FIG. 08 Field notes

Lessons from the SOC, written plainly.

A working journal from the IronCastle SOC and detection engineering teams. Incident write-ups (sanitised), threat intelligence we think you'd actually use, and the occasional opinion piece on the state of managed security for SMBs.

FEATUREDINCIDENT WRITE-UP · 18 MIN READ

The 6-minute compromise that took us nine days to find.

A logistics SMB. A finance manager's MFA fatigue. A token-stealer hidden in a fake Microsoft Authenticator update. Here's the full timeline, what our detection missed, what caught it, and what we shipped fleet-wide so it never happens to anyone else again.

By Mariana Reyes, VP Security Operations · 14 February 2026

9d
DWELL TIME · BEFORE DETECTION
GUIDE

Does a 30-person company need a SOC?

What a security operations center actually does, what it costs to build versus buy, and how a small business gets 24/7 coverage without a million-dollar team.

12 Jun 20268 MIN
THREAT INTEL

Helldown ransomware — what we're seeing in APAC manufacturing.

A new ransomware family targeting OT-adjacent networks via Zyxel firewall CVEs. We've seen it three times in our fleet this month; all three contained pre-encryption.

09 Feb 202611 MIN
ENGINEERING

Why we moved 90 days of telemetry to ClickHouse.

From Elasticsearch to ClickHouse: a four-month migration that cut our query p95 from 11 seconds to 340ms while halving the storage bill. The trade-offs we made and the ones we didn't.

04 Feb 202614 MIN
OPINION

SMB security has a noise problem, not a tooling problem.

The average SMB IT lead is drowning in alerts from tools that were sold to them as solutions. A reset on what we should be measuring.

28 Jan 20269 MIN
INCIDENT WRITE-UP

BEC against an architectural firm — Sydney, December.

A spoofed director email, a $114,000 wire transfer, and the seven-second window where our detection scored the conversation as anomalous. Containment, recovery, and what changed in the runbook.

22 Jan 202616 MIN
CUSTOMER LETTER

What our customers asked us to ship in 2026.

Annual roadmap letter. The five things we're committing to ship publicly, the three we're not, and why.

14 Jan 20267 MIN
THREAT INTEL

OAuth grant abuse against Microsoft 365 — December trend.

A 4× increase in malicious OAuth consent grants targeting M365 tenants. The three permissions to watch, the policy switch most tenants haven't enabled, and a one-page response runbook.

09 Jan 202610 MIN
ENGINEERING

The case against scoring detections in real time.

Why our detection engine deliberately delays scoring by 30–90 seconds. A short essay on noise budgets, batch correlation, and the engineering value of patience.

02 Jan 20268 MIN
RELEASE NOTES

Q4 2025 release notes — 31 detections, 4 integrations, 2 nice things.

Everything we shipped to the platform in October–December, with the rationale and any backtest results worth noting.

22 Dec 20255 MIN
OPINION

"Just buy CrowdStrike" — a cautionary tale.

An EDR licence is not a security operations program. A long, friendly argument with a customer who almost left us, and what we both learned.

18 Dec 202511 MIN
INCIDENT WRITE-UP

Insider-risk pattern at a Dubai logistics firm.

A departing operations manager, two USB exfil events, and a polite conversation with HR. Sanitised but instructive.

11 Dec 202513 MIN
THREAT INTEL

Why "AI phishing" still mostly fails — for now.

A look at LLM-generated phishing in our fleet. Click-rates are up; conversion-to-compromise is flat. The actual rising threat is something else.

04 Dec 20259 MIN
CUSTOMER LETTER

On the price-lock — and why we're holding it.

Cloud costs are up 18% this year for us. We're absorbing it. Here's the reasoning and the maths.

27 Nov 20256 MIN
ENGINEERING

Building the owner's digest with a 1024-token budget.

How we prompt-engineered the weekly owner digest to stay calm, accurate, and 220-words-or-fewer. With examples and a couple of regrettable failures.

20 Nov 202512 MIN
INCIDENT WRITE-UP

Ransomware via a managed-services partner — November.

A customer's MSP got popped. Lateral movement attempted into our customer's environment. Caught in 11 minutes. The trust-boundary lessons.

13 Nov 202515 MIN
OPINION

The MSSP industry is broken. We're trying to be different.

A founder essay. The industry's incentive structures, why most managed-security engagements fail SMBs, and the specific bets we made differently.

06 Nov 202517 MIN
THREAT INTEL

Q3 fleet trends — the five shifts that matter for SMBs.

Quarterly intel digest. Identity attacks now account for 41% of our fleet's confirmed-malicious incidents. The full breakdown.

30 Oct 202514 MIN
INCIDENT WRITE-UP

The phone-call BEC that nearly worked.

A vishing call to a finance team, a near-wire, and the callback policy that saved $230k. With audio waveforms (sanitised).

23 Oct 202511 MIN
INCIDENT WRITE-UP

Drive-by JS supply-chain compromise on a regional ad-tech.

A third-party JS pixel got compromised. Our fleet caught the C2 beacon within 4 minutes. The vendor took six days to respond.

16 Oct 202510 MIN

A monthly letter from the SOC.

Six emails a quarter, on average. Field notes, threat intel digests, the occasional opinion piece. Read by ~7,400 SMB IT leads. Unsubscribe in one click.