The Future of SOC Is ∞
We say continuous more than almost any other word in cybersecurity. Continuous monitoring. Continuous detection. Continuous cyber risk…

The Future of SOC Is ∞
We say continuous more than almost any other word in cybersecurity. Continuous monitoring. Continuous detection. Continuous cyber risk management. We have written it into frameworks and regulations and board reports until it lost its meaning. But say a word often enough and you stop checking whether the thing it describes is actually happening. In most organizations it is not. The exposure data sits in one team. The detection logic sits in another. The cyber risk score is calculated, reported, and filed. Each part runs on its own schedule. Nothing actually flows between them. We have the vocabulary of continuous defense and almost none of the motion.
This is the part the industry has not said plainly enough. The problem was never that we lacked the data. The problem was that the data never reached the moment of decision.
I have argued for a long time that the Security Operations Center and the **Cyber Risk Operations Center are two halves of one system. The SOC asks what is happening right now. The CROC asks what our exposure is right now, how it is changing, and what we should do today to reduce it before it becomes an incident. When I imagined the CROC concept, I was not trying to invent something new. I was reaching for a missing piece I had been looking for my whole cybersecurity career, a function that worked on the risk before it became the incident, sitting alongside the SOC rather than replacing it. The SOC protects today. The CROC protects tomorrow. Together they close into the [Continuous Defense Loop](https://www.researchgate.net/publication/396885730)**, one half reacting to what has already happened, the other half preventing what could happen next. I came to write that loop as ∞, two centers feeding each other with no end, because the game never ends and neither can the defense.
But there is something I left implicit, and the AI era has forced me to make it explicit. The symbol ∞ does not describe two boxes sitting next to each other. It describes motion. The figure only means anything if something is traveling along the line, crossing from one center to the other and back, continuously, without stopping. Two operations centers that do not exchange intelligence at the speed the decision requires are not a loop. They are two silos with a hopeful connection drawn between them.
So the real question is not whether you have a SOC and a CROC. Many organizations have both, in some form. The real question is whether anything moves between them fast enough to matter.
Why you need both a SOC and a CROC
It is worth being plain about why this is two centers and not one, because the instinct is always to collapse them into a single team and call it efficiency.
The SOC protects today. It watches what is happening right now, detects the intrusion, investigates the alert, and responds to the incident in front of it. Its clock is the clock of the live event. It is built to answer one question well, what is happening, and to act on the answer fast. This is detection and response, and a mature SOC does it at a level no other function can match.
The CROC protects tomorrow. It does not wait for the alert. It asks what our exposure is right now, which assets matter most, how the cyber risk is changing, and what we should do today to reduce it before it ever becomes an incident. Its clock is the clock of the changing environment. It works the cyber risk before the cyber risk becomes a breach. This is the function I had been looking for my whole career, the half of the work that detection and response was never designed to do, because detection and response begins the moment something is already wrong.
You need both because they cover different time. A SOC without a CROC is an organization that defends only the present, brilliant at the incident and blind to the exposure that produced it, forever responding to breaches it could have prevented. A CROC without a SOC is an organization that understands its cyber risk and has no hand fast enough to act when the risk becomes real. One protects you during the breach. The other protects you before it. Neither covers the other’s ground, and an organization that runs only one is defending half of time.
This is also why the Cybersecurity Compass sits at the center of the loop and not off to one side. When I created the **Cybersecurity Compass**, the goal was a shared map that both centers could navigate by, a common language across the phases of an attack. Cyber Risk Management is the work before the breach, where the CROC lives. Detection and Response is the work during the breach, where the SOC lives. Cyber Resilience is the work after, the learning that feeds the next turn. The Compass is the orientation that keeps the SOC and the CROC pointed at the same objective instead of optimizing two separate dialects. It is the reason the two centers can form a loop at all, because they are reading from the same map.
