Blog

Cyber decision, in writing.

Essays for the people who own the outcome. Why a SOC is a decision system rather than an alert feed. What a correlation engine owes the analyst who has to act on its cases. How an AI analyst earns the right to a verdict, and where a person must stay in the loop. And what NIS2, DORA and CIR 2024/2690 actually require of a managed security provider, in the law's own words. Every statistic is attributed to whoever measured it, and every claim about the platform is one we will show you on your own telemetry.

Cyberdecision

The SOC is a decision system. Build it like one.

"Cyberdecision" is not a dashboard word. It is the claim that a security operations centre exists to produce decisions, not alerts — and that every tool in it should be judged on how it changes the next decision.

· 8 min read
How it helps

How Seculogik helps a small SOC do the work of a large one

Most fully staffed SOCs are two to ten people, and most of them run 24/7 anyway. Here is where the hours actually go, and what a decision layer gives back.

· 7 min read
SIROC

SIROC: an AI analyst that argues in the open and gets fact-checked

An AI analyst is only as useful as its governance. SIROC lays out its hypotheses and evidence before its verdict, has that evidence checked against your own alerts, runs on your box by default, records every cloud-bound call, and never takes a destructive action without a person.

· 10 min read
From Wazuh

We started with Wazuh. Here is the floor we built above it.

Why a free, open detection agent was the right place to start, what a detection agent was never meant to do, and how a source-agnostic decision layer turns Wazuh — or whatever stack you already run — into qualified cases, explained verdicts and decisions, without an ingest meter.

· 7 min read
Correlation

Why the correlation engine is our crown jewel

A correlation engine owes an analyst three things — a case that explains itself, a client boundary that cannot be crossed, and bursts that never become lost alerts. What each one means for your SOC, whatever detection stack you already run.

· 9 min read
Regulation

NIS2, DORA, CIR 2024/2690: what the law actually asks of an MSSP

Three European texts now name managed security providers as a regulated class, put a clock on incident classification, and require exactly the monitoring a decision layer provides. The precise wording, the dates, and what is vendor folklore.

· 8 min read