flâneur — a map of the web's best reading

AI-Powered SOC: it's the end of the Alert Fatigue as we know it? | by Alex Teixeira | Apr, 2024 | Detect FYI

medium.com · saved by 1 readers

That's actually a pretty valid question, especially when it comes from cybersecurity leaders or project sponsors. It not only serves as an entry-point for the quantity x quality discussion, but also hints on how far a team has gone in terms of engineering throughput. Yet that metric could turn into the fastest route to Alert Fatigue since it essentially suggests more detection — not better detection. Many topics I approach here are about requests or discussions I face as an independent security consultant. But before getting into it, let's explore a few challenges around Detection Engineering and Security Analytics practices so that hopefully you will be able to see things a bit differently. Feedback always welcome! In project management, the demand for new features or changes is sometimes challenging to manage. Among other issues, it goes up to a point that delivery quality starts to noticeably and significantly drop. That phenomena is known as Scope Creep. Similarly, after crossing t

That's actually a pretty valid question, especially when it comes from cybersecurity leaders or project sponsors. It not only serves as an entry-point for the quantity x quality discussion, but also hints on how far a team has gone in terms of engineering throughput. Yet that metric could turn into the fastest route to Alert Fatigue since it essentially suggests more detection — not better detection. Many topics I approach here are about requests or discussions I face as an independent security consultant. But before getting into it, let's explore a few challenges around Detection Engineering

Explore this link on the map →