2026
09 May 2026 Terminal as the workbench SOC platforms spent years building the 'single pane of glass'. OpenCode, Claude Code, and Codex built it in a terminal. The analysts who noticed are not waiting around. 08 May 2026 What it means to be a PM, and how AI changed my answer Shreyas Doshi's definition of a PM is the best I've found. But AI has added a dimension to it that changes what the job actually looks like day to day. 01 May 2026 The false positive problem is a product problem SOC teams don't have an alert volume problem. They have a fidelity problem. Those are different things, and the fix is different too. 15 Apr 2026 What it actually means to be embedded with your users Everyone says 'talk to your users'. Fewer PMs mean sitting inside the team that does the work every day and letting that reshape the roadmap. 10 Mar 2026 Velocity is a product requirement AI doesn't just make individual tasks faster. It changes what a small team can credibly take on. That changes the PM's job. 01 Mar 2026 Platform thinks, analyst decides The right division of labour between AI and humans in security operations. What to automate, what to surface, and why the reasoning must always be visible. 03 Feb 2026 The fidelity flywheel Closing alerts is table stakes. The best operators are the ones who make the queue smarter over time. That only works if the platform makes tuning frictionless.
2025
11 Oct 2025 One surface, no context switches When a security analyst has to move between eight tools to close a single case, that is not a process problem. It is a product failure. 10 Oct 2025 Four types of security operator Security operations is not a single job. It is a spectrum of people asking completely different questions with the same data. Building for all of them requires understanding which one to serve first. 09 Oct 2025 External Introducing REACT: why we built an elite incident response team Cloudforce One launches REACT, a team of expert security responders that eliminates the gap between perimeter defense and internal incident response. Network-native mitigation, vendor-agnostic scope, and threat intelligence built into every engagement.
2024
15 Aug 2024 Security tools win on tolerance, not affection Operators don't leave their incumbent platforms because they love them. They stay because switching costs are real. That changes how you should think about building in this space. 12 Jul 2024 External Security in six: NIST 2.0 The updated NIST CSF reorganises cybersecurity into six core functions, with Govern as the new first step. A look at why governance now leads the conversation, and what that means for how organisations approach security. 29 Apr 2024 External NIST 2.0 as a framework for all The updated NIST Cybersecurity Framework is no longer just for federal agencies or critical infrastructure. It is now designed for any organisation managing cyber risk, and the new Govern function changes how security fits into enterprise strategy.