
From Cyber Defense To Cyber Understanding
Cybersecurity leadership is increasingly defined not by the volume of signals an organization can collect, but by how quickly it can transform those signals into a reliable understanding of what is happening, what is at risk, and what must happen next.
As part of Global Cloud Security Forum 2026, presented by Cyngular, Paul Moskovich, Co-Founder and CEO of Cyngular Security, examines a defining contradiction within modern security operations. Enterprises possess more telemetry, detections, alerts, logs, and specialized cybersecurity tools than at any previous point, yet the people responsible for protecting the organization can still struggle to understand what is actually taking place inside the environment.
Moskovich approaches this problem through a career spanning national cyber operations, military command, aerospace and defense, financial services, and more than two decades as a CISO. He previously served as Deputy Director General and Chief of Cyber Operations at the Israeli National Cyber Directorate, reporting directly to the Israeli Prime Minister. He also served as a lieutenant colonel and operations commander in the Israeli military’s C4I Directorate and held senior security positions at Rafael, Elbit Systems, and the third-largest bank in Israel. He now leads Cyngular Security, which he describes as an agentic AI SOC platform focused primarily on cloud and hybrid environments.
That experience gives his argument an operational rather than theoretical character. Moskovich is not examining the security operations center solely as a collection of tools, workflows, and dashboards. He presents the SOC as a command environment in which analysts must interpret incomplete and sometimes conflicting evidence, determine whether a threat is real, understand what is at risk, and guide an effective response before the situation moves beyond the organization’s control.
He introduces the challenge through the story of Air France Flight 447. The aircraft entered a severe storm, critical instruments malfunctioned, and the cockpit became flooded with conflicting alerts. Moskovich’s point is that the pilots did not lack information. They were overwhelmed by information that did not provide a sufficiently clear understanding of the developing situation. The analogy establishes the central argument of the session. More signals do not necessarily create better decisions when those signals arrive without context, hierarchy, or explanation.
The modern SOC operates inside a similar tension. Moskovich describes it as the beating heart of the security organization, responsible for identifying and addressing threats that may already be developing within the computing environment. Yet analysts often begin each day inside a digital cockpit filled with unconnected alerts, uncertain priorities, and fragmented evidence. Organizations depend on these teams to protect critical systems while asking them to reason through more activity than people can realistically investigate.
The Context Crisis In The Modern SOC
Security technologies are highly effective at observing activity and producing alerts, but the production of an alert does not determine whether the activity is malicious, whether the affected asset is important, whether the identity involved has legitimate access, or whether the event belongs to a wider sequence. Those questions remain with the analyst, who must retrieve evidence from multiple systems and reconstruct the context surrounding the warning.
Moskovich describes the resulting operating condition through one of the strongest statements in the session.
“We’re drowning in noise, and yet we’re still starving for context.”
— Paul MoskovichHe reaches this conclusion after speaking with more than 200 CISOs and SOC managers about their investigative experience. When he asks how quickly an analyst can place a new alert into context, the answer may be one or two hours even when the analyst is experienced, focused, and working early in the day. The delay reflects the work required to understand what sits underneath the alert. Analysts must identify the asset, examine the identity, retrieve the relevant logs, assess permissions, compare activity across systems, and determine whether the event represents a benign action or an active threat.
This is why Moskovich argues that the underlying challenge is not simply an alert problem. The tools perform the task for which they were designed. They identify something worthy of attention and transfer responsibility for interpretation to the security team. The analyst must determine whether the alert is malicious or benign, understand what is occurring, and decide how quickly the organization needs to respond.
Understanding the problem is only part of the work. The SOC must also determine what action is appropriate and what operational consequences may follow. Containment, isolation, identity suspension, workload interruption, or network segmentation can stop malicious activity, but each decision can also affect customers, employees, revenue, or essential services. The organization therefore needs context not only to recognize the threat, but also to choose a response that protects the business while controlling the incident.
Defending An Environment That Will Not Hold Still
Traditional SOC operating models developed around infrastructure that changed comparatively slowly. Systems were persistent, networks were more visible, and experienced defenders could build an enduring mental model of the environment. Security teams still faced sophisticated adversaries, but they generally knew which servers, applications, accounts, connections, and boundaries they were expected to defend.
Moskovich contrasts that environment with the modern cloud. Workloads can be created and removed rapidly, containers and Kubernetes resources can change continuously, and services may exist only long enough to perform a particular function. Even people operating inside the company may be unable to describe precisely how the environment looked the previous day because its topology is continually being reshaped through deployment, scaling, automation, development, and business activity.
The difficulty is therefore not only that the environment has become larger. It has become fluid. Analysts are being asked to investigate activity inside an environment whose shape can change while the investigation is taking place. A workload may disappear, an entitlement may be modified, or a service relationship may be replaced before the analyst has finished gathering evidence.
