<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Seculogik</title>
    <link>https://seculogik.pages.dev/blog/</link>
    <description>Essays on security operations as a decision system, for CISOs, SOC leads and MSSP founders.</description>
    <language>en</language>
    <atom:link href="https://seculogik.pages.dev/rss.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Vulnerability prioritisation: rank by exploitability, not by severity score</title>
      <link>https://seculogik.pages.dev/blog/vulnerability-prioritisation-exploitability/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/vulnerability-prioritisation-exploitability/</guid>
      <pubDate>Tue, 08 Sep 2026 09:00:00 GMT</pubDate>
      <category>Vulnerabilities</category>
      <description>Vulnerability prioritisation by CVSS alone puts the wrong work first. Rank the remediation backlog by known exploitation, ransomware use, reachability and business impact.</description>
    </item>
    <item>
      <title>Alert triage, step by step: the six stages and where the hours go</title>
      <link>https://seculogik.pages.dev/blog/soc-alert-triage-process/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/soc-alert-triage-process/</guid>
      <pubDate>Tue, 08 Sep 2026 09:00:00 GMT</pubDate>
      <category>Triage</category>
      <description>Alert triage in six steps: dedupe, group, scope, verdict, action, record. Where the hours really go, which steps a machine should own, and what needs a person.</description>
    </item>
    <item>
      <title>SIEM cost per gigabyte: why the unit makes your team argue for less visibility</title>
      <link>https://seculogik.pages.dev/blog/siem-cost-per-gigabyte/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/siem-cost-per-gigabyte/</guid>
      <pubDate>Tue, 08 Sep 2026 09:00:00 GMT</pubDate>
      <category>Pricing</category>
      <description>SIEM cost is usually metered per gigabyte, so every new log source becomes a budget argument — and vendor lock-in is the fear underneath it. What a per-deployment unit changes, and what it honestly does not.</description>
    </item>
    <item>
      <title>Open source SIEM: what it gives you, and what you still build yourself</title>
      <link>https://seculogik.pages.dev/blog/open-source-siem-what-you-still-build/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/open-source-siem-what-you-still-build/</guid>
      <pubDate>Tue, 08 Sep 2026 09:00:00 GMT</pubDate>
      <category>Open source</category>
      <description>An open source SIEM solves collection, storage and rule execution. Detection engineering, cross-source correlation, case lifecycle and reporting are yours to build.</description>
    </item>
    <item>
      <title>What an MSSP SOC platform has to do that a single-organisation SIEM never will</title>
      <link>https://seculogik.pages.dev/blog/mssp-multi-tenant-soc-platform/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/mssp-multi-tenant-soc-platform/</guid>
      <pubDate>Tue, 08 Sep 2026 09:00:00 GMT</pubDate>
      <category>MSSP</category>
      <description>A managed SOC platform owes you four things a single-organisation SIEM does not: a wall between the customers you serve, unattributable alerts held rather than guessed at, reporting under your brand, and a flat fee.</description>
    </item>
    <item>
      <title>The MITRE ATT&amp;CK coverage gap, and why your real number is lower than the dashboard says</title>
      <link>https://seculogik.pages.dev/blog/mitre-attack-coverage-gap/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/mitre-attack-coverage-gap/</guid>
      <pubDate>Tue, 08 Sep 2026 09:00:00 GMT</pubDate>
      <category>Detection</category>
      <description>Measured MITRE ATT&amp;CK coverage sits far below what most teams report. What a coverage number counts, how a broken detection rule stays green, and how to audit yours.</description>
    </item>
    <item>
      <title>The SOC is a decision system. Most tools still treat it as a monitoring one.</title>
      <link>https://seculogik.pages.dev/blog/cyber-decision-center/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/cyber-decision-center/</guid>
      <pubDate>Tue, 08 Sep 2026 09:00:00 GMT</pubDate>
      <category>Cyberdecision</category>
      <description>'Cyberdecision' is not a dashboard word. A security operations centre exists to produce decisions, not alerts — a triaged case, a verdict with its evidence, a queue that says what to open first. Judge every tool in it on how it changes the next decision, whatever detection stack you already run.</description>