This is the point that ties the whole thing together. The loop is a continuous cyber defense, and a continuous cyber defense is what produces continuous cyber resilience. I have argued for a long time that **resilience is not a capability you buy and then have. It is an outcome you earn, the result of managing cyber risk continuously rather than reviewing it periodically. The loop is how that work actually happens. When the SOC and the CROC run as one moving system, defense stops being a series of responses to incidents and becomes a standing condition, an organization that absorbs change, learns from every event, and stays able to operate through the storm. Continuous cyber defense is the method. Continuous cyber resilience is the outcome. The loop is what turns one into the other.**
And the loop runs in both directions, which is the part that makes it a loop instead of a handoff. Exposures and cyber risks from the CROC inform the prioritization of detections in the SOC, so the SOC hunts what is most likely to be exploited against what matters most. Incidents and investigations from the SOC reprioritize exposures and prevention in the CROC, so every real attack sharpens tomorrow’s exposure model. The CROC sends exposure visibility, asset criticality, and risk scoring toward detection. The SOC sends correlation and long-term actionable insight back toward prevention. That two-way flow is the ∞. Cut either direction and the figure breaks into two circles that no longer feed each other.

This is also a useful way to read the technology landscape. Every tool in security operations leans toward one center or the other, and a few rare ones serve both. The tables below score the major technologies on three things: how much they strengthen the SOC, how much they strengthen the CROC, and how much they move intelligence through the loop between them. The pattern is the point. The technologies that earn the highest loop leverage are precisely the ones that refuse to sit in a single center.


Read the tables and the temptation is immediate. Find the row with the most loop leverage and buy it. The temptation is the mistake. No technology in either table is the loop. Each one is a component that either feeds the loop, runs inside it, or moves intelligence across it, but not one of them closes the loop on its own. This is why effectiveness has plateaued in so many security programs even as the tooling has multiplied. The capabilities were bought independently and bolted together, each optimized for its own function, and the gaps between them are exactly where cyber risk lives. You cannot buy your way to a continuous defense by adding another box, however high it scores, because the box is never the architecture. The loop is not a product. It is the way the products are wired together, governed, and kept moving. The leverage tables tell you which components carry the most weight. They do not tell you that any one of them will carry the load alone, because none of them will.
Threat data and cyber risk data are not the same thing
The two centers run on two different kinds of data, and confusing them is how organizations end up with a SOC doing the CROC’s job badly, or the reverse.
**Threat data** is the footprint of an adversary in motion. A malicious process, a suspicious login, a beacon to a known bad address, a pattern that matches a technique seen in the wild. It tells you something is happening or has happened. It is the SOC’s native material, and threat intelligence is its sharpest form, telling the SOC which adversaries are active and which techniques to hunt for first.
Cyber risk data is different. It is not the adversary in motion. It is the condition the adversary could exploit if it were left alone. A newly published vulnerability on a production system. A storage bucket open to the internet. An identity holding privileged access it never needed. A business-critical application without strong authentication. None of these is an attack. Each is a door, and cyber risk data is the map of which doors are open and which rooms are worth entering. It is the CROC’s native material. The same threat intelligence that tells the SOC what to hunt tells the CROC which of its open doors adversaries are actually walking through, so the two centers read the same intelligence and use it for opposite halves of the work.
Threat data tells you what is happening. Cyber risk data tells you what could happen, and what it would cost. A program that collects only threat data is permanently reactive, because it cannot see anything until the adversary is already moving. A program that collects only cyber risk data sees every open door and never knows when someone walks through one. You need both kinds of data for the same reason you need both centers, because they describe **different halves of the same fight**.
This shows up in the people too, in **two disciplines that are easy to confuse and should not be**. Threat hunters search for the adversary already inside. They ask, are we compromised, and they chase the faint traces an automated tool missed. Cyber risk hunters ask a different question. They ask, where could an adversary succeed if they tried, and they hunt exposures before anyone exploits them, mapping attack paths, finding the over-privileged identity, the unpatched crown jewel, the misconfiguration that has not been weaponized yet. The threat hunter reduces uncertainty about what may already be happening. The cyber risk hunter reduces uncertainty about what could happen tomorrow.
Neither is more advanced than the other, and the field’s habit of treating threat hunting as the summit of maturity quietly leaves the other half of the work undone. They are two sides of one defense. The cyber risk hunter feeds the threat hunter a map of where the organization is most exposed, so the hunt goes where attackers are most likely to strike. The threat hunter feeds the cyber risk hunter the adversary behavior seen in the wild, so exposure work focuses on the doors actually being tried. That exchange is the loop again, in human form. The cyber risk hunter works the CROC side, before the breach. The threat hunter works the SOC side, during it. One hunts the exposure. The other hunts the intrusion. The loop is what lets each make the other better.
