<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>OwlSOC blog</title>
    <link>https://www.owlsoc.com/blog/</link>
    <atom:link href="https://www.owlsoc.com/blog/rss.xml" rel="self" type="application/rss+xml" />
    <description>Honest writing on AI alert triage, out-of-hours coverage and audit evidence, for teams running Microsoft Sentinel, Microsoft Defender or AWS Security Hub.</description>
    <language>en-GB</language>
    <lastBuildDate>Tue, 21 Jul 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>How we test OwlSOC, including the bar we currently fail</title>
      <link>https://www.owlsoc.com/blog/how-we-test-our-ai-soc/</link>
      <guid isPermaLink="true">https://www.owlsoc.com/blog/how-we-test-our-ai-soc/</guid>
      <description>Nobody can verify a vendor accuracy claim from the outside. So here is our evaluation set in full: 30 labelled scenarios, the bars we hold ourselves to, our results, and the one bar we currently fail.</description>
      <category>Evaluation</category>
      <pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>We built an AI SOC and deliberately gave it no write access</title>
      <link>https://www.owlsoc.com/blog/autonomous-soc-human-approval/</link>
      <guid isPermaLink="true">https://www.owlsoc.com/blog/autonomous-soc-human-approval/</guid>
      <description>Nearly every AI SOC vendor sells autonomy. We deliberately built the opposite. Here is the asymmetry that drove the decision, where automation is genuinely safe, and how to pressure-test an autonomy claim before you buy.</description>
      <category>AI SOC</category>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Nobody is watching at 3am. Here are the four honest options.</title>
      <link>https://www.owlsoc.com/blog/24-7-security-coverage-small-team/</link>
      <guid isPermaLink="true">https://www.owlsoc.com/blog/24-7-security-coverage-small-team/</guid>
      <description>Attackers deliberately work when you do not. If you cannot staff a night shift, you still have four real options. Here is what each one actually costs, and what it genuinely does and does not cover.</description>
      <category>Coverage</category>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Your auditor will sample 25 alerts. Can you show what you checked?</title>
      <link>https://www.owlsoc.com/blog/soc-2-alert-triage-evidence/</link>
      <guid isPermaLink="true">https://www.owlsoc.com/blog/soc-2-alert-triage-evidence/</guid>
      <description>Auditors do not test whether you own a SIEM. They sample individual alerts and ask what you did about each one. Here is what that evidence looks like, the three ways teams fail it, and how to produce it without a SOC team.</description>
      <category>Compliance</category>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