Moskovich asks how an organization can defend something that is effectively shapeless and changing all the time. The question does not imply that the cloud is unknowable. It indicates that understanding can no longer depend primarily on a static diagram. It must be constructed dynamically from the relationships among identities, workloads, permissions, configurations, data, activities, and events.
Artificial intelligence increases the operating speed of this environment while also expanding the capabilities available to adversaries. Cloud systems already move faster than traditional manual security processes were designed to accommodate. AI can accelerate discovery, experimentation, adaptation, and attack execution, raising the possibility that automated agents may operate against infrastructure that is itself being created and modified through automation.
The imbalance is reinforced by a structural asymmetry between attackers and defenders. The adversary may need only one successful path, while the defender is expected to maintain continuous coverage without a meaningful lapse. At the same time, organizations face a chronic shortage of experienced analysts and continue to consume scarce senior talent through large volumes of repetitive, weakly contextualized investigations.
Cloud and AI therefore magnify a problem that already exists within the SOC. The environment changes faster, the adversary can operate faster, and the defender remains dependent on human investigation processes that do not expand at the same rate.
Human Investigation Has Reached Its Scaling Limit
The traditional SOC attempts to manage alert volume through a tiered operating model. Tier-one analysts perform initial triage and escalate selected cases to tier-two investigators, who reconstruct the activity and determine whether deeper analysis or response is necessary. Complex incidents may then move to senior analysts, incident responders, threat hunters, engineers, or leadership.
The structure creates an escalation path, but it does not resolve the capacity constraint. Moskovich estimates that a seasoned tier-two analyst may require approximately half an hour to investigate one alert when the relevant systems and evidence are readily accessible. Across a realistic working day, that produces a capacity of roughly 16 to 20 alerts. When the queue contains far more activity than one person can examine, the organization must leave alerts uninvestigated, reduce the depth of review, or hire more staff.
None of these choices provides a durable response to an environment whose complexity and event volume continue to expand. Analyst teams cannot grow without limit, experienced personnel are expensive and difficult to recruit, and additional headcount does not remove the delays created by fragmented evidence, missing permissions, tool switching, and manual correlation.
Moskovich therefore concludes that human-driven investigation cannot scale sufficiently within the modern cloud environment. This does not mean that people should be removed from security operations. It means that the organization must change which parts of the investigative process consume human time.
Analysts create the greatest value when they assess ambiguity, apply business judgment, determine the consequences of containment, and take responsibility for decisions that affect the organization. They create less value when most of their time is spent locating logs, requesting access, switching among consoles, assembling screenshots, or manually connecting evidence that machines can process more quickly and consistently.
The analyst shortage becomes more manageable when the SOC stops treating every investigation as a fresh manual reconstruction. The relevant evidence already exists across cloud systems, identity platforms, workload telemetry, configuration records, runtime activity, and security tools. The operational challenge is to connect that evidence into a coherent investigation before the analyst has spent hours assembling it.
From Alert-Centric To Investigation-Centric Operations
Moskovich proposes a transition from people-centric and alert-centric operations toward an investigation-centric SOC. In the traditional model, the queue is organized around individual warnings and the analyst is responsible for determining which alerts belong together, what they mean, and whether they represent a broader sequence. In the investigation-centric model, the operating unit becomes the contextualized security case rather than the isolated alert.
This difference matters because attacks rarely appear as one self-contained detection. They develop through relationships among identities, permissions, workloads, credentials, data, configuration changes, network behavior, and attempts to persist or move. Each individual action may appear incomplete when examined alone. The investigation becomes meaningful when those actions are connected into a coherent account.
“Let the machine do the heavy lifting of connecting the dots for us, the analysts, and let the analyst be the one to decide what actions are needed to be taken when something is going wrong.”
— Paul MoskovichThis division of responsibility preserves human command while applying machines where they can create the greatest leverage. An agentic system can process evidence, identify relationships, reconstruct sequences, compare behavior, and maintain consistency across a large number of investigations. The analyst can evaluate whether the resulting explanation is credible, determine the business significance, consider the consequences of containment, and authorize or guide the response.
The model is not equivalent to autonomous remediation without accountability. Moskovich emphasizes that security actions can have significant operational consequences. If suspicious activity appears within an online banking environment, isolating the affected segment may protect the institution while also disrupting customer access. Faster understanding provides the time required to coordinate communication, containment, continuity, and recovery rather than forcing the organization to choose between delayed action and unmanaged disruption.
An investigation-centric SOC can also alter the relationship between junior and senior analysts. In a traditional tiered model, less experienced personnel are expected to perform initial reasoning and communicate a partially developed story to more experienced investigators. When machines construct the initial context and evidence chain, analysts at different levels begin from a stronger and more consistent foundation.
Senior analysts can concentrate on cases that genuinely require their expertise, while developing analysts gain access to a clearer explanation of the activity. The SOC can reduce duplicated investigative effort and create a more useful learning environment because the team is working from structured investigations rather than repeatedly searching for disconnected evidence.