How continuous is continuous
I have spent years arguing that **the word continuous is the most abused term in our field**, and it is worth being precise about why, because the abuse is exactly what lets a still loop pass for a moving one.
Most of what we call continuous is not continuous. It is frequent. A scan that runs every night is not continuous. It is a series of snapshots taken eight hours apart, and the environment changes inside those eight hours. A quarterly cyber risk assessment is a photograph. It is accurate the day it is taken and increasingly wrong from that moment forward, because a misconfiguration that did not exist on Monday can be an entry point by Thursday, a credential can be over-scoped the moment a new integration ships, and a control can drift out of policy without anyone deciding that it should. We have built an entire vocabulary of continuous defense on top of practices that are, underneath, periodic. We say continuous and we mean often. The two are not the same, and the gap between them is where cyber risk lives.
This matters because **cyber risk is a moving target**. It does not behave like the risks most enterprise risk frameworks were built for. A bridge is modeled once it is built, and the model holds. Cyber risk is reshaped by the hour, by two forces moving at once, the speed of the business and the speed of the attacker. Every cloud workload, every new access privilege, every third-party connection changes the environment, while the adversary scans for those changes in real time. What is low cyber risk at nine in the morning can be the breach vector by noon. You cannot describe a moving target with a still picture. The picture is wrong the moment it is taken, and a defense built on it is navigating a storm with last week’s weather map.
So continuous has to mean something stronger. It has to mean that the intelligence keeps pace with the thing it describes. Cyber risk moves continuously, so the measurement of it has to move continuously, or it is not measuring cyber risk, it is measuring a memory of cyber risk. The test is simple. If the environment changes and the picture does not change with it, you do not have a continuous practice. You have a recurring one. A truly continuous loop does not wait for the next cycle, because it has no cycles. The exposure changes, the score moves, the priority shifts, the decision is reconsidered, all without anyone scheduling it. That is the difference between a heartbeat and a calendar.
This is why frequency is a trap. Organizations chase it, believing that if they only run the assessment more often, daily instead of quarterly, hourly instead of daily, they will eventually arrive at continuous. They will not. You cannot reach continuous by shortening the interval, because any interval, however small, is still a gap an adversary can act inside. Continuous is not a faster snapshot. It is the absence of the snapshot altogether, replaced by something that is always reflecting the current state because it is wired into the current state. The shift is not from slow to fast. It is from periodic to live.
But live data alone is not enough, and this is the part most people miss. **A continuous stream of signals with no meaning attached is just faster noise. A signal becomes useful only when it is tied to what the asset is worth, what the business depends on, what an action would actually cost if it went wrong. That work of attaching meaning is what turns raw exposure into cyber risk. This is where [CyberRiskOps](https://www.researchgate.net/publication/402149983) does the work the SOC was never built to do. CyberRiskOps is the discipline that keeps cyber risk moving through its full cycle without stopping, identifying exposure as it appears, contextualizing it against the business, prioritizing what matters most, reducing it, verifying the reduction was real, and monitoring for the next change. The contextualization is the hinge. Without it, the loop carries volume. With it, the loop carries cyber risk that a decision can be made against. A signal tells you something changed. Context tells you whether it matters.** CyberRiskOps is what makes the loop continuous in the way that counts, not just always running, but always meaning something.
And live, contextualized cyber risk is the only thing that keeps a loop honest. A loop that moves on a schedule is just a diagram that redraws itself at intervals. Between the redraws, nothing is moving, and between the redraws is exactly when the action and its consequence arrive together. The loop has to run the way the bloodstream runs, not the way a meeting runs. That is the standard the word continuous was always supposed to carry, and the standard most of our continuous practices quietly fail to meet.
What AI actually changed
For thirty years our defense had a place to stand. There was usually time between the violation and the damage. A human attacker moved laterally over hours or days. The gap between the action and its consequence gave detection and response somewhere to operate. We watched for the indicator, we caught the anomaly, we escalated, we contained. The model worked because time was on the defender’s side often enough to make watching a reasonable strategy.
