From Cyber Defense To Cyber Understanding
As part of Global Cloud Security Forum 2026, presented by Cyngular, Paul Moskovich, Co-Founder and CEO of Cyngular Security, examines why modern security operations centers remain overwhelmed despite the continued expansion of cybersecurity tools, telemetry, and alerting capabilities. Drawing on leadership experience across national cyber operations, military command, aerospace and defense, financial services, and more than two decades as a CISO, Moskovich presents the SOC as a critical command environment whose effectiveness depends on transforming security signals into timely and reliable understanding.
The session explains that traditional SOCs were designed for comparatively static computing environments, while modern cloud systems are dynamic, ephemeral, and continuously reshaped through automation. Artificial intelligence further increases the operating speed of both the environment and the adversary. Analysts are consequently asked to investigate expanding volumes of disconnected alerts while facing limited time, incomplete access, fragmented tools, and a shortage of senior expertise. Moskovich describes the resulting condition as one in which security teams are drowning in noise while starving for context, and he argues that human-driven investigation cannot scale sufficiently as cloud complexity and automated activity continue to increase.
Moskovich proposes moving from alert-centric and people-dependent operations toward an investigation-centric SOC. In this model, agentic systems perform the heavy work of connecting identities, workloads, assets, permissions, activities, and evidence into a coherent investigation, while analysts retain responsibility for validating the findings, considering operational consequences, and determining the response. The objective is not autonomous action without accountability, but a faster path to understanding that allows human judgment to operate while the organization still has meaningful control over the outcome. He further calls for SOC performance to be measured through insight, analyst efficiency, and control rather than ticket closure volume alone.
Session Intelligence
This session reframes the central challenge of security operations as a deficit of contextual understanding rather than a shortage of alerts. Its core insight is that the speed at which an organization can understand suspicious activity increasingly determines the effectiveness of its response. A modern SOC therefore requires connected investigations, machine-supported context, human command, and performance metrics that measure insight and control rather than workflow volume alone.
Context Before Closure
Security tools produce alerts, but the SOC must determine whether activity is malicious, what it affects, how events connect, and what response is appropriate.
Dynamic Cloud Understanding
Ephemeral workloads, identities, permissions, containers, and cloud services require understanding to be constructed dynamically rather than inherited from static infrastructure maps.
Investigation-Centric SOC
Agentic systems can connect evidence and construct investigations, allowing analysts to focus on validation, judgment, remediation, and operational consequences.
Human Command And Insight Metrics
SOC effectiveness depends on whether the organization understands and controls the situation, not simply on how many alerts or tickets it closes.