← Playbooks

The Operating Model

Security isn't one loop. It's five —
an immune system, not an ambulance.

Every security program runs five decision loops at once, each with its own tempo. The fast loops buy time; the slow loops make sure the fast ones rarely have to fire. Invest in prevention and DFIR becomes what it should be — the failure mode, not the capability.

The loop stack · fastest protects slowest

01Containmentminutes
02Detection & Responsemin – hrs
03Posture / Driftcontinuous
04Vulnerability Mgmthrs – days
05Structuralwks – mos
below the stack · DFIR · the ambulance

The principle

Five loops, different tempos.
The fast ones buy time. The slow ones spend it well.

A SOC that treats security as a single "detect and respond" loop is measuring one heartbeat and calling it health. Real programs run five loops at once — from minutes to months — and the trick isn't speeding up any one of them. It's letting each protect the others.

Fast protects slow

If containment is fast enough, you buy time for everything downstream. If detection is good enough, containment triggers early and the blast radius stays small. Speed at the front of the stack is what keeps a bad day from becoming an existential one.

Slow reduces fast

The reverse is the prevention corollary: invest in the slow loops — posture, vulnerability management, structural change — and the fast loops rarely have to fire at all. You don't scale a SOC by hiring more responders. You scale it by needing fewer responses.

The metaphor

We're a care team. The environment is the patient.

A hospital is the honest picture of a security program: constant, quiet, prevention-weighted, and only dramatic when something has already gone wrong. It also names the part the industry ignores — the work is emotional labour. You're always standing with someone on the worst day of their year.

Immune system, not an ambulance

The immune system works so the ambulance never gets called. Prevention is the default state; response is the failure case. A program that measures itself by fires fought is measuring the wrong thing.

The patient can be non-compliant

You can screen, advise, and vaccinate — but the patient owns their own health. That's the shared-responsibility line, said without blame: we advise, they decide, and the record shows what was recommended.

Read the vitals early

A good nurse catches it in the vitals before it's an emergency. Detections and posture monitoring exist to see the crash coming, not to document it after the fact.

The five loops

From minutes to months — and the ambulance below them all.

Each loop is a decision cycle with its own tempo and its own automation ceiling. The fast, repeatable loops automate well; the slow ones need human judgment and business context.

01

Containment

Minutes · the crash cart

Kill the network path, rotate the credentials, revoke the sessions. Binary, pre-authorized decisions — the highest automation potential in the stack, because the human hesitation at 3 a.m. ("but that'll disrupt the business") is exactly what costs hours.

The rule that makes it safe: contain at least as wide as the attacker could be. Containment wider than the attacker's footprint cuts every path at once and buys time. Containment narrower than it — one host isolated, one account revoked, while a second foothold or a consented app stays live — buys the attacker time instead: it tells them they've been found while they still have a way in. Until the scope is known, go broad: the segment, the tier, tenant-wide token revocation. Go surgical only once the scope is known.

Stop the bleeding first — and cut wider than the wound.

02

Detection & Response

Minutes – hours · diagnosis & treatment

Alert → triage → investigate → verdict → action. The immune system's core work. High automation for the patterns you know; human judgment for the ones you don't. This is where owning your detection content decides whether the loop is fast and accurate or slow and noisy.

Fix the rule, not your patience — a bad detection is a bug, not a fact of life.

03

Posture / Drift

Continuous · monitoring the vitals

Configuration monitoring and control-reliability engineering — plus making sure the defenses themselves haven't quietly weakened. Detections are software; untested, they regress. Hunting and adversary emulation live here: proving the immune system still works before an attacker does.

An untested detection is a hope, not a control.

04

Vulnerability Management

Hours – days · preventive medicine

Find → prioritize → fix → deploy. Screening and vaccination for the environment. Prioritize by real exposure (exploited-in-the-wild and business impact), not by chasing every severity score. Reducing the attack surface here is the cheapest security you will ever buy.

The condition treated early never becomes the emergency.

05

Structural Improvement

Weeks – months · public health

Class-level elimination, architecture change, segmentation, framework deployment. Low automation, high judgment — the work that removes whole categories of risk so the faster loops have less to catch. This is where the program stops fighting instances and starts redesigning the ward.

Every new customer should cost you less, not more.

Below
the stack
DFIR is the failure mode, not the capability. The ambulance is dispatched only when all five loops have failed to contain. A healthy program keeps it a rare, bounded backstop — not the identity of the team. When response becomes the point, prevention has already lost.

Every failure is paid-for intelligence

An incident is the most expensive data the program will ever collect, so it doesn't close at recovery. The case feeds back up the stack: how they got in goes to vulnerability management and posture, what detection missed goes to the detection backlog, and the visibility and process gaps that made it slow go to structural improvement. An incident that ends at "systems restored" will be paid for twice.

Machines collect, humans curate

Harvesting the case is automated: indicators, TTPs, timeline and gaps are pulled from every investigation. Promoting any of it to intelligence is not. Before an indicator becomes a permanent rule, a block, or a line in a shared feed, an analyst checks it, gives it a date, a source and an expiry, and states how confident we are. Automated verdicts run the SOC; intelligence is curated by people.

How we talk about it

The operating model, in one breath each.

A handful of lines, repeated until the team finishes them for you. Each one is a strategy, not a slogan.

We're an immune system, not an ambulance.Prevention is the default; response is the failure case.
Bad alert? Fix the rule, not your patience.Own the detection content and feed the loop.
A green dashboard never stopped an attacker.Every metric needs a counter, or it's vanity.
Every new customer should cost us less, not more.Scale by needing fewer responses, not more responders.
Willingness isn't a system.Structure and handovers beat heroics and adrenaline.
An untested detection is a hope, not a control.Detections are software — prove them, or they rot.
Contain at least as wide as the attacker could be.Broad buys time; narrow only tips them off. Go surgical once the scope is known.
Machines collect, humans curate.Every incident feeds the slow loops; nothing becomes intelligence until an analyst signs for it.