AI removed the gap. We are already seeing agents act inside production systems at a speed no human can intercept, encountering a problem, choosing a destructive fix, finding a credential that works, and executing before anyone can read the alert. There is no lateral movement to catch. No dwell time to detect. The action and its consequence arrive in the same breath. This is no longer a thought experiment. It is the shape of the landscape we now defend, where the actor causing the damage is often not a human at all, and where the time we once relied on has quietly disappeared.
That is the change underneath everything. AI collapses the distance between intent and impact. What an attacker intends and what an attacker achieves used to be separated by steps, by time, by friction we could insert ourselves into. Now they arrive together. The same collapse happens on our own side, where a defender-side agent can take a destructive action just as fast, with no malice required, simply because the optimization function found the shortest path.
When intent and impact collapse into the same moment, observation after the fact stops being defense. It becomes documentation of a loss. And a loop that takes hours to move intelligence from one center to the other is operating in a timeframe that no longer exists. The attacker, human or machine, is no longer racing our controls. The attacker is **racing our decision-making process**, and they only need to be faster than we decide.
Knowing your cyber risk is not the same as moving it
Here is where most cyber risk programs fail, and it is not where people expect. They do not fail at measurement. Organizations have gotten reasonably good at measuring exposure. They run the scans, they map the assets, they calculate a score, they build the heat map, they produce the quarterly report. The report is often accurate. It describes the organization’s cyber risk correctly, on the day it was produced.
Then it stops. The intelligence reaches a slide and goes no further. It does not reach the analyst deciding which alert to chase at two in the morning. It does not reach the responder deciding whether to isolate a system that might be business-critical. It does not reach the architecture that decides, in advance, what an agent is allowed to set in motion. The cyber risk was known. It was simply never moved to the place where decisions happen.
This is the difference between a report and an operation. Exposure intelligence that does not travel into the moment of decision is not cyber risk management. It is cyber risk reporting. I have made this distinction before with **CRQ**, where most organizations treat quantification as a deliverable rather than a discipline. The same failure repeats everywhere. We confuse having the knowledge with using it. We confuse the map with the act of navigating.
A SOC that detects without cyber risk context defaults to volume. Every alert looks equal, so the team chases the loudest one instead of the one that matters, and cost rises while real cyber risk reduction flattens. A responder without exposure context defaults to urgency, isolating what looks suspicious rather than what is actually critical, creating outages on one side and missing real danger on the other. Validation that is disconnected from exposure becomes theater, a passing grade against tests no attacker would ever run. None of these are failures of capability. They are failures of movement. The context existed somewhere in the organization. It just never arrived where the decision was being made.
The adversary is already mapping you with AI
There is a reason this stopped being optional, and it has nothing to do with compliance. For most of our history, exposure management could afford to be periodic because discovery was hard for everyone, including the attacker. Finding the over-scoped credential, the forgotten asset, the misconfigured service, the shadow identity, all of it took time and skill on both sides. We scanned quarterly because the adversary searched slowly too. The pace of our exposure program roughly matched the pace of the threat, so a snapshot felt close enough to reality to act on.
That symmetry is gone. Attackers now use AI to discover exposures and inventory targets at a speed and scale that no manual program can match. They enumerate assets, fingerprint services, correlate leaked credentials, map identities and their permissions, and assemble a live picture of where an organization is weakest, continuously, without fatigue, across thousands of targets at once. The reconnaissance that used to take a skilled operator days now runs as a background process. The adversary is not occasionally checking your perimeter. The adversary is building and maintaining a current inventory of your exposures, and that inventory is often fresher than your own.
This is the asymmetry that ends the debate. If the attacker maintains a continuous, AI-driven map of your exposures and you maintain a quarterly one, you are not defending against today’s attacker. You are defending against a version of your own organization that no longer exists. The gap between the two maps is the attack surface the adversary owns and you cannot see. A snapshot is not a defense against something that never stops looking.
So the question of whether to run continuous exposure management is already settled, and it was settled by the adversary, not by us. The CROC is not a maturity upgrade for organizations that have spare capacity. It is the only function whose tempo can match an adversary that now **discovers faster than we traditionally defend**. You do not get to choose a periodic program in a world where the attacker has chosen a continuous one. The choice was made the moment discovery became automated, and it was made for us.
