The Ultimate Guide to Security Operations Centres
A curated American edition of TechDay news, analysis, interviews, reviews, job moves, and related resources for Security Operations Centres (SOCs).
What to know about Security Operations Centres
A Security Operations Centre (SOC) serves as the critical hub for monitoring, detecting, and responding to cybersecurity threats within organisations. Covering a wide spectrum of digital environments, SOCs integrate advanced technologies such as AI, machine learning, and automation tools to enhance threat detection and incident response capabilities.
Exploring recent developments in this field reveals insights on evolving challenges like alert fatigue, skills shortages, and the increasing complexity of cyberattack surfaces. Readers can learn how organisations leverage innovations in SOC-as-a-Service, AI-driven threat hunting, and next-generation platforms to build adaptable, efficient security operations tailored to their needs.
Whether you are an IT professional, security analyst, or business leader, following stories under the 'Security Operations Centre' tag offers valuable perspectives on managing cyber risk, improving operational efficiency, and preparing your organisation for the dynamic cybersecurity landscape ahead.
American Security Operations Centres News
Regional stories with direct local relevance
Executives & staff split on AI cyber risk at DNSFilter
A new survey shows IT managers are far more concerned than executives about unreported incidents, shadow AI and attackers' use of AI.
Greenwich Pacific launches cyber-recovery service for banks
US banks are under pressure to prove systems can be restored quickly as regulators and counterparties demand tested resilience, not paper plans.
Thrive appoints John Toney as security services chief
The hire deepens Thrive's push into cybersecurity as customers seek outside help with threat detection, response and risk management.
Manifold Security appoints Joe Sullivan to its board
The move bolsters Manifold's push to help enterprises police AI agents, as concern grows over how autonomous software behaves at work.
Netcraft wins five more top US banks as takedowns rise
Banking groups are increasingly paying for rapid removal of phishing and impersonation scams as AI-driven attacks spread across multiple channels.
Red Sift brings OnDMARC to Microsoft Sentinel Marketplace
Microsoft security teams can now ingest email authentication signals in one place, helping spot phishing and spoofing sooner during investigations.
Analyst Insights
Research and market analysis connected to Security Operations Centres
Thrive bolsters NextGen platform with Elastic, Cato
Thrive adds Elastic & Cato to NextGen security platform
Fortinet named Gartner Leader in hybrid mesh firewall
Check Point named Leader in Gartner hybrid mesh firewall
Embedded systems hit USD $585 billion as edge AI grows
Featured News
Zscaler takes zero trust beyond the corporate network
Critical infrastructure operators are using cellular links to secure distributed assets as outages and spoofing raise the stakes for resilience.
Mimecast CEO: Agentic AI threat novel but not entirely new
Hidden AI risks are already widespread in workplaces, with Mimecast saying users are driving shadow tools and most exposure still starts with people.
Lumana's focus on vertical applications for AI video surveillance platform
Lumana's Principal Product Manager says its camera-agnostic AI platform is expanding beyond security into retail, healthcare and smart cities.
AI arms race forcing businesses to rethink cybersecurity
Security teams are racing to shrink exposure windows as AI makes newly disclosed vulnerabilities exploitable almost immediately.
Check Point CTO on AI's double-edged sword
AI is shrinking the gap between vulnerability disclosure and real-world exploitation to hours, forcing security teams to adapt fast.
Check Point: Be the best, or get out the way
Rising AI-driven attacks are compel security buyers to cut vendor sprawl, though Check Point warns over-consolidation can still raise risk.
Check Point: Hackers are already in. Act accordingly
Hackers are exploiting vulnerabilities in hours or minutes, leaving many organisations compromised before defenders spot the breach.
Visa strengthens AI defences amid new era of cyber threats
Visa is pouring billions into AI defences as regulators demand safer, auditable systems to counter faster cyber threats and fraud.
