03Defense

Detection is a habit, not a product

A SIEM can collect a billion events a day and still miss the one that mattered. Detection lives or dies with the people reading the signals.

01The alert queue illusion

More tooling usually means more alerts, not more detection. Analysts drowning in low-fidelity notifications learn to triage fast and trust less — the exact opposite of what good detection requires.

The organizations that catch intrusions early are not the ones with the most dashboards. They are the ones whose analysts know what normal looks like well enough to notice a single wrong note.

02Instinct is trained

Great analysts share a pattern: they have seen hundreds of investigations, real or simulated. Each one compresses into intuition — the slight wrongness of a login time, a process name that is almost right, a data transfer that is one size too large.

You cannot buy that intuition in a license. You build it with reps: hands-on investigations, log analysis drills, and incident walkthroughs that force real decisions on incomplete information.

03Building the habit

Make investigation a routine, not an emergency activity. Short, frequent exercises beat annual marathons. Rotate scenarios across phishing, lateral movement, and data exfiltration so instincts generalize.

Tools amplify trained people. They cannot substitute for them.

All publicationsNext publicationThe human layer of every breach
Skip to main content