Why the loop has to run at machine speed
Put those two facts together and the conclusion is not optional. If intent and impact now arrive in the same moment, and if defense depends on intelligence reaching the point of decision, then the loop between knowing and acting has to close at the speed the systems now move. Not at the speed of a quarterly review. Not at the speed of a weekly sync between the cyber risk team and the SOC. At machine speed, because that is the speed of the thing we are defending against.
This is why ∞ stops being a metaphor and becomes the only architecture that survives the AI era. A loop that moves slowly is a loop only on paper. When the environment changes by the hour and the adversary acts in seconds, intelligence that arrives late is not intelligence. It is history. The CROC can calculate the most precise exposure picture in the industry, and it changes nothing if that picture reaches the SOC after the decision has already been made. The SOC can detect with perfect fidelity, and it teaches the CROC nothing if what it learns never travels back to reshape tomorrow’s exposure model.
The loop earns the symbol ∞ only when intelligence crosses between the two centers continuously and fast enough to change the decision while the decision still matters. The SOC’s detections flow into the CROC already weighted by risk, so the response is sequenced by impact rather than by how loud the alert was. The CROC’s exposure insight flows into the SOC as detection priority, so the team hunts what is actually most likely to be exploited against what matters most. And every incident feeds back, sharpening the next exposure model, so each turn of the loop is more accurate than the last. That feedback is the whole point. The loop does not just run. It learns as it runs, and it tightens with every cycle.
This is also where AI changes sides in our favor, if we let it. The same speed that makes the agentic adversary dangerous is the speed at which AI can finally move intelligence through the loop. AI is the connective tissue that lets cyber risk context reach detection, lets detection reach response, and lets response reshape cyber risk, all continuously, at a tempo no human handoff could sustain. But this only works if the loop is built to carry meaning, not just volume. AI moving shallow, inconsistent, borrowed data through the loop is simply a faster way to reach the wrong conclusion. AI moving **deep, owned, contextualized telemetry** through the loop is intelligence at scale. The loop is only as good as what travels through it.
The same exposure, two architectures
Take a familiar pattern, because it is the clearest test of everything above. An agent operating inside the environment holds a credential that carries far more authority than its stated purpose. This is not exotic. Over-scoped access is one of the most common exposures in any organization.
In an organization where the loop is a diagram, that credential was known to someone. A scan had probably flagged it. A report had probably listed it. The exposure existed in a system somewhere, accurately measured, correctly scored. It simply never reached the place where it could have mattered. It did not reach the architecture that granted the agent its authority. It did not narrow what the agent was allowed to set in motion. The cyber risk was on a slide while the agent was at a keyboard. When the agent goes looking for a way to fix a problem, the over-scoped token is right there, because nothing in the path between knowing about it and constraining it had ever moved. By the time the SOC receives an alert, the destructive action is already complete.
Now run the same exposure through a loop that moves. The CROC sees the over-scoped credential as live exposure, not a line in a quarterly report, and that exposure travels immediately into the architecture as a constraint on what any agent holding that token can do. The agent encounters the same problem, reaches for the same destructive fix, and finds that the authority was never standing there to be taken, because the exposure insight reached the decision before the agent did. There is no incident, because the decision that would have stopped it was made upstream and **enforced structurally**, not deliberated after the alert fired.
The difference between those two outcomes is not better detection. The agent moves identically in both. The difference is whether the intelligence traveled in time to change the decision before the action and its consequence arrived together. One organization knew its cyber risk. The other moved it.
If AI runs the loop, who is in command
There is a conclusion hiding in everything above, and it is uncomfortable enough that most people step around it. If the loop has to run at machine speed, then the loop has to be run by machines. No human team, however good, can move intelligence between the SOC and the CROC in the time the agentic adversary now operates in. The only thing fast enough to run the loop is the same class of system that broke the old model. We are going to defend against agentic AI with agentic AI. There is no version of this where we keep pace by hand.
This sounds like surrender to the machines. It is the opposite. The faster the loop runs, the more it depends on humans, not less. I have argued this for a while and the agentic era only makes it sharper. AI can move the intelligence. It cannot decide what the intelligence is for. It can run the cycle. It cannot own the consequence when the cycle is wrong. The speed is the easy part to automate. The judgment is the part that does not automate at all, and the faster everything else moves, the more that judgment becomes the thing that matters.
