Arcanna

    Insights & Articles

    Insights on Decision Models, agentic workflows, and governed AI for SOC teams. Articles for CISOs, SOC managers, and MSSPs on consistency, evidence, and risk reduction.

    Latest Articles

    All Articles

    Decision Layer
    AI Governance

    What to Look for in AI SOC Platforms: Thresholds, Drift, Rollback

    How do you evaluate an AI SOC platform that will still be working in 18 months? A practitioner-led framework: thresholds, drift detection, and rollback.

    May 20, 2026
    Read article
    Alert Triage
    SOC Automation

    From Pilot to Business Case: Evaluating AI Triage Tools

    Most AI SOC automation tools fail in pilot because evaluators confuse training with overhead. Darius Iakabos on how to build a defensible business case for AI triage without a heavy configuration burden — and why your data is the asset, not the obstacle.

    May 15, 2026
    Read article
    Agentic AI
    SOC Automation

    Inside an Agentic Investigation: The Architecture That Actually Works

    What an agentic investigation actually looks like — and what it takes to make one trustworthy enough for production. Denis Stefan walks through the four guardrails that separate agentic AI demos from systems you can actually run in a SOC.

    May 7, 2026
    Read article
    SOC Automation
    AI Security

    Governing AI in the SOC: The Case for a Trust Layer

    If AI is making security decisions inside your environment, who's accountable when it's wrong? Alina Marcu, PhD, on why AI in the SOC needs a Trust Layer — grounded decisions, governed agentic investigations, and the architecture CISOs need before the board asks what happened.

    April 28, 2026
    Read article
    SOC Automation
    AI Security

    Why SOAR Breaks at Scale, and What Actually Replaces It

    SOAR hit its ceiling. Playbook sprawl, LLM inconsistency, and headcount-driven scaling broke the model. Here's what the next layer of SOC automation looks like.

    April 21, 2026
    Read article
    SOC Automation
    Decision Models

    Arcanna: The Foundation for an Evolving SOC

    SOCs worldwide are being bombarded with messaging around Agentic AI. While SOAR provides significant value, throwing out playbooks isn't viable. Learn how Decision Models simplify and enable SOC evolution.

    July 18, 2025
    Read article
    Decision Intelligence
    Predictive AI

    Decision Making in the Era of AI

    Decision Intelligence harnesses AI to make better, faster decisions in cybersecurity. Learn how Arcanna.ai combines predictive and generative AI to create an autonomous decision-making system for SOC teams.

    January 20, 2025
    Read article
    CISO
    Operational Efficiency

    CISOs Guide to Balancing Operational Efficiency and Cost

    As a CISO, you constantly deal with improving operational efficiency while keeping costs down. Learn the common problems and strategies for finding the right balance to keep your organization's data safe.

    January 20, 2025
    Read article
    SIEM
    Threat Detection

    Top Five SIEM Use Cases for Active Threat Detection

    A critical tool that an IT department and their SOC needs to rely on is their SIEM tool. Learn the top 5 use cases for active threat detection including privileged account monitoring, defense evasion, DDoS, and data exfiltration.

    January 19, 2025
    Read article

    Practitioner interviews

    INSIDE ARCANNA

    3 perspectives on why existing security stacks are breaking, and what trustworthy AI in operations actually requires.

    Darius Iakabos, Technical Solution Architect at Arcanna

    Darius Iakabos

    Technical Solution Architect

    SOC SCALE

    “SOAR was built for predictable workflows. SOC reality isn’t predictable.”

    Why SOAR’s scaling ceiling isn’t compute — it’s the playbook maintenance burden — and what replaces it.

    27 MINWatch
    Alina Marcu, PhD, Chief Data Scientist at Arcanna

    Alina Marcu, PhD

    Chief Data Scientist

    DECISION TRUST

    “AI without governance isn’t intelligence. It’s exposure.”

    What a Trust Layer actually does — and why grounded decisions, drift control, and rollback are the price of putting AI in front of operations.

    23 MINWatch
    Denis Stefan, AI Engineer at Arcanna

    Denis Stefan

    AI Engineer

    CONTROLLED AUTOMATION

    “An agentic investigation works when the agent knows what it doesn’t know.”

    How agentic investigations actually run end-to-end — structured outputs, decision-model guardrails, and verification at every step.

    18 MINWatch