Insights
From the Conifers blog
Field notes on agentic SOC operations, threat response and the work of running security at machine speed.
-
The Lossy Handshake: Why Context Dies Between SOC Functions
One identity incident, five different stories. What gets lost when work moves between threat intelligence, hunting, detection engineering, investigation, and remediation, and…
-
The U.S. Is Rethinking How It Fights Cybercrime for the AI Era of Scale
AI is making it possible for criminal networks to target far more Americans and American organizations without needing far more people. That…
-
The Attack Loop Is Compressing. The SOC Is Not.
AI does not need to invent a new class of cyberattack. It only needs to make attacker iteration cheap. Why the attack…
-
Is Astra Actually a New Cybersecurity Threat, or Are We Rebranding a Risk We Already Have?
This is where the Astra announcement deserves more scrutiny. OpenAI says it cannot rule out that Astra has reached its highest category…
-
The SOC’s New Mission: Defending the Organization From Its Own AI Agents
The recent OpenAI and Anthropic cyber incidents revealed something much bigger than advances in AI capability. They showed that a legitimate objective…
-
Qwen3.8-Max Isn’t Just Another Model. It’s Another Signal.
Qwen3.8-Max isn’t important because it’s another large language model. It’s important because it confirms a trend that security leaders should be watching…
-
Four Lessons From the OpenAI and Anthropic Cyber Incidents
Over the last ten days, OpenAI and Anthropic disclosed incidents that may become a watershed moment for cybersecurity. Not because AI discovered…
-
Why AI Forces Us Back to the Behavioral SOC
The recent OpenAI and Anthropic cyber incidents taught us something that I don’t think the industry is talking about enough. Everyone focused…
-
Kimi K3 Is Not the Most Capable Cyber Model. That Is Exactly Why CISOs Should Pay Attention.
The release of Kimi K3 should change the cybersecurity conversation. Not because Kimi K3 is now the world’s most capable AI model.…
-
SecOps Guide: Why a disconnected SOC can’t keep pace with machine-speed risk
Frontier AI moved attack discovery and execution toward machine speed. Why a disconnected SOC falls behind, and how a connected, adaptive cyber-defense…