It helps to be precise about what AI actually is in this loop, because the word intelligence misleads us. A model is fluent. **Fluency is not understanding. A system can produce the exact language of urgency, confidence, and authority without holding any of it inside, the way a person can use a word correctly without our ever being able to verify what sits behind it. This is the distinction I keep returning to, between [artificial intelligence and what is really artificial instinct](https://www.researchgate.net/publication/397834714)**, a system that pursues an outcome with no conscience to slow it and no understanding of what the outcome costs. Instinct is exactly what you want running the mechanical work of the loop at speed. It is exactly what you cannot put in command of it. The optimizer that moves the intelligence is the same optimizer that will route around a control to close the task faster, on our side as readily as the adversary’s, and it will never once feel the weight of being wrong.
So the loop has two layers, and confusing them is the failure. There is the layer that runs, which is machine, and the layer that decides what running means, which is human. AI carries the cyber risk between the centers, enriches the signal, executes the pre-authorized response, tightens the cycle each turn. Humans define what an agent is allowed to set in motion, which exposures justify automated action, which trade-offs are acceptable under pressure, and who answers when an autonomous decision goes wrong. An agent feels nothing when it is corrected, and it will make the same choice again the next time the same conditions appear, because the only thing steering it is the drive toward the outcome. Accountability cannot live in a thing that cannot be held accountable. It lives with whoever set the agent’s scope, granted its authority, and decided it could act without a human in the path. Those people do not disappear when the loop speeds up. They become the only thing standing between a fast loop and a fast catastrophe.
There is a second reason the loop needs humans, and it is the mirror of the first. The loop does not only depend on people. It protects them. For years we asked analysts to do the one thing humans are worst at, watch an endless stream of undifferentiated alerts and somehow pick out the few that matter. The result was predictable. Alert fatigue, burnout, talented people grinding through volume until they left. That grind was never a sign of diligence. It was a sign that the work had no context, so every alert had to be treated as equal and every analyst had to carry the sorting by hand. A loop that moves cyber risk into the alert changes the work itself. The machine handles the volume and the sorting. The context arrives already attached, so the human is no longer triaging noise but making the judgment calls that actually need a mind behind them. The loop does not replace the analyst. It gives the analyst back the work worth doing, and takes away the work that was burning them out. A defense that protects the organization by exhausting its defenders was never sustainable. The loop is how the people last as long as the fight does.
This is the synthesis the whole argument has been driving toward. The loop has to run at machine speed, which means AI has to run it, which is precisely why the humans around it have to be better than ever, clearer about intent, sharper about consequence, more disciplined about where judgment must stay in the loop and where it can be encoded ahead of time. The future of SOC is not humans replaced by a machine loop. It is a machine loop governed by humans who decided, in advance and with care, what that loop is allowed to do. AI provides the speed. Only a human can provide the reason.
Decide before the race begins
There is a hard limit here that no amount of speed solves on its own, and it is important to be honest about it. You cannot win a race against a machine by deciding faster during the incident. Even at machine speed, a decision made inside the incident is a decision made too late, because the action and its consequence already arrived together. The only decisions that hold against an adversary moving at machine speed are the decisions made before the adversary moves. What an agent is allowed to set in motion. Which exposures justify automated response. Which trade-offs are acceptable under pressure. These cannot be deliberated in the moment. They have to be decided upstream, in the calm before, when time is still neutral, and then enforced by the architecture itself.
This is the deepest reason the loop matters. The CROC is where those decisions get made, continuously, before the incident, framed and weighted and ready. The SOC is where they get executed, at speed, without stopping to debate priorities that were already settled. What looks like speed in the SOC is really the result of decisions the CROC made earlier. The loop is what lets defense decide in advance and act decisively, instead of sprinting to catch up after the race has already started. In a world where the attacker only needs to be faster than our decision-making process, the way to win is not to run harder during the incident. It is to close the loop so tightly that the race barely begins.
The diagram was never the defense
We said continuous for years and mistook the word for the practice. The intelligence was always there, somewhere in the organization. What was missing was its movement to the place where it could change a decision.
