
A Note from Chris
Hi everyone, The way we interact with software is changing. Over the past several months we’ve watched a growing number of security professionals spend less…
Read the storyWriting
Detection engineering, agentic security operations, and the architecture underneath. Written by the people building it.
Premiere
Company direction and the architecture shaping The Unbounded SIEM.

Hi everyone, The way we interact with software is changing. Over the past several months we’ve watched a growing number of security professionals spend less…
Read the story
The exhibit floor at Black Hat this August had one theme, and it was not subtle. Roughly 235 of the 450 or so vendors on the floor marketed AI or agentic…
Read the storyThe archive
51 articles
Visit the official Fluency blog"Headless" is a programming term, and it's older than the AI conversation now borrowing it. It describes a simple situation: a program wants to work with an…

Loading the Elevenlabs Text to Speech AudioNative Player... “AI is compressing the cyber kill chain” is a warning that now appears throughout the security…

Articles comparing Kimi K3 with Claude Fable 5 often describe the result as Kimi competing with Claude. That comparison sounds reasonable because each name…

Loading the Elevenlabs Text to Speech AudioNative Player... Swarm AI is becoming a prominent term in AI marketing, often presented as a meaningful advance…

If you use Claude CoWork, Codex, or another agentic coding environment, you’ve probably noticed that you spend less time inside the applications that…

Whether Gartner calls it an endorsement or not, executive teams use the Magic Quadrant to plan technology roadmaps, build procurement shortlists, and make…

The current AI discussion is heavily focused on execution. Can AI investigate alerts? Can it write code? Can it summarize documents? Can it perform the work…

Efficiency used to be measured through labor. Organizations invested in software, automation, and process improvements to reduce the amount of human effort…

Last year we proposed that AI would not eliminate the role of the security analyst. Instead, it would redefine it. As AI became capable of performing…

Fluency is releasing a major architectural change designed specifically for AI-assisted operations. The architecture is intended to work with emerging…

I just got back from two weeks in South Africa. It was one of the more intense business trips I’ve had in a long time. ... But by the end of the trip, it…

Most people still think of a SIEM as a giant database. You see it in how they talk about platforms like Splunk, Sumo Logic, or Elastic. The conversation is…

A better experience must mean a smarter model. A more helpful response must mean the model is learning. This assumption is natural, but it is also incomplete.

Daniel Miessler wrote one that genuinely stood out, "Cybersecurity Changes I Expect in 2026: My thoughts on what's coming for Cybersecurity in 2026". I read…

Ingext Community Edition is now available as a self-hosted, Kubernetes-based deployment, distributed using Helm charts. This release makes Ingext platform…

The way we move data is broken. Every SIEM on the market is choking on its own telemetry, and vendors are finally admitting it.

Ingext is a data fabric designed to treat all telemetry—regardless of origin, format, or transport—within a single architectural flow.

The small businesses that employ nearly half of America’s workforce are barely represented in business research.

Implementing a streaming data fabric gives organizations a new foundation of control. SIEMs become sticky not because of the technology itself, but because…

Because there is no Agentic AI framework, there is no way to enforce security.

If both rudeness and politeness can make the AI more accurate, what is actually changing inside the conversation?

In recent years, data fabrics such as Ingext, Cribl, and CrowdStrike’s Onum have become increasingly popular, not only because they simplify data…

You can detect configuration changes in real time through audit events, rather than relying on annual or periodic reviews to find MFA issues.

MTTD and MTTR measure speed. They do not measure the effectiveness of the overall operation.

Curious what happens in your brain when you let ChatGPT, or any AI, do the heavy lifting? The team at MIT’s Media Lab recently tackled this exact question…

The technology for SIEM continues at a rapid pace. It's an easy statement to make, but what are the basic features that define today's Next-Gen?

The Global AI SOC roadmap defines that progression as five distinct phases, Atomic, Role-based, Process-based, Action-oriented, and Self-learning, and…

Recent research published in Proceedings of the National Academy of Sciences and covered by Futurism has revealed a surprising phenomenon: large language…

Small and mid-sized businesses (SMBs) face many of the same security pressures as global corporations, so how to get the same SIEM capabilities?

When professionals depend too heavily on AI systems, the fundamental acts of analysis, interpreting, judging, and deciding, can deteriorate.

A new study shows the more you know about AI the less you trust it—what that really means for hype, adoption, and the coming AI bubble.

This article addresses a rising skepticism about whether vendors are sufficiently transparent, accountable, and secure.

The real value of a SIEM isn’t in storing data, it’s in the process of transforming, interpreting, and routing that data into something usable for security…

It’s easy to mistake a Security Information Event Management (SIEM) for a data lake. Both ingest large volumes of telemetry, offer search capabilities, and…

95% of AI pilots fail to deliver measurable business impact. Only 5% of enterprise AI projects reach operational deployment, and even fewer show sustainable…

AI-assisted attacks are not yet being uniquely defended by AI-aware systems. Most defensive tools using AI are blind to whether the adversary used AI at…

What are the characteristics of a SIEM that make it a good match for AI workflows and AI in general?

ChatGPT-5 modifications, while not overhauling the core architecture, alter the way the system communicates, guides decision-making, and handles potentially…

IdentitySIEM isn’t a new technology—it’s a long-overdue shift in perspective, recognizing that identity, not machines, is the foundation of meaningful…

Docker issued a strongly worded security advisory urging developers to stop using the Model Context Protocol (MCP), citing widespread vulnerabilities that…

The Reality of AI Vulnerabilities: What the Data Actually Says There is no shortage of bold claims when it comes to the risks of adopting AI. Industry…

Prompt injection is a relatively new term in cybersecurity, and one that many people are still unaware even exists.

if we’re going to move beyond toy examples and build real, automated Gen-AI workflows — especially in high-stakes domains like SOAR or SIEM — we need more…

You feel the ground shifting—and you should. AI isn’t nibbling around the edges of the Security Operations Center (SOC); it’s coming straight for the jobs,…

You have two logins. One from Spain. One from Switzerland. Eight minutes apart. The system fires an alert: “Impossible travel.” But here’s the problem—it’s…

In cybersecurity, operational models are more than academic—they define how teams respond to threats, allocate resources, and maintain continuity. At the…

The rise of generative AI has reignited excitement across cybersecurity, with many looking to these tools as accelerants for investigation. The most…

By Chris Jordan: I often write on more advanced topics, but I find there is a lack of good material on that gap between buying products and starting…

By Chris Jordan The Early Days: A Culture of Curiosity For many in my generation, movies like WarGames might have been the spark that ignited an interest in…

Security operations have always faced the fundamental challenge of scale. Years ago, when I started working in cybersecurity, we knew the volume of data…

Phase 3 marks a major advancement in how AI supports security operations—not by simply analyzing alerts, but by understanding process.

The Unbounded SIEM
Thirty minutes, live product, your question on screen. You leave with the written finding whether or not you buy anything.