Logo
Search
RSS
Home
Blog-Posts
Upgrade
Login
Sign Up
Oliver Buchannon
Filip Stojkovski

I’ve been doing cybersecurity for 15+ years. I started in the SOC on 12 hour night shifts, then bounced through threat intel, forensics, hunting, security engineering, and leadership roles (all the way up to VP). These days I’m on the product side. I write about SecOps the way it really works.

The Fear of Not Doing Enough

Feb 13, 2026

•

10 min read

The Fear of Not Doing Enough

Why Security Teams Keep Generating Work They Can't Handle

Filip Stojkovski
Filip Stojkovski

Automation Framework

+1

The SOC Autonomy Trap

Jan 19, 2026

•

11 min read

The SOC Autonomy Trap

Why 'Fully Autonomous SOC' is a Design Mistake

Filip Stojkovski
Filip Stojkovski
Understanding Semantic Layers in Security Operations

Dec 9, 2025

•

11 min read

Understanding Semantic Layers in Security Operations

Filip Stojkovski
Filip Stojkovski

Automation Framework

Can AI Drive Response?

Nov 11, 2025

•

18 min read

Can AI Drive Response?

Why the Right Side Still Needs Forensics and Automation

Filip Stojkovski
Filip Stojkovski
SOC Reality Check

Nov 4, 2025

•

12 min read

SOC Reality Check

Why Detection Is Only Half the Battle

Filip Stojkovski
Filip Stojkovski

AI SOC

From PDF Playbooks to Machine-Executable Logic

Oct 22, 2025

•

16 min read

From PDF Playbooks to Machine-Executable Logic

Filip Stojkovski
Filip Stojkovski
How AI Transforms Detection Engineering

Oct 14, 2025

•

14 min read

How AI Transforms Detection Engineering

From Narrow Precision to Broad Coverage

Filip Stojkovski
Filip Stojkovski
Rebranding Announcement

Oct 10, 2025

•

2 min read

Rebranding Announcement

CyberSec Automation is now SecOps Unpacked

Filip Stojkovski
Filip Stojkovski

AI SOC

AI SOC Core Component

Oct 2, 2025

•

13 min read

AI SOC Core Component

Filip Stojkovski
Filip Stojkovski

AI SOC

AI SOCs You Can Actually Control and Customize

Sep 16, 2025

•

12 min read

AI SOCs You Can Actually Control and Customize

Filip Stojkovski
Filip Stojkovski

AI SOC

AI SOC Shift Left and Shift Right!

Sep 11, 2025

•

11 min read

AI SOC Shift Left and Shift Right!

Introducing the AI SOC Shift Map

Filip Stojkovski
Filip Stojkovski

AI SOC

Is Your AI SOC Optimistic or Pessimistic?

Aug 21, 2025

•

14 min read

Is Your AI SOC Optimistic or Pessimistic?

Memory, Bias, and Drift in Real SOCs

Filip Stojkovski
Filip Stojkovski

Podcast

The Monthly Debrief: CyberSec Automation Podcast Roundup

Aug 13, 2025

•

6 min read

The Monthly Debrief: CyberSec Automation Podcast Roundup

Jul-Aug / 25

Filip Stojkovski
Filip Stojkovski

Automation Tech Stack

+1

Why SOC Analysts Ignore Your Playbooks

Jul 31, 2025

•

10 min read

Why SOC Analysts Ignore Your Playbooks

Are Your SOC Playbooks Broken?

Filip Stojkovski
Filip Stojkovski

Automation Tech Stack

Stop Chasing the Single Pane of Glass

Jul 22, 2025

•

14 min read

Stop Chasing the Single Pane of Glass

Start Building It

Filip Stojkovski
Filip Stojkovski

Automation Framework

Automate Smarter, Not Louder: Using Interactive AI Feedback Loops

Jun 25, 2025

•

10 min read

Automate Smarter, Not Louder: Using Interactive AI Feedback Loops

DSAEM Loop (Detect > SOP > Automate > Emulate > Measure

Filip Stojkovski
Filip Stojkovski
Will MCP, A2A and AG-UI help us the Single pane of glass for SecOps

Jun 17, 2025

•

13 min read

Will MCP, A2A and AG-UI help us the Single pane of glass for SecOps

Filip Stojkovski
Filip Stojkovski
Measuring ROI of AI agents in security operations

May 29, 2025

•

4 min read

Measuring ROI of AI agents in security operations

Introducing PICERL Index

Filip Stojkovski
Filip Stojkovski

Automation Framework

+1

Integrating AI Agents into Existing SOC Workflows: Best Practices

May 20, 2025

•

14 min read

Integrating AI Agents into Existing SOC Workflows: Best Practices

Filip Stojkovski
Filip Stojkovski

Automation Playbooks

AI Agents vs. Automation Playbooks

May 7, 2025

•

12 min read

AI Agents vs. Automation Playbooks

What’s the Actual Difference?

Filip Stojkovski
Filip Stojkovski

Automation Tech Stack

Evaluating AI agents for SOC

Apr 28, 2025

•

9 min read

Evaluating AI agents for SOC

Technical considerations for Security Operations teams

Filip Stojkovski
Filip Stojkovski

Automation Framework

How I’d Use AI Agents in a Security Automation Platform

Apr 23, 2025

•

8 min read

How I’d Use AI Agents in a Security Automation Platform

Filip Stojkovski
Filip Stojkovski
Why SOCs are Turning to AI Agents

Apr 3, 2025

•

12 min read

Why SOCs are Turning to AI Agents

Addressing Critical Investigation and Triage Bottlenecks

Filip Stojkovski
Filip Stojkovski

Automation Framework

+1

What an Autonomous SOC Looks Like

Mar 25, 2025

•

10 min read

What an Autonomous SOC Looks Like

And What Your Team Will Actually Do

Filip Stojkovski
Filip Stojkovski

Automation Playbooks

EDR Alert Automation

Mar 20, 2025

•

11 min read

EDR Alert Automation

A Practical Guide to Automated Alert Triage

Filip Stojkovski
Filip Stojkovski
Load more

Cyber Security Automation and Orchestration

Welcome to the one and only Cyber Security Automation dedicated blog. This space is dedicated to practical insights on security automation, detection engineering, and the move toward AI-driven, autonomous SOCs. I cover the frameworks, playbooks, and tools that help security teams automate with purpose, whether you’re building workflows, scaling your detection program, or exploring how AI fits into your operations. If you’re focused on making your security program faster, smarter, and more effective, you’ll find value here.

© 2026 Filip Stojkovski.
Report abusePrivacy policyTerms of use
beehiivPowered by beehiiv