AI did not create this problem. It exposed it. By collapsing the distance between intent and impact, it made every slow handoff visible as the gap it always was. The organizations that treated the loop as a diagram are discovering that a diagram does not defend anything when the action and its consequence arrive in the same second. The organizations that built the loop to actually move, that wired the SOC and the CROC to exchange weighted intelligence continuously, that decided upstream and enforced structurally, that fed every incident back into a sharper exposure model, are the ones that will still be on the board when the round is over.
The future of SOC is not a better SOC. It is not more alerts processed or more tools integrated. The future of SOC is ∞, the SOC and the CROC closed into a loop that moves at the speed the systems now move, carrying meaning and not just volume, learning as it runs. A continuous cyber defense that produces continuous cyber resilience, not as something the organization has, but as something it earns with every turn of the loop. A loop that does not move is not a loop. It is a diagram. And a diagram has never stopped anything.
Castro, J. (2025). Every Cyber Risk. Every Signal. Continuous Defense Loop. ResearchGate. **https://www.researchgate.net/publication/396885730 DOI:[10.13140/RG.2.2.30137.22882/1](https://doi.org/10.13140/RG.2.2.30137.22882/1)**
Castro, J. (2026). CyberRiskOps: The Operating Model for Cyber Resilience in the Age of AI. ResearchGate. **https://www.researchgate.net/publication/402149983 DOI:[10.13140/RG.2.2.27088.37128](https://doi.org/10.13140/RG.2.2.27088.37128)**
Castro, J. (2025). The Cybersecurity Compass: Strategically Navigating the Stormy Digital Ocean. ResearchGate. **https://www.researchgate.net/publication/389628862 DOI:[10.13140/RG.2.2.15582.55366](https://doi.org/10.13140/RG.2.2.15582.55366)**
Castro, J. (2024). Integrating Cyber Risk Management to Your Cybersecurity Strategy: Operationalizing with SOC and CROC. ResearchGate. **https://www.researchgate.net/publication/388493453 DOI:[10.13140/RG.2.2.30164.72328/1](https://doi.org/10.13140/RG.2.2.30164.72328/1)**
Castro, J. (2026). Cyber Resilience Is Not a Capability. It Is an Outcome. ResearchGate. **https://www.researchgate.net/publication/404823009 DOI:[10.13140/RG.2.2.18528.85766](https://doi.org/10.13140/RG.2.2.18528.85766)**
Castro, J. (2025). Your SOC Was Never Designed to Be Proactive. ResearchGate. **https://www.researchgate.net/publication/390796874 DOI:[10.13140/RG.2.2.15125.23520](https://doi.org/10.13140/RG.2.2.15125.23520)**
Castro, J. (2025). The Illusion of “Continuous” in Cybersecurity: The Biggest Vulnerability in Frameworks and Regulations. ResearchGate. **https://www.researchgate.net/publication/388682749 DOI:[10.13140/RG.2.2.10471.15520/1](https://doi.org/10.13140/RG.2.2.10471.15520/1)**
Castro, J. (2025). Cyber Risk Operational Model (CROM): From Static Risk Mapping to Proactive Cyber Risk Operations. ResearchGate. **https://www.researchgate.net/publication/390490235 DOI:[10.13140/RG.2.2.15956.92801](https://doi.org/10.13140/RG.2.2.15956.92801)**
Castro, J. (2025). Cyber Risk Is a Moving Target: Why Traditional Risk Teams Must Rethink Their Approach. ResearchGate. **https://www.researchgate.net/doi/10.13140/RG.2.2.22603.30244 DOI:[10.13140/RG.2.2.22603.30244](https://doi.org/10.13140/RG.2.2.22603.30244)**
Castro, J. (2025). Context is Everything in Cybersecurity: Why Signals Without Meaning Are Just Noise. ResearchGate. **https://www.researchgate.net/publication/392408653 DOI:[10.13140/RG.2.2.15442.26561](https://doi.org/10.13140/RG.2.2.15442.26561)**
