Research by Oliver Rochford on AI, security operations, security data architecture and emerging cybersecurity technologies.
Some papers are independently funded and some are vendor sponsored. Sponsorship is disclosed on the work.
AI SOC tools, AI-enabled MDR and the choices between them
AI SOC tools and AI-enabled MDR services increasingly promise the same outcome: fewer alerts, faster investigations and less work for analysts.
They get there in different ways.
This research examines the operating models behind each approach, where each is strongest and what security leaders should consider before choosing between them.
Sponsored by Daylight Security
Why security data architecture is changing
Security teams are collecting more telemetry while SIEM economics are making it increasingly expensive to put all of it in the same platform.
This report examines the emerging security telemetry pipeline market and the architectural shift towards separating data collection, transformation, routing, storage and analytics.
Sponsored by Auguria
What AI analysts change about the SOC
AI agents are increasingly capable of carrying out parts of triage and investigation that once required human analysts.
The interesting question is not whether they eliminate the SOC. It is how they change the operating model.
This research looks at how organisations can structure security operations when AI performs a growing share of routine analytical work.
Sponsored by Dropzone AI
How European organisations are approaching continuous threat exposure management
Research into the adoption of continuous threat exposure management, the technologies involved and the organisational changes required to make it work.
What the AI SOC market says — and what practitioners report
AI SOC vendors make ambitious claims about automation, analyst replacement and autonomous security operations.
Practitioners are considerably more cautious.
This research examines the gap between the two and what it tells us about the current state of AI adoption in security operations.
A simple model for estimating the security budget available to a target customer based on company size and broader IT economics.
A view of the emerging AI security operations vendor landscape and the different problems vendors are trying to solve.
Research and working material on technologies and market categories developing around security operations.