DiscoverCloud Security Podcast by GoogleEP263 SOC Refurbishing: Why New Tools Won't Fix Broken Processes (Even With AI)
EP263 SOC Refurbishing: Why New Tools Won't Fix Broken Processes (Even With AI)

EP263 SOC Refurbishing: Why New Tools Won't Fix Broken Processes (Even With AI)

Update: 2026-02-16
Share

Description

Guest:

Topics:

  • What is the right way for people to bridge the gap and translate executive dreams and board goals into the reality of life on the ground?
  • How do we talk to people who think they have "transformed" their SOC simply by buying a better, shinier product (like a modern SIEM) while leaving their old processes intact?
  • What are the specific challenges and advantages you've seen with a federated SOC versus a centralized one? What does a "federated" or "sub-SOC" model actually mean in practice?
  • Why is the message that "EDR doesn't cover everything" so hard for some people to hear? Is this obsession with EDR a business decision or technology debt?
  • How do you expect AI to change the calculus around data centralization versus data federation?
  • What is your favorite example of telemetry that is useful, but usually excluded from a SIEM?
  • What are the Detection and Response organizational metrics that you think are most valuable?
  • Is the continued use of Excel an issue of tooling, laziness, or just because it is a fundamentally good way to interact with a small database?

Resources:

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

EP263 SOC Refurbishing: Why New Tools Won't Fix Broken Processes (Even With AI)

EP263 SOC Refurbishing: Why New Tools Won't Fix Broken Processes (Even With AI)

Anton A Chuvakin