Skip to content
Insights · Security & SOC

Security & SOC — field notes from production detection.

SIEM, XDR, SOAR, and SOC engineering from the perspective of teams that have to defend their decisions in front of auditors and regulators.


What you need to know about security & soc

Security Operations Centers face a structurally hard problem: the volume of telemetry a modern enterprise generates exceeds what any analyst team can process manually, but the cost of a missed detection is catastrophic. Extended Detection and Response (XDR) platforms address this by correlating signals across endpoints, network, cloud, and identity — but correlation logic that works in a test environment often produces false positives at scale that erode analyst trust. The discipline of threat-informed detection, using frameworks like MITRE ATT&CK, creates detection content that is explicit about what attacker behaviour each rule targets. AiRAT's security engineering notes cover SIEM architecture, XDR deployment patterns, SOC automation, and the evidence and auditability requirements that enterprise and regulated financial institution SOC teams face in practice.


DateTopicArticle
Aug 2026Security & SOCCPS 234 Control Testing: The Evidence APRA-Regulated Entities NeedAug 2026Security & SOCEssential Eight Maturity Level 2 Assessment in 2026: Evidence Assessors Test and What ASD's New Essentials MeansAug 2026Security & SOCKeeping Security and Search Logs in Australia: Sydney, Melbourne, and APP 8Aug 2026Security & SOCAgentic SOC Maturity Model: Manual to AutonomousJul 2026Security & SOCCustom SIEM Integration Architecture: APIs to OCSFJul 2026Security & SOCSIEM Integration Guide: EDR, Cloud, Identity & ITSMJul 2026Security & SOCAI Security's Research-to-Production Gap: What to Test NowJul 2026Security & SOCMCP Security in 2026: Authorisation and Trust BoundariesJul 2026Security & SOCSecuring AI Infrastructure: Cloud & Data-Centre ChecklistJul 2026Security & SOCRed vs Blue vs Purple vs White Team: Which Do You Need?Jul 2026Security & SOCAI Is Compressing Cyberattack TimelinesJun 2026Security & SOCRBI Model Risk: AI Security Controls for Banks & NBFCsJun 2026Security & SOCContinuous AI Security Testing: Beyond One-Time GuardrailsJun 2026Security & SOCAI Red Teaming in 2026: Models, RAG, Memory, AgentsJun 2026Security & SOCAgentic AI Security in 2026: A Control Plane for Identity, Tools, Memory and ActionsMay 2026Security & SOCDeepfake-Resistant Authentication: Securing Enterprise Identity in 2026Feb 2026Security & SOCBuilding a Threat-Informed Detection Engineering PracticeJul 2025Security & SOCSOC Automation That Survives the Audit: Evidence, Not Theatre

Using these insights in your work?

If an article surfaces a problem you're dealing with, bring it to a call. We scope problems before we discuss solutions.

Get started

Leave your email - we'll reach out.

Share your work email and we'll follow up with a tailored note on security, AI, or data programmes - usually within one business day.

No spam. We only use your email to respond to this request.

Explore services →