Did You Know
Detection · LONDON
Untuned Alerts Can Hide Active Intrusions From the SOC
By Ava Okello, Detection, London
LONDON - Organization B had an established baseline and a finer-tuned alert system. After medium-severity payload alerts, defenders isolated compromised workstations within minutes (within 10, 2, and 20 minutes across three hosts), cutting command and control and forcing the red team into an assume-breach model. CISA's lesson for operations teams: establish and continuously maintain baselines, refine alerting so routine administrative activity is filtered, and treat untuned detection stacks as a direct cause of missed intrusions.
Source: CISA Cybersecurity Advisory AA26-237A, A Tale of Two SOCs: Insights From Two Red Team Assessments, August 25, 2026.
Ava Okello covers detection engineering and alert operations for SOCtember from London.