The D3 Blog
Learn about the latest from D3 and the world of cybersecurity, with news, analysis, and more.
-
Cost Savings or Freed Capacity? Field Notes From Agentic SOC Deployments
Field notes from production agentic SOC deployments: where the returns land, what the no-analysts pitch skips, and the proof to demand from any vendor.
-
The 12 Best Agentic SOC Platforms in 2026: Architectures, Autonomy Levels, and a Full Comparison
Definitive 2026 comparison of agentic SOC platforms. 12 vendors scored by agentic architecture, autonomy level, integrations, and pricing, with a vendor-neutral evaluation framework.
-
Control Evidence by Design: How To Oversee an AI You Can’t Watch in Real Time
You can’t watch an autonomous SOC in real time. Here’s the architecture that makes human oversight provable: read-only investigation, gated actions, one record.
Filter by category:
Search blog:
-
Agentic SOCCost Savings or Freed Capacity? Field Notes From Agentic SOC Deployments
Field notes from production agentic SOC deployments: where the returns land, what the no-analysts pitch skips, and the proof to demand from any vendor.
-
Agentic SOCThe 12 Best Agentic SOC Platforms in 2026: Architectures, Autonomy Levels, and a Full Comparison
Definitive 2026 comparison of agentic SOC platforms. 12 vendors scored by agentic architecture, autonomy level, integrations, and pricing, with a vendor-neutral evaluation framework.
-
Agentic SOC, Autonomous SOCControl Evidence by Design: How To Oversee an AI You Can’t Watch in Real Time
You can’t watch an autonomous SOC in real time. Here’s the architecture that makes human oversight provable: read-only investigation, gated actions, one record.
-
Agentic SOC, Autonomous SOCKeep ServiceNow, Kill the Meter, Own the Models
Keep ServiceNow for IT, drop the Now Assist usage meter, and run a SOC AI you can audit. The practical case for moving security operations…
-
Agentic SOC, Autonomous SOCThe 3 a.m. Question: Who’s Liable When Your AI Acts Alone?
When your AI acts in the SOC at 3 a.m., liability stays with you. Here’s how to prove what it did and defend autonomy in…
-
Agentic SOC, Autonomous SOCThe Story of an Alert, in 8 Stages You Can Prove
Investigating every alert at L2 depth is an engineering problem. Here is the 8-stage lifecycle behind it: autonomous at every stage, governed at every stage.
-
Agentic SOC, Autonomous SOCWhat a Governed Agentic SOC Does When It Can’t Be Sure
The most useful moment in an agentic SOC demo is the failure path, not the clean verdict. Here’s what to ask to see, and what…
-
Agentic SOC, SOAR100 Wrong Verdicts a Day: The Fine Print Inside a “99% Accurate” AI SOC
LLMs perform pattern completion over whatever context they’re given. Why AI triage reads missing evidence as benign, and the guardrail that prevents it.
-
Agentic SOC, Autonomous SOCWhat Good Looks Like in an Agentic SOC (and the Five Questions That Prove It)
Every agentic SOC demos well. Here’s what separates production-ready from a demo: an eight-stage lifecycle and five questions any buyer can ask any vendor.