Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

More Tools Never Fixed the SOC: The Bottleneck Was Never Visibility

Odysseus left Troy with a fleet and reached Ithaca with nothing, having lost every ship to the sea. While the war was won by force, the journey home was won by wits, and ultimately the fleet barely mattered. Most security operations centers are still running their SecOps voyage the way Odysseus ran the war: more tools, more force, more signal. It is the wrong instinct, because the SOC bottleneck was never how much you can see. It is how fast you can decide.

Arctic Wolf President & CEO Nick Schneider on AWS Security LIVE! at Black Hat USA 2026

The volume, velocity, and sophistication of cyber threats continue to grow. Security teams need a new approach. At AWS Security LIVE! during Black Hat USA 2026, Arctic Wolf President & CEO Nick Schneider joined Amazon Web Services' Jess Kubat, Ryan Orsi and Brian Mendenhall for a discussion on security operations at Machine Speed and how organizations can combine AI-powered capabilities with security expertise to stay ahead of modern threats.

What Is a Security Operations Center? a 2026 Guide

A security operations center is a centralized function that continuously monitors, detects, investigates, and responds to cyber threats across an organization's environment. The global SOC market was valued at USD 42.85 billion in 2024 in one estimate and is projected to reach USD 91.88 billion by 2034, while another estimate places it at USD 52.3 billion in 2025 with a projection of USD 130.2 billion by 2034 (market estimate).

The Tiered SOC Is Breaking: Why the Agentic SOC Is the Only Model Built for Machine-Speed Attacks

Twenty-two seconds. That’s the median time it now takes for one attacker to hand freshly compromised access to the next team in the chain, the group that drives toward ransomware. In 2022, that hand-off took more than eight hours. In 2025, it took twenty-two seconds. Now consider how the average security operations center (SOC) is structured to respond. An alert fires, lands in a queue, and waits for a Tier 1 analyst to triage it. It escalates to Tier 2 for investigation.

Slash Commands Bring Expert SecOps Workflows to Atlas

Security teams don't have a shortage of data. They have a shortage of time, repeatability, and senior expertise available at the exact moment an analyst needs it. That's the problem Atlas slash commands are designed to solve. With /hunt, /investigate, and /signal, Atlas turns a simple chat interaction into a guided SecOps workflow grounded in live endpoint state.

The Howler Episode 33 - Matt Setzer, SVP, Chief Architect

This month, we sit down with Matt Setzer, Senior Vice President, Chief Architect, to learn more about a day in the life of an architect, his philosophy on meaningful innovation, and so much more! Matt Setzer is SVP & Chief Architect at Arctic Wolf, where he partners with product and engineering leadership to set the technical strategy for the Arctic Wolf products and platform. Matt has spent the last twenty years in senior engineering and architect roles in the security space at Microsoft and Sophos. Prior to that he spent number of years working in the game industry.

Solving the SOC Data Problem: How Modern SIEM Platforms Cut Noise Without Cutting Visibility

Security teams have a data problem, not a detection problem. Most SOCs today aren't short on logs - they're drowning in them. Every firewall, endpoint, identity provider, and cloud workload generates a steady stream of events, and somewhere inside that noise sits the handful of signals that actually matter. The challenge isn't collecting more data. It's finding the right data fast enough to act on it.

Proving the value of security operations with Christopher Crowley [344]

Today we're speaking with Christopher Crowley, cybersecurity consultant through Montance and Senior Instructor with the SANS Institute, about the value of cybersecurity operations — how to measure it, how to express it to the business, and how AI is changing the work of the SOC.

Cybersecurity Threat Detection: A SOC Guide for 2026

You're probably living this already. Your SIEM is collecting more logs than anyone can read, your endpoint tool is firing alerts that look urgent until they aren't, and someone on the leadership team keeps asking whether the organization is “covered” without defining what covered means. That's the pressure behind cybersecurity threat detection in 2026. Teams don't need another disconnected console.

Is an AI SOC Better Than MDR? What Security Teams Should Weigh

Security teams are expected to investigate more alerts than they have people to handle. IBM's 2025 Cost of a Data Breach Report puts a number on what that gap costs: organizations take an average of 158 days to identify a breach, and a further 83 days to contain it. That is 241 days of exposure, the fastest pace in nine years, and still measured in months. For most SOC teams, the bottleneck was never finding threats. It was having enough people to do anything about them.

Arctic Wolf Cocktail Chats - Nick Schneider, President & CEO | Black Hat 2026

Arctic Wolf President & CEO Nick Schneider sits down with Ilina Cashiola, SVP of Corporate Marketing, for a cocktail chat at Black Hat USA 2026 to break down three major announcements shaping the next chapter of AI-led security operations.

Arctic Wolf Cocktail Chats - Dan Schiappa, President, Technology & Services | Black Hat 2026

Arctic Wolf President of Technology & Services Dan Schiappa sits down for a cocktail chat with Arctic Wolf SVP of Corporate Marketing Ilina Cashiola at Black Hat USA 2026 to break down the momentum behind the Aurora Agentic SOC and what's next for AI-led security operations.

Super Instinct Meets Super AI | Arctic Wolf Aurora

Attackers are using AI to move faster, scale broader, and automate attacks at machine speed, but no one wants fully autonomous AI making high-stakes decisions unchecked. There's a better way: Super Instinct meets Super AI. Meet the Aurora Agentic SOC, the world's largest commercial agentic SOC, built on the Aurora Superintelligence Platform. The completely new operating model pairs human instinct with AI-powered security operations to outperform human-only and AI-only approaches alike.

Introducing Agentic SecOps: Live Endpoint Truth for the AI-Driven SOC

Security operations teams are being asked to move faster than ever. Adversaries are using automation, infrastructure changes by the minute, and the number of alerts, exposures, and investigative paths keeps growing. But too many SOC workflows still depend on scarce expert time. A senior analyst writes the query, translates the hypothesis, pivots across tools, validates the result, and then hands the finding off for action. The craft works.