The Speed Of Understanding Defines The Outcome
Moskovich draws one of the central lessons of the presentation from his experience in national cybersecurity operations.
“The speed of understanding defines the outcomes.”
— Paul MoskovichA security organization may possess extensive technology, experienced personnel, response procedures, and executive support, yet still lose control of an incident when it cannot understand the developing situation quickly enough. An investigation that follows the wrong path may consume hours while malicious activity continues. A team that cannot determine whether an alert is genuine may ignore a real threat or interrupt operations in response to benign behavior.
Speed in this context does not mean acting before the evidence is understood. It means reducing the time required to reach an explanation reliable enough to support action. The faster the organization can determine what is occurring, the more options remain available for containment, communication, continuity, recovery, and escalation.
Moskovich connects this requirement to three constrained resources: capacity, speed, and skill. Security organizations do not have unlimited analyst time, investigative speed, or senior expertise. An operating model that consumes all three resources on repeated manual enrichment remains structurally disadvantaged as cloud complexity and automated threats increase.
The organization must therefore reduce the latency and friction embedded in investigation. Analysts may lose time because they lack permission to inspect a system, need another team to retrieve evidence, cannot access a server, or must move repeatedly among disconnected tools. Each delay weakens the organization’s ability to understand the activity while it is still unfolding.
Moskovich’s proposed operating model reorganizes the SOC around immediate understanding rather than continued data accumulation. The objective is not to collect every possible signal and leave interpretation until later. It is to connect the evidence surrounding suspicious behavior rapidly enough for the organization to determine whether the environment remains secure and what action must follow.
Measure Insight, Not Ticket Closure
An investigation-centric SOC also requires a different understanding of performance. Traditional metrics frequently emphasize alert volume, mean time to acknowledge, tickets closed, or queue reduction. These figures can show that workflow is moving, but they do not necessarily demonstrate that the organization understands its exposure or has identified threats developing inside the environment.
Moskovich recalls that, as a CISO, he asked his team at the end of each day to explain the insights they had developed rather than report only how many tickets they had closed. Ticket closure records the completion of a process. Insight demonstrates whether the security team has improved the organization’s understanding of its environment.
This distinction matters because a SOC can close large numbers of alerts while remaining uncertain about whether hidden threats persist. High throughput can coexist with weak control when analysts are incentivized to dispose of tickets rather than investigate relationships and anomalies that may indicate a deeper problem.
Moskovich therefore calls for metrics that evaluate analyst efficiency and the quality of understanding rather than closure volume alone. The relevant question is whether the team can explain what happened, determine why it matters, establish whether the environment remains exposed, and guide an effective response.
This shift can also improve the leadership conversation around the SOC. Executives and boards often struggle to interpret large quantities of operational security data because ticket counts and detection volume do not translate naturally into business understanding. An investigation-centered model can provide a more meaningful account of what the security organization knows, what remains uncertain, and where action is required.
The SOC becomes less of an alert-processing function and more of an intelligence and decision environment. Its value is expressed through the organization’s ability to understand risk while that risk can still be controlled.
Cybersecurity Becomes A Race For Understanding
Moskovich closes by reframing the competitive dynamic of cybersecurity. Organizations have long described cyber defense as a race involving tools, coverage, automation, talent, and technical capability. Those elements remain important, but technology alone does not establish whether the defender understands the environment or the attack developing within it.
“Cybersecurity is becoming a race for understanding.”
— Paul MoskovichThe phrase captures the central progression of the session. Defenders already receive large quantities of information. Their disadvantage emerges when the information arrives faster than they can connect, interpret, and convert into action. Cloud environments increase the number and fluidity of the relationships that must be understood, while artificial intelligence increases the speed at which both legitimate activity and malicious behavior can develop.
The organization that understands first retains more control over the outcome. It can distinguish malicious activity from benign change, direct scarce expertise toward the right cases, coordinate containment with business operations, and act before the incident has expanded beyond the available response options.
The role of agentic AI within this model is not to replace security leadership or remove human responsibility. It is to perform investigative work at the speed and scale of the environment, providing analysts with connected evidence and a clearer account of what may be occurring. Human judgment remains responsible for validating that account, evaluating the consequences, and determining the action the organization is prepared to take.
Moskovich ultimately leaves security leaders with a question more demanding than how many tools are deployed, how many alerts were closed, or whether established procedures were followed. The question is whether the organization truly understands what is happening across the environment under its responsibility.
That question defines the movement from cyber defense to cyber understanding. Defense reacts to what has been detected. Understanding connects the environment, the activity, the risk, and the consequences into a basis for informed control.
Explore The Dedicated Session
Access the Global Cloud Security Forum 2026 session featuring Paul Moskovich of Cyngular Security.
View The Session Page