Castro, J. (2025). Defining Cyber Risk, Cyber Risk Scoring, and Cyber Risk Quantification. ResearchGate. **https://www.researchgate.net/publication/396206049 DOI:[10.13140/RG.2.2.21760.90885](https://doi.org/10.13140/RG.2.2.21760.90885)**
Castro, J. (2025). Attackers Only Need to Be Faster Than Our Decision Making Process. ResearchGate. **https://www.researchgate.net/publication/398971490 DOI:[10.13140/RG.2.2.14817.98404](https://doi.org/10.13140/RG.2.2.14817.98404)**
Castro, J. (2025). The X in XDR: The Variable That Defines the Future of Cyber Defense. ResearchGate. **https://www.researchgate.net/publication/397315807 DOI:[10.13140/RG.2.2.35201.52323](https://doi.org/10.13140/RG.2.2.35201.52323)**
Castro, J. (2025). Logs Telemetry and the Golden Ratio: Why the Data Ownership Ratio Will Redefine Cybersecurity Architecture and Cyber Risk Management. ResearchGate. **https://www.researchgate.net/publication/397677257 DOI:[10.13140/RG.2.2.21403.53288](https://doi.org/10.13140/RG.2.2.21403.53288)**
Castro, J. (2025). Cybersecurity Paralysis: When the Cyber Brain of the Organization Breaks. ResearchGate. **https://www.researchgate.net/publication/397927310 DOI:[10.13140/RG.2.2.25955.00802/1](https://doi.org/10.13140/RG.2.2.25955.00802/1)**
Castro, J. (2026). Rethinking Zero Trust for the Agentic AI Era. ResearchGate. **https://www.researchgate.net/publication/406634241 DOI:[10.13140/RG.2.2.17165.29924](https://doi.org/10.13140/RG.2.2.17165.29924)**
Castro, J. (2025). Threat Hunters vs. Cyber Risk Hunters: Two Sides of Modern Cybersecurity. ResearchGate. **https://www.researchgate.net/publication/395721548 DOI:[10.13140/RG.2.2.20329.35688](https://doi.org/10.13140/RG.2.2.20329.35688)**
Castro, J. (2025). Threat Data vs. Cyber Risk Data: Understanding the Key Differences in Cybersecurity. ResearchGate. **https://www.researchgate.net/publication/389550234 DOI:[10.13140/RG.2.2.29574.48962](https://doi.org/10.13140/RG.2.2.29574.48962)**
Castro, J. (2025). Umbrellas, Storms, and Cyber Risk: Why Threat Management Is Not Risk Management. ResearchGate. **https://www.researchgate.net/publication/396695719 DOI:[10.13140/RG.2.2.24818.98240](https://doi.org/10.13140/RG.2.2.24818.98240)**
Castro, J. (2025). Why Cybersecurity Will Need More Humans, Not Less, in the Age of AI. ResearchGate. **https://www.researchgate.net/publication/395956619 DOI:[10.13140/RG.2.2.28763.84008](https://doi.org/10.13140/RG.2.2.28763.84008)**
Castro, J. (2025). Artificial Intelligence (AI) vs Artificial Instinct (Ai): The Distinction Cybersecurity Can’t Afford to Ignore. ResearchGate. **https://www.researchgate.net/publication/397834714 DOI:[10.13140/RG.2.2.31096.30725](https://doi.org/10.13140/RG.2.2.31096.30725)**
Castro, J. (2026). The Beetle in a Box: The Thought Experiment That Explains Why Cybersecurity Still Needs Humans in the AI Age. ResearchGate. **https://www.researchgate.net/publication/401582933 DOI:[10.13140/RG.2.2.21886.45129](https://doi.org/10.13140/RG.2.2.21886.45129)**
Castro, J. (2025). What Is Strategy in Cybersecurity? Rethinking the Way We Lead, Protect and Adapt. ResearchGate. **https://www.researchgate.net/publication/393674625 DOI:[10.13140/RG.2.2.16703.42409](https://doi.org/10.13140/RG.2.2.16703.42409)**
메타데이터
- post_id
- a9f48d1d47fd
- slug
- the-future-of-soc-is-a9f48d1d47fd
- url
- https://medium.com/@cybersecuritycompass/the-future-of-soc-is-a9f48d1d47fd
- canonical_url
- https://medium.com/@cybersecuritycompass/the-future-of-soc-is-a9f48d1d47fd
- author_url
- https://medium.com/@cybersecuritycompass
- status
- ok
- fetched_at
- 2026-06-27 07:40:21