Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The latest News and Information on Security Incident and Event Management.

How SLED can win the cybersecurity race with agentic AI

Adversaries are using AI to launch cyber attacks in record time, forcing security teams to measure responses in minutes instead of months. Phishing campaigns built with large language models (LLMs) achieve click-through rates 4.5 times higher than traditional methods,1 and the average time between initial compromise and lateral movement has fallen to just 29 minutes.2 This is a 65% increase from the prior year.2 State and local governments and higher education institutions are at an inflection point.

How to Improve MTTR: A Practical Guide for Security Teams

A critical alert enters the SOC queue during the overnight shift. By morning, the dashboard shows an acceptable headline MTTR because the incident was closed quickly after an analyst finally picked it up. The timeline tells a different story: the alert sat unassigned for nine hours because severity routing sent it to the wrong queue. The team optimized the visible number while leaving the dangerous delay untouched.

Agentic First Security -- Customer Brown Bag - August 20th, 2026

Join Jeremy Powell, CISO of Sumo Logic, to learn how AI-powered agents are reshaping modern security operations. Discover the key principles, governance, and best practices for building an agentic security program that enhances analyst productivity, accelerates threat response, and strengthens organizational resilience.

What Is a Security Operations Center? a 2026 Guide

A security operations center is a centralized function that continuously monitors, detects, investigates, and responds to cyber threats across an organization's environment. The global SOC market was valued at USD 42.85 billion in 2024 in one estimate and is projected to reach USD 91.88 billion by 2034, while another estimate places it at USD 52.3 billion in 2025 with a projection of USD 130.2 billion by 2034 (market estimate).

What Is SIEM and How It Works: Complete Guide 2026

SIEM is a platform that centralizes logs from across an environment, normalizes them, and correlates them in real time to surface threats and satisfy compliance audits. Gartner's 2024 reprint records SIEM market growth from $5.03 billion in 2022 to $5.7 billion in 2023, a 13% annual growth rate (Gartner's SIEM definition). You're likely dealing with the problem SIEM was built to solve.

What CRN's 2026 Annual Report Card Says About the Next Phase of AI Security

AI security is entering a more demanding phase. The market is moving beyond who can add AI to a product and toward who can make it useful in the real world — across existing security environments, partner ecosystems, and day-to-day operations. CRN’s 2026 Annual Report Card offers a useful snapshot of that shift. In the AI Security category, Exabeam earned the top overall score at 90.6, leading all four subcategories and every one of the 21 individual evaluation criteria.

GLBA Security Requirements: A 2026 Compliance Guide

The most popular advice about GLBA security requirements is also the least useful: review the policy annually, collect signatures, and keep the evidence in an audit folder. That approach may prove that someone approved a program. It doesn't prove that multifactor authentication protects every relevant system, that logs capture unauthorized access, or that the incident response team can identify a reportable event quickly enough to act.

Features Don't Win Budget Conversations. Operational Evidence Does.

CISOs can strengthen security budget conversations by replacing feature comparisons with measurable operational evidence. Establish the current burden, show how an investment changes security operations, and connect those improvements to financial impact. Metrics such as alert volume, analyst investigation time, manual effort, and capacity gained help CFOs evaluate security investments in terms of cost, benefit, predictability, and measurable business value. Every CISO has been there.

Antivirus and Firewall: Building Layered Defense with SIEM

“Install antivirus and enable the firewall” is still common security advice. It's also incomplete. Those controls can block malicious code and unwanted traffic, but they don't automatically connect an endpoint detection to the firewall event that preceded it, identify a compromised identity, or tell an analyst whether a policy change was legitimate.