Ask Lonic

What would you like to know?

Answers are drawn from Lonic's published reporting on lonic.bond, with every source listed.

No account needed — answers are generated from our article library.

Answer

web security

Security operations centres are built around a triage funnel: alerts arrive, humans assess them, a subset becomes incidents. The funnel assumes attacker activity unfolds slowly enough for that assessment to matter. Once an intrusion can move from initial access to exfiltration inside a working day — the tempo implied by the Anthropic disclosure — the funnel becomes a bottleneck rather than a filter.

  • Identity hygiene: short-lived credentials, phishing-resistant MFA, and elimination of long-lived service account keys. Most automated intrusion depends on credentials that should not have existed.
  • Egress visibility: exfiltration is the one step an attacker cannot skip, and it is the least well instrumented in most environments.
  • Asset truth: automated attackers enumerate faster than defenders inventory. An accurate, current asset list is a security control.
  • Detection as code: version-controlled, tested detections with measured false-positive rates, rather than a growing pile of untested rules.

People also asked

Browse the whole library

New here? Start with today's trending stories or read how Lonic reports.