# Security Operations Center

A Security Operations Center (SOC) is a team or centralized function that continuously monitors, detects, investigates, and responds to cybersecurity threats and incidents.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## AI didn't replace our Security Team, it multiplied it

DevFeed: [AI didn't replace our Security Team, it multiplied it](<https://devfeed.tech/articles/ai-didn-t-replace-our-security-team-it-multiplied-it-9171.md>)

Original publisher: [Read original article](<https://webflowmarketingmain.com/blog/ai-didnt-replace-our-security-team>)

Author: Andy Gombar

Published: 2026-07-17T00:00:00Z

Content type: article

Language: en

Sources: [Webflow Blog](<https://devfeed.tech/sources/webflow-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [incident](<https://devfeed.tech/topics/incident.md>), [SOC](<https://devfeed.tech/topics/soc.md>), [log management](<https://devfeed.tech/topics/log-management.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [incident](<https://devfeed.tech/tags/incident.md>), [logs](<https://devfeed.tech/tags/logs.md>), [operations](<https://devfeed.tech/tags/operations.md>), [production](<https://devfeed.tech/tags/production.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>)

### AI overview

Webflow describes an engineer-led security detection and response program that uses AI in production to handle more work without a dedicated SOC. AI supports alert triage, context gathering, and post-incident workflows, helping the team manage a 200% increase in detections; one change saved 504 hours in a quarter.

### Source excerpt

Webflow's security engineers built AI into triage and post-incident work. One change alone saved 504 hours in a single quarter.

## Preparing for OMB M-26-14: How Datadog supports federal logging maturity

DevFeed: [Preparing for OMB M-26-14: How Datadog supports federal logging maturity](<https://devfeed.tech/articles/preparing-for-omb-m-26-14-how-datadog-supports-federal-logging-maturity-2302.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/omb-m-26-14-federal-logging-maturity/>)

Author: Chris Leffler; Sophie Wang

Published: 2026-06-29T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [bits-ai](<https://devfeed.tech/tags/bits-ai.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [govcloud](<https://devfeed.tech/tags/govcloud.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [observability](<https://devfeed.tech/tags/observability.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [systems](<https://devfeed.tech/tags/systems.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [workflow-automation](<https://devfeed.tech/tags/workflow-automation.md>)

### AI overview

This article explains how OMB Memorandum M-26-14 changes federal logging guidance from prescriptive requirements to a risk- and maturity-based model. It describes continuous event monitoring and threat hunting, investigation, response, and forensics, including centralized security telemetry, visibility across IT, OT, and IoT environments, threat detection, searchable and retrievable logs, cross-source correlation, incident response, and forensic analysis. It also presents Datadog as a unified observability and security platform for helping agencies meet these requirements.

### Source excerpt

Learn how Datadog helps federal agencies prepare for OMB M-26-14 by providing centralized telemetry data, threat detection, and automated incident response.

## How to build effective runbooks for your SOC

DevFeed: [How to build effective runbooks for your SOC](<https://devfeed.tech/articles/how-to-build-effective-runbooks-for-your-soc-11804.md>)

Original publisher: [Read original article](<https://incident.io/blog/how-to-build-effective-runbooks-for-your-soc>)

Author: Tom Wentworth

Published: 2025-03-11T20:16:00Z

Content type: tutorial

Language: en

Sources: [The incident.io Blog](<https://devfeed.tech/sources/the-incident-io-blog.md>)

Topics: [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [analysts](<https://devfeed.tech/tags/analysts.md>), [audits](<https://devfeed.tech/tags/audits.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [guide](<https://devfeed.tech/tags/guide.md>), [guides](<https://devfeed.tech/tags/guides.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-channel](<https://devfeed.tech/tags/incident-channel.md>), [incident-management](<https://devfeed.tech/tags/incident-management.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [onboarding](<https://devfeed.tech/tags/onboarding.md>), [outage](<https://devfeed.tech/tags/outage.md>), [post-mortem](<https://devfeed.tech/tags/post-mortem.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [slack-incident](<https://devfeed.tech/tags/slack-incident.md>), [soc](<https://devfeed.tech/tags/soc.md>), [training](<https://devfeed.tech/tags/training.md>)

### AI overview

A practical guide to creating effective SOC runbooks that standardize incident response, reduce errors, accelerate resolution and analyst onboarding, and support audits and continuous improvement.

### Source excerpt

Learn how to create clear, practical runbooks that help your SOC respond faster and with fewer errors. A step-by-step guide for building, maintaining, and improving runbooks that actually get used.