Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The latest News and Information on Security Incident and Event Management.

What Is Noise Reduction in SIEM and Security Monitoring

A SOC analyst starts a shift with a queue full of alerts. The first few investigations reveal repeated authentication failures from the same service account, blocked network scans from a known internal scanner, and endpoint events that three different sensors reported separately. Somewhere in that queue may be a real compromise, but the analyst has to work through the noise before finding it.

Living Off the Land Attacks: Detection and Response Guide

The most popular advice about living off the land attacks is also the least useful when it stands alone: hunt for suspicious PowerShell, block LOLBins, and alert whenever a signed Microsoft binary behaves unexpectedly. Those controls have value, but they don't solve the operational problem. PowerShell, WMI, certutil.exe, and bitsadmin.exe are legitimate administrative utilities, and attackers abuse them precisely because security teams can't remove them without disrupting normal work.

How SLED can win the cybersecurity race with agentic AI

Adversaries are using AI to launch cyber attacks in record time, forcing security teams to measure responses in minutes instead of months. Phishing campaigns built with large language models (LLMs) achieve click-through rates 4.5 times higher than traditional methods,1 and the average time between initial compromise and lateral movement has fallen to just 29 minutes.2 This is a 65% increase from the prior year.2 State and local governments and higher education institutions are at an inflection point.

How to Improve MTTR: A Practical Guide for Security Teams

A critical alert enters the SOC queue during the overnight shift. By morning, the dashboard shows an acceptable headline MTTR because the incident was closed quickly after an analyst finally picked it up. The timeline tells a different story: the alert sat unassigned for nine hours because severity routing sent it to the wrong queue. The team optimized the visible number while leaving the dangerous delay untouched.

Agentic First Security -- Customer Brown Bag - August 20th, 2026

Join Jeremy Powell, CISO of Sumo Logic, to learn how AI-powered agents are reshaping modern security operations. Discover the key principles, governance, and best practices for building an agentic security program that enhances analyst productivity, accelerates threat response, and strengthens organizational resilience.

What Is a Security Operations Center? a 2026 Guide

A security operations center is a centralized function that continuously monitors, detects, investigates, and responds to cyber threats across an organization's environment. The global SOC market was valued at USD 42.85 billion in 2024 in one estimate and is projected to reach USD 91.88 billion by 2034, while another estimate places it at USD 52.3 billion in 2025 with a projection of USD 130.2 billion by 2034 (market estimate).

What Is SIEM and How It Works: Complete Guide 2026

SIEM is a platform that centralizes logs from across an environment, normalizes them, and correlates them in real time to surface threats and satisfy compliance audits. Gartner's 2024 reprint records SIEM market growth from $5.03 billion in 2022 to $5.7 billion in 2023, a 13% annual growth rate (Gartner's SIEM definition). You're likely dealing with the problem SIEM was built to solve.

What CRN's 2026 Annual Report Card Says About the Next Phase of AI Security

AI security is entering a more demanding phase. The market is moving beyond who can add AI to a product and toward who can make it useful in the real world — across existing security environments, partner ecosystems, and day-to-day operations. CRN’s 2026 Annual Report Card offers a useful snapshot of that shift. In the AI Security category, Exabeam earned the top overall score at 90.6, leading all four subcategories and every one of the 21 individual evaluation criteria.