TLDRocket
Sign in

What an ex-NSA red teamer wants every SOC to stop doing

The New Stack Carly Page

SOC teams now drown in alerts from every cloud app and endpoint they monitor. A former NSA red teamer says the fix isn't more data, it's better context.

Based on reporting by The New Stack, Carly Page — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Security teams got exactly what they asked for. More visibility across endpoints, cloud platforms, identities, SaaS apps, you name it. And now they're paying for it with a flood of alerts that no human can realistically triage. Alert fatigue isn't a new complaint in security operations, but it keeps getting worse, and the reason isn't really volume. It's that a single alert almost never tells you anything useful on its own.

A weird login. An odd process spinning up. A connection to a server nobody recognizes. Individually, each one looks like nothing. Stack them together around the same user or the same workload, though, and suddenly there's a story worth investigating. That's pushing SOCs to redesign detection around entities, meaning devices, accounts, and workloads, rather than isolated events, so analysts get a running narrative instead of a pile of disconnected tickets they have to stitch together themselves.

This is the gap AI is actually filling right now, not as some autonomous defender but as a tireless log reader that helps tune detection rules, summarize findings, build playbooks, and flag what deserves a human's attention first. None of that works, though, without a real data strategy behind it. Some logs need to be instantly searchable. Others need enrichment before anyone looks at them. Plenty can just sit in cold storage for compliance until an investigation calls for them. Figuring out what goes where has become as important as deciding what to collect in the first place.

The person making this case is Chas Clawson, Sumo Logic's VP of Security Strategy, who spent two decades moving between government and enterprise security work, including building the Department of Commerce's SIEM and running offensive exercises with the NSA Red Team. That combination, breaking into systems and later building the defenses meant to stop people like his old self, is why his take on AI in the SOC carries some weight. Clawson joins The New Stack on July 23 for a webinar digging into how detection, AI, and data management need to work as one strategy rather than three separate projects bolted together.

The pitch, stripped of webinar marketing, comes down to a simple line: logging everything is the easy part. The hard part is deciding what actually deserves a person's attention, and that's the difference between a SOC that functions and one that's just generating noise at scale.

My take — AI-written commentary, not fact-checked reporting

The red-team-to-blue-team career arc always produces the most useful security voices, because these are people who've actually broken the systems they now defend, not just read about it. My real gripe is with the industry's instinct to keep buying more telemetry instead of fixing the correlation problem underneath, which is basically hoarding data and calling it a strategy. AI tuning detection rules is genuinely useful, but if a company hasn't solved data tiering first, they're just handing a tireless intern more haystacks to search.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.