Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The latest News and Information on Security Incident and Event Management.

Exabeam vs. Splunk: Which Approach Improves Security Operations Outcomes?

Not every SIEM solution is built for modern security operations. While Splunk is widely used for log management, many teams face unpredictable pricing, complex tuning, and slow investigations as environments scale. New-Scale Fusion takes a different approach, It combines behavioral analytics, dynamic risk scoring, and coordinated AI agents to help teams detect risk earlier and move investigations forward faster. Here are six ways Exabeam improves outcomes compared to Splunk.

HIPAA Compliance Reporting: A Playbook for Security Teams

A healthcare security team rarely gets a clean warning before hipaa compliance reporting becomes real. One week it's a patient complaint about access, the next it's an OCR request for records, and the next it's a suspected breach that needs a defensible timeline, not a scramble for screenshots. In that environment, a SIEM is more than a detection tool, it's the system that turns logs, alerts, and evidence into a reporting record auditors can follow.

Mastering Baseline Configuration Management in Hybrid IT

Your audit passed last quarter because the screenshots matched the baseline. Then someone pushed an emergency firewall tweak, a legacy admin account came back, and no one recorded the exception. By the time operations noticed the drift, the environment no longer matched the documentation, and the control that was supposed to prove stability had become part of the problem.

How we brought agentic workflows to Cloud SIEM with the Datadog MCP Server

Security engineers using Cloud SIEM spend their day-to-day investigating signals, tuning detection rules, managing suppressions, running historical jobs across interconnected workflows, and more. Agents are becoming a practical way to navigate that complexity, and we built a set of security tools for the Datadog MCP Server to support them. Cloud SIEM is only one part of a broader cloud security ecosystem, so the Security MCP toolset has to grow across many teams and products.

The New CISO Ep. 148 - Lou Rabon | How Many Tokens to Breach Your Network?

What if your next breach came down to a token budget? In this episode, Steve Moore is joined by Lou Rabon, Founder and CEO of Cyber Defense Group, for a conversation on the modern CISO's world—from how to interview for the seat, to why AI agents are the next insider threat, to research that reframes breach cost as a token calculation.

Suricata IDS/IPS Data in Graylog

If you’re running Suricata to watch your network, you already know how much signal lives in its logs. Graylog provides a purpose-built way to make that signal immediately actionable. The Suricata IDS/IPS Content Pack, available with an Illuminate license and Graylog Enterprise or Graylog Security, delivers ready-to-use parsing rules, streams, GIM categorization, and a dashboard so you can turn raw Suricata EVE JSON events into structured, searchable security intelligence.