Arcanna

    Insights & Articles

    Insights on Decision Models, agentic workflows, and governed AI for SOC teams. Articles for CISOs, SOC managers, and MSSPs on consistency, evidence, and risk reduction.

    Latest Articles

    All Articles

    34 articles total
    Alert triage
    Investigation Layer

    When analysts can't keep up with low-priority alerts: what AI triage actually fixes

    An analyst opens a queue of hundreds of low-priority alerts — what's actually going wrong, and can AI fix it? Denis Stefan, AI Engineer at Arcanna, breaks down why rule tuning, SOAR, and LLM assistants stall, and what an agentic investigation runs step by step.

    May 28, 2026
    Read article
    Decision Layer
    AI Governance

    What to Look for in AI SOC Platforms: Thresholds, Drift, Rollback

    How do you evaluate an AI SOC platform that will still be working in 18 months? A practitioner-led framework: thresholds, drift detection, and rollback.

    May 20, 2026
    Read article
    Alert Triage
    SOC Automation

    From Pilot to Business Case: Evaluating AI Triage Tools

    Most AI SOC automation tools fail in pilot because evaluators confuse training with overhead. Darius Iakabos on how to build a defensible business case for AI triage without a heavy configuration burden — and why your data is the asset, not the obstacle.

    May 15, 2026
    Read article
    Agentic AI
    SOC Automation

    Inside an Agentic Investigation: The Architecture That Actually Works

    What an agentic investigation actually looks like — and what it takes to make one trustworthy enough for production. Denis Stefan walks through the four guardrails that separate agentic AI demos from systems you can actually run in a SOC.

    May 7, 2026
    Read article
    SOC Automation
    AI Security

    Governing AI in the SOC: The Case for a Trust Layer

    If AI is making security decisions inside your environment, who's accountable when it's wrong? Alina Marcu, PhD, on why AI in the SOC needs a Trust Layer — grounded decisions, governed agentic investigations, and the architecture CISOs need before the board asks what happened.

    April 28, 2026
    Read article
    SOC Automation
    AI Security

    Why SOAR Breaks at Scale, and What Actually Replaces It

    SOAR hit its ceiling. Playbook sprawl, LLM inconsistency, and headcount-driven scaling broke the model. Here's what the next layer of SOC automation looks like.

    April 21, 2026
    Read article
    SOC Automation
    AI Security

    Trustworthy AI In the SOC

    AI's time is now, but it's not just 'AI Agent All the things'. Most SOCs are drowning in alerts, and while AI Agents promise autonomous solutions, the reality is more nuanced. Learn why Decision Models offer a fast, trustworthy, and cost-effective approach.

    July 18, 2025
    Read article
    SOC Automation
    Decision Models

    Arcanna: The Foundation for an Evolving SOC

    SOCs worldwide are being bombarded with messaging around Agentic AI. While SOAR provides significant value, throwing out playbooks isn't viable. Learn how Decision Models simplify and enable SOC evolution.

    July 18, 2025
    Read article
    Autonomous AI
    Decision Intelligence

    Autonomous Decisions: Turning the Tables in the Defenders' Favor

    Security analysts face information overload and evolving threats daily. Learn how autonomous decision-making AI can handle the 99.99% of tedious work while experts focus on what truly matters.

    January 20, 2025
    Read article