David Girvin as they chat about the importance of using threat models, a simple framework, and five policy areas you are probably ignoring.