Reviews
Expert Columns
The autonomous SOC takeover
How security leaders should measure AI SOC performance
AI closes vulnerability window as zero-day exploits surge
The future of autonomous security
Singapore's security teams are losing a race they don't know they're running
When AI memory, simulation and provenance collide
Supercharged security: Cyber risk in the age of frontier AI
The cost of false positives in DSPM
The post-quantum mandate isn't about algorithms, it's about operational trust
Why faster AI is exposing slower security thinking
Interviews
Interviews and video coverage from the networkRecent Security Operations Centres News
Qualcomm launches dual Snapdragon 8 Elite Gen 6 chips
Premium Android handsets are set to get more on-device AI and imaging tools as Qualcomm adds a second flagship chip option for makers.
Proofpoint launches AI security system for data risk
As AI tools gain access to sensitive systems, Proofpoint says separate data and oversight products no longer catch the full risk.
Rockwell study flags cybersecurity as industrial growth risk
More than a third of industrial decision-makers now see cyber risk as a top barrier to growth, a Rockwell survey found.
Akamai warns of blind spots in workplace agentic AI
More than 40% of enterprise users have installed AI browser tools, leaving security teams struggling to spot permission changes and rogue agents.
Honeywell flags OT cybersecurity visibility gap in industry
Incomplete asset inventories are leaving industrial operators exposed, with only 21% able to track every OT system despite 88% calling programmes mature.
AI agents top insider risk concern for security chiefs
Surveyed firms are struggling to spot when autonomous tools stray from approved tasks, as 48% of security leaders now rank them as their biggest insider threat.
Dragos buys NetRise & runZero to boost xOT security
Critical infrastructure operators gain broader visibility across devices, firmware and cloud systems as Dragos folds two specialist tools into its platform.
Rockwell joins Anthropic's Project Glasswing programme
Industrial control systems could be patched faster as Rockwell tests controlled access to Claude Mythos 5 to spot flaws before attackers exploit them.
Integrity360 rebrands Advantus360 in Canada after buyout
Canadian customers gain access to a larger cyber security and identity services team as Calgary becomes Integrity360's North American base.
Google warns AI is reshaping cyber attacks & defences
Attackers are exploiting AI tools to speed intrusions and drain cloud resources, pushing defenders towards machine-speed security operations.
Mandiant warns of AI agents fuelling new attack risks
Autonomous systems are now creating fresh avenues for code theft, remote execution and runaway cloud spending, Mandiant says.
Horizon3 links NodeZero to CrowdStrike Falcon SIEM
Security teams can now compare validated exposure findings with endpoint and cloud telemetry after Horizon3 tied NodeZero into CrowdStrike's SIEM.
AI agents now seen as biggest insider risk, Exabeam
Nearly half of security leaders now rank AI agents above external hackers and malicious insiders, according to Exabeam's survey.
Microsoft & Google use shared exchange to hit RedVDS
Criminal access to thousands of Microsoft accounts was cut off after the companies shared threat data through the Global Signal Exchange.
Tanium tests Anthropic AI for code vulnerabilities
By probing its own production code, Tanium is aiming to catch flaws before attackers can exploit software used by thousands of organisations.
Okta expands identity governance & access security
Security teams face tighter control over cloud and AI access as Okta adds automation to cut manual reviews and curb credential abuse.
Rubrik launches Code Guardian & expands Anthropic ties
The private previews aim to help security teams spot exploitable code chains and connect AI agents to Rubrik's governance tools more safely.
Hexnode launches Synapse AI layer for IT workflows
It aims to cut manual handoffs in onboarding, access changes and incident response by linking multiple enterprise tools under one AI layer.
Connected vehicle cloud market set to hit GBP £573bn
Automakers' shift to software-defined cars is driving demand for remote updates, diagnostics and digital services across fleets.
Proofpoint expands insider-risk tools to Microsoft 365
Investigators will get a fuller audit trail as the software links Microsoft 365 activity and AI prompts with emails, files and logs.
Job Moves
Thrive appoints John Toney as security services chief
Manifold Security appoints Joe Sullivan to its board
Ondaro promotes three to vice president in ServiceNow shift
Jazz appoints six senior leaders as DLP push scales
iCOUNTER names Ali Waezzadah as Chief Information Security Officer
1Kosmos names Roger Hale as Chief Information Security Officer
CodeHunter appoints Anurag Jain as Engineering Chief