    </item>
    <item>
      <title>Alert fatigue is an arithmetic problem, not a morale problem</title>
      <link>https://seculogik.pages.dev/blog/alert-fatigue-arithmetic/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/alert-fatigue-arithmetic/</guid>
      <pubDate>Tue, 08 Sep 2026 09:00:00 GMT</pubDate>
      <category>Alert fatigue</category>
      <description>Alert fatigue is three numbers — alerts arriving, minutes a real triage takes, analyst-hours in a week. Why hiring and tuning both lose to it, and the one term that brings the backlog down.</description>
    </item>
    <item>
      <title>AI SOC analyst: what to demand before you trust one</title>
      <link>https://seculogik.pages.dev/blog/ai-soc-analyst-what-to-demand/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/ai-soc-analyst-what-to-demand/</guid>
      <pubDate>Tue, 08 Sep 2026 09:00:00 GMT</pubDate>
      <category>AI SOC</category>
      <description>Hand an AI SOC analyst your tier 1 triage only if it shows what it ruled out, cites evidence you can check, drops its confidence score in the open, and keeps a human in the loop on every destructive action.</description>
    </item>
    <item>
      <title>How Seculogik helps a small SOC do the work of a large one</title>
      <link>https://seculogik.pages.dev/blog/how-seculogik-helps/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/how-seculogik-helps/</guid>
      <pubDate>Sun, 06 Sep 2026 09:00:00 GMT</pubDate>
      <category>How it helps</category>
      <description>Most fully staffed SOCs are two to ten people, and most run 24/7 anyway. Where the hours actually go — tier 1 triage, escalation, the shift handover, the backlog — and what the Verdict Layer gives back.</description>
    </item>
    <item>
      <title>A self-hosted AI SOC analyst: running the model on your own hardware</title>
      <link>https://seculogik.pages.dev/blog/siroc-ai-analyst/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/siroc-ai-analyst/</guid>
      <pubDate>Fri, 04 Sep 2026 09:00:00 GMT</pubDate>
      <category>Sovereign AI</category>
      <description>A self-hosted AI SOC analyst that reasons on your own hardware, with no GPU and nothing leaving the box. How SIROC runs local by default, what redaction happens before any cloud call, and how to refuse cloud models outright.</description>
    </item>
    <item>
      <title>We started with Wazuh. Here is the floor we built above it.</title>
      <link>https://seculogik.pages.dev/blog/wazuh-next-level/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/wazuh-next-level/</guid>
      <pubDate>Sun, 30 Aug 2026 09:00:00 GMT</pubDate>
      <category>From Wazuh</category>
      <description>Why a free, open detection agent was the right place to start, what a detection agent was never meant to do, and how a source-agnostic decision layer turns Wazuh — or whatever stack you already run — into triaged cases with an owner, an escalation path and an explained verdict, without an ingest meter.</description>
    </item>
    <item>
      <title>Why the correlation engine is our crown jewel</title>
      <link>https://seculogik.pages.dev/blog/correlation-crown-jewel/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/correlation-crown-jewel/</guid>
      <pubDate>Thu, 27 Aug 2026 09:00:00 GMT</pubDate>
      <category>Correlation</category>
      <description>A correlation engine owes you four things — a case that explains itself, deduplication that absorbs a burst without losing an alert, a triage queue that ranks on what a case has become rather than on how it started, and, if you serve several customers, a wall between them that cannot be crossed. What each one means for your SOC, whatever detection stack you already run.</description>
    </item>
    <item>
      <title>NIS2, DORA, CIR 2024/2690: what the law actually asks — and what your platform has to prove</title>
      <link>https://seculogik.pages.dev/blog/nis2-dora-decision-center/</link>
      <guid isPermaLink="true">https://seculogik.pages.dev/blog/nis2-dora-decision-center/</guid>
      <pubDate>Sat, 22 Aug 2026 09:00:00 GMT</pubDate>
      <category>Regulation</category>
      <description>Three European texts now name managed SOC providers as a regulated class in their own right, put a clock on incident classification for financial entities, and set out monitoring and logging duties in the language a verdict layer is built to evidence. The precise wording, the dates, and what is vendor folklore.</description>
    </item>
  </channel>
</rss>
