Security Operations and Response by Kai London
This is the volume about the day it happens. Detecting it early, triaging it honestly, containing it without destroying the evidence, and leading an organisation through the hours when the technical problem has become a business crisis.
Available on Amazon.
What is inside
Designing the SOC
Operating model, staffing, shift reality and the decision of what to build versus what to buy.
SIEM and SOAR that earn their cost
Data selection, normalisation, retention economics and automation that removes work rather than adding tickets.
Detection engineering
Detections as code — written, tested, versioned and measured against real ATT&CK coverage.
Threat hunting and intelligence
Turning intelligence into hypotheses and hunts, and hunts into permanent detection content.
Incident response and forensics
Containment, eradication and evidence handling that preserves the option of legal or insurance action.
Ransomware and crisis response
Command structure, decisions under pressure, communications, and recovery sequencing.
Who it is for: SOC analysts and managers, detection engineers, incident responders and forensic practitioners, and the executives who will be in the crisis room with them.
Contain fast, but do not destroy the evidence you will need to prove what happened.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.