← Blog Cyberdecision

The SOC is a decision system. Build it like one.

"Cyberdecision" is not a dashboard word. It is the claim that a security operations centre exists to produce decisions, not alerts — and that every tool in it should be judged on how it changes the next decision.

Ask a SOC analyst what they did today and you will hear a number: alerts closed, cases touched, tickets moved. Ask what they decided and the room goes quiet. That silence is the whole problem, and it is why we call Seculogik a Cyber Decision Center rather than a SIEM, a SOAR or an XDR.

It does not replace any of those. Your log store stays your log store and your sensors stay your sensors. Seculogik sits above whatever detection stack you already run — open-source stacks such as Wazuh, OpenSearch, Elastic or ClickHouse; market platforms such as Splunk, Microsoft Sentinel, CrowdStrike, Microsoft Defender, SentinelOne or Cortex XDR; or a source of your own, for which we build the connector — and turns the flood of alerts into a small number of qualified cases, each with a readable explanation and a queue that says what to do next. On your own infrastructure, with no per-GB meter.

Monitoring answers the wrong question

A monitoring dashboard answers "what is happening?" It is a very good answer to that question: counts by severity, a map of source addresses, a line of events per second. It is also almost useless at 03:14, when a single analyst has forty minutes of attention and twelve thousand rows. Most SOCs are small — the SANS SOC Survey 2025 puts the typical fully staffed team at two to ten people, and 79% of them run 24/7 — so the hours when one person holds the whole estate are exactly the hours an unranked screen costs you the most.

A decision screen answers a different question: "what do I do now?" It has to be ranked, it has to be short, and every item on it has to be one click from the thing it is about. Seculogik opens on a decision queue with four lanes: awaiting triage, SLA at risk, high risk, unassigned critical. Nothing else. The queue is computed from the facts of each case, deterministically, never guessed by a model — because the first thing your analyst opens should not depend on an AI being awake.

Triage is a decision, and the platform treats it as one

Most case tools let a case drift from new to in progress because somebody clicked on it. In Seculogik a case does not become an investigation until a person has triaged it — the explicit act of deciding that this is worth someone's time. It sounds like a formality. It is the difference between a backlog that measures attention and a backlog that measures judgement.

That one rule is what makes every downstream number honest. Time to acknowledge, time to resolve, SLA attainment: each of them now measures a decision a human actually made, not a click that happened to land. For a CISO reporting to a board, or an MSSP reporting to a client, that is the difference between a metric you can defend and a metric you hope nobody questions.

The decision must survive the person who made it

Six months after an incident, the question is never "what happened?" — the logs answer that. The question is "why did we decide it was fine?" or "why did we escalate?" That answer normally lives in someone's head, and the someone has changed jobs.

So every case in Seculogik keeps a decision trace it can show you: which signals mattered, how the verdict was reached, and what would have had to be different for the verdict to change. The Correlation Engine looks at every alert from several independent angles — the entities involved, how far the attack has progressed, whether more than one source agrees, whether the pattern matches a recognised attack storyline such as phishing leading to account takeover — and the case records how those angles were weighed. When the AI analyst is involved, its hypotheses and the evidence for and against them are stored alongside. A CISO, an auditor or a client can read why a case exists a year later without re-running anything, and without tracking down the analyst who closed it.

Numbers have to carry their evidence

The most dangerous artefact in a SOC is a clean dashboard that is actually blind. A zero on a screen means one of two things: nothing happened, or nothing was looked at. A dashboard that cannot tell you which is worse than no dashboard, because it is reassuring.

Seculogik holds itself to a plain rule: a zero must be explainable. Every number on a report carries the evidence that produced it. A metric that cannot be computed from real data says so — insufficient data — rather than showing a comforting blank or an extrapolation. A vulnerability report states how much of the estate it actually covered before it tells you how clean the rest was. The compliance evidence packs — NIST CSF, ISO 27001, GDPR, DORA, NIS2 — say on their own cover that they are self-assessed coverage signals, not attestations, because the day you hand one to a regulator is the wrong day to discover it was overstating.

For a buyer, that is the difference between a report you forward and a report you have to caveat.

AI recommends. The human decides and stays accountable.

A decision centre with an AI in it has one more obligation: the AI must not quietly become the decider. SIROC, our AI analyst, proposes a verdict only after it has listed the benign explanations and the evidence on both sides, so you see its reasoning before you see its conclusion. Then its cited evidence is checked against the case's own alerts, and a verdict the alerts do not support is downgraded in front of the analyst rather than passed along as fact.

The same discipline applies to response. Destructive actions — isolating a host, resetting a credential, blocking an address — always require a person, and no playbook can lower that bar. The AI can propose them, queue them and explain them; a human approves them. And it runs on your terms: a local open-licence model on your own box by default, your own cloud key by choice, and every cloud-bound call recorded in a tamper-proof ledger you can audit.

That is the discipline the word cyberdecision stands for. Not that the machine decides faster, but that every decision — human or assisted — is explicit, ranked, evidenced, and still readable when the person who made it is gone.

What this changes for a buyer

If you evaluate Seculogik, do not ask how many alerts it shows. Ask how many decisions it produced from a week of your telemetry, whether each one explains itself, and whether the queue told your analyst the right thing to open first. Those three questions are the product — and they are what a demo answers: thirty minutes on your own telemetry, from whatever stack you already run.