The Context Gap: Why Your SOC Misses Attacks It Already Logged
Every SOC has the same secret: the breach was in the logs the whole time. The login fired, the badge swipe was recorded, the query ran. The data was there. Nobody could read the story it was telling. That's not a visibility problem, it's a context problem. A 2 AM login means nothing until you know the account owner resigned yesterday, the box it hit is a domain controller, and the user has wire-transfer authority. Same event, three answers, and only one of them is "escalate now." This talk is about the layer most SOCs never build: identity, asset, business, and operational context wired into the alert before an analyst opens it. Through real investigations, we'll show how the same alert goes from a 45-minute tab-hunting chase to a 5-minute escalation, why this context gap is an attacker's window and not just an inefficiency, and how to get the data out of departments such as HR, IT, and Finance, who don't report to you. And we'll cover why this same context layer is what every AI agent in your SOC will live or die on as the SOC gets agentic. Key takeaways: Why more data and more tools quietly made triage worse, not better. The four kinds of context that change what an alert means (identity, asset, business, operational) and how that transforms detections and investigations. Practical ways to build a more decision-driven SOC.
Speaker

Marvin Ngoma
Elastic, Principal Security Architect, Security Evangelist
Marvin is a seasoned consultant and security architect. He has a strong passion for helping organizations succeed in their cybersecurity programs. He has led many projects in both the private and public sectors, architecting and building Security Operations and Intelligence capabilities; unifying tools, processes, and people. Prior to joining Elastic, Marvin worked as a security consultant at IBM and was the primary SME for QRadar in the nordics. In addition to his work with clients, Marvin... read more