Cyber Security All-in-One · Volume 3

Security Operations and Response by Kai London

This is the volume about the day it happens. Detecting it early, triaging it honestly, containing it without destroying the evidence, and leading an organisation through the hours when the technical problem has become a business crisis.

Available on Amazon.

What is inside

Designing the SOC

Operating model, staffing, shift reality and the decision of what to build versus what to buy.

SIEM and SOAR that earn their cost

Data selection, normalisation, retention economics and automation that removes work rather than adding tickets.

Detection engineering

Detections as code — written, tested, versioned and measured against real ATT&CK coverage.

Threat hunting and intelligence

Turning intelligence into hypotheses and hunts, and hunts into permanent detection content.

Incident response and forensics

Containment, eradication and evidence handling that preserves the option of legal or insurance action.

Ransomware and crisis response

Command structure, decisions under pressure, communications, and recovery sequencing.

Who it is for: SOC analysts and managers, detection engineers, incident responders and forensic practitioners, and the executives who will be in the crisis room with them.

MITRE ATT&CKNIST SP 800-61NIST CSF 2.0ISO/IEC 27035ISO/IEC 27001

Contain fast, but do not destroy the evidence you will need to prove what happened.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.