The principle
Five loops, different tempos.
The fast ones buy time. The slow ones spend it well.
A SOC that treats security as a single "detect and respond" loop is measuring one heartbeat and calling it health. Real programs run five loops at once — from minutes to months — and the trick isn't speeding up any one of them. It's letting each protect the others.
Fast protects slow
If containment is fast enough, you buy time for everything downstream. If detection is good enough, containment triggers early and the blast radius stays small. Speed at the front of the stack is what keeps a bad day from becoming an existential one.
Slow reduces fast
The reverse is the prevention corollary: invest in the slow loops — posture, vulnerability management, structural change — and the fast loops rarely have to fire at all. You don't scale a SOC by hiring more responders. You scale it by needing fewer responses.
The metaphor
We're a care team. The environment is the patient.
A hospital is the honest picture of a security program: constant, quiet, prevention-weighted, and only dramatic when something has already gone wrong. It also names the part the industry ignores — the work is emotional labour. You're always standing with someone on the worst day of their year.
Immune system, not an ambulance
The immune system works so the ambulance never gets called. Prevention is the default state; response is the failure case. A program that measures itself by fires fought is measuring the wrong thing.
The patient can be non-compliant
You can screen, advise, and vaccinate — but the patient owns their own health. That's the shared-responsibility line, said without blame: we advise, they decide, and the record shows what was recommended.
Read the vitals early
A good nurse catches it in the vitals before it's an emergency. Detections and posture monitoring exist to see the crash coming, not to document it after the fact.
The five loops
From minutes to months — and the ambulance below them all.
Each loop is a decision cycle with its own tempo and its own automation ceiling. The fast, repeatable loops automate well; the slow ones need human judgment and business context.
Containment
Kill the network path, rotate the credentials, revoke the sessions. Binary, pre-authorized decisions — the highest automation potential in the stack, because the human hesitation at 3 a.m. ("but that'll disrupt the business") is exactly what costs hours.
The rule that makes it safe: contain at least as wide as the attacker could be. Containment wider than the attacker's footprint cuts every path at once and buys time. Containment narrower than it — one host isolated, one account revoked, while a second foothold or a consented app stays live — buys the attacker time instead: it tells them they've been found while they still have a way in. Until the scope is known, go broad: the segment, the tier, tenant-wide token revocation. Go surgical only once the scope is known.
Stop the bleeding first — and cut wider than the wound.
Detection & Response
Alert → triage → investigate → verdict → action. The immune system's core work. High automation for the patterns you know; human judgment for the ones you don't. This is where owning your detection content decides whether the loop is fast and accurate or slow and noisy.
Fix the rule, not your patience — a bad detection is a bug, not a fact of life.
Posture / Drift
Configuration monitoring and control-reliability engineering — plus making sure the defenses themselves haven't quietly weakened. Detections are software; untested, they regress. Hunting and adversary emulation live here: proving the immune system still works before an attacker does.
An untested detection is a hope, not a control.
Vulnerability Management
Find → prioritize → fix → deploy. Screening and vaccination for the environment. Prioritize by real exposure (exploited-in-the-wild and business impact), not by chasing every severity score. Reducing the attack surface here is the cheapest security you will ever buy.
The condition treated early never becomes the emergency.
Structural Improvement
Class-level elimination, architecture change, segmentation, framework deployment. Low automation, high judgment — the work that removes whole categories of risk so the faster loops have less to catch. This is where the program stops fighting instances and starts redesigning the ward.
Every new customer should cost you less, not more.
the stack
Every failure is paid-for intelligence
An incident is the most expensive data the program will ever collect, so it doesn't close at recovery. The case feeds back up the stack: how they got in goes to vulnerability management and posture, what detection missed goes to the detection backlog, and the visibility and process gaps that made it slow go to structural improvement. An incident that ends at "systems restored" will be paid for twice.
Machines collect, humans curate
Harvesting the case is automated: indicators, TTPs, timeline and gaps are pulled from every investigation. Promoting any of it to intelligence is not. Before an indicator becomes a permanent rule, a block, or a line in a shared feed, an analyst checks it, gives it a date, a source and an expiry, and states how confident we are. Automated verdicts run the SOC; intelligence is curated by people.
How we talk about it
The operating model, in one breath each.
A handful of lines, repeated until the team finishes them for you. Each one is a strategy, not a slogan.