Close Menu
geekfence.comgeekfence.com
    What's Hot

    The Best Backpacking Sleeping Pads, Tested on the Trail (2026)

    July 26, 2026

    AT&T bets its fiber and 600 MHz on agentic AI traffic

    July 26, 2026

    Stranded in the Slow Zone – O’Reilly

    July 26, 2026
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook Instagram
    geekfence.comgeekfence.com
    • Home
    • UK Tech News
    • AI
    • Big Data
    • Cyber Security
      • Cloud Computing
      • iOS Development
    • IoT
    • Mobile
    • Software
      • Software Development
      • Software Engineering
    • Technology
      • Green Technology
      • Nanotechnology
    • Telecom
    geekfence.comgeekfence.com
    Home»Cyber Security»Findings Report from the SOC at RSAC 2026 Conference
    Cyber Security

    Findings Report from the SOC at RSAC 2026 Conference

    AdminBy AdminJuly 1, 2026No Comments4 Mins Read10 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Findings Report from the SOC at RSAC 2026 Conference
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Cisco Security and Splunk Security released the Findings Report from the Security Operations Center at RSAC 2026 Conference.

    This year marked the 10th year of the SOC at RSAC. Since 2017, the mission has stayed consistent: protect the conference network, educate attendees about what happens on an open wireless network, and innovate with new integrations, workflows, and security operations practices.

    The 2026 SOC was also an important step toward something bigger. We were not yet operating a fully agentic SOC at RSAC 2026, but the foundation was taking shape: integrated telemetry, automated escalation, full packet evidence, AI-protected workflows, and a closed-loop operating model between Cisco XDR and Splunk Enterprise Security. Those lessons helped inform the Agentic SOC work that followed at Cisco Live Americas 2026.

    RSAC is a uniquely valuable environment for learning. The Moscone Center wireless network is open and unsecured, similar to the networks people use every day in hotels, airports, coffee shops, and major events. The SOC does not decrypt encrypted traffic. Instead, the team uses network telemetry, DNS visibility, packet capture, threat intelligence, and integrated security tools to identify risk, investigate suspicious activity, and help attendees better protect themselves.

    For RSAC 2026, the team deployed the SOC in a Box architecture, connecting Endace full packet capture, Splunk Enterprise Security, Cisco XDR, Cisco Secure Firewall, Cisco Secure Access, Cisco AI Defense, ThousandEyes, Splunk Attack Analyzer, Cisco Secure Malware Analytics, Cisco Talos intelligence, and partner (alphaMountain, Pulsedive and StealthMole) and community threat intelligence sources.

    The full report includes the details, but a few themes stood out.

    First, integration changed how the SOC worked. Cisco XDR supported efficient triage and correlation, while Splunk Enterprise Security supported deeper investigation, hunting, enrichment, and reporting. Splunk SOAR helped connect the workflow so that context could move between systems instead of forcing analysts to manually re-enter evidence or switch consoles to understand what happened.

    Second, automation reduced toil. Cleartext credentials continued to appear on the network, but the team advanced the response model from standalone scripting to an integrated Splunk SOAR workflow. Detections became formal findings in Splunk Enterprise Security, and the playbook could notify affected users, update the finding, and close the case. That saved more than nine hours of analyst time during the event and created a repeatable model for future conferences.

    Third, encrypted traffic remained both a success and a challenge. Encryption helps protect attendee privacy, and the SOC does not decrypt attendee traffic. But defenders still need ways to identify threats. Cisco Secure Firewall’s Encrypted Visibility Engine helped the team find meaningful signals in encrypted sessions without decryption, including activity that supported a malware investigation and response.

    Fourth, AI became part of the security story in two ways. The SOC used Cisco AI Defense to gain visibility into generative AI application usage and to help protect on-premises AI models running in the SOC in a Box. At the same time, the team observed that AI demonstrations and agentic applications can introduce risk when they are built or operated without basic secure communication controls.

    Finally, the human mission of the SOC remained the same. The report includes examples of accidental data exposure, insecure email, unsecured web applications, misconfigured access paths, exposed storage, phishing infrastructure, scam domains, and malware investigations. In each case, the goal was not only to detect the issue, but to help RSAC and affected attendees understand and reduce the risk.

    That is why the full Findings Report matters. It is not just a list of alerts. It is a field report from a live, high-pressure SOC operating in a real conference environment, where technology, process, automation, AI, and human judgment all have to work together.

    Download the full RSAC 2026 SOC Findings Report to see the architecture, metrics, investigations, lessons learned, and recommendations from the 10th year of the SOC.

    The core advice remains simple: encrypt, encrypt, never trust, and always verify.

    Our thanks to the engineers, analysts and partners who made the SOC possible.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

    July 26, 2026

    LG to Ban Residential Proxies from Smart TV Apps – Krebs on Security

    July 25, 2026

    Cyber readiness for SMBs: Getting the basics right

    July 24, 2026

    US Mobile Speeds Jump 74% as Verizon and T-Mobile Split RootMetrics Honors

    July 23, 2026

    How Cisco architected AI-driven support and validated against industry benchmarks

    July 22, 2026

    Ukraine warns fake CAPTCHAs are being used to make you hack yourself

    July 21, 2026
    Top Posts

    Understanding U-Net Architecture in Deep Learning

    November 25, 202566 Views

    Hard-braking events as indicators of road segment crash risk

    January 14, 202633 Views

    Redefining AI efficiency with extreme compression

    March 25, 202631 Views
    Don't Miss

    The Best Backpacking Sleeping Pads, Tested on the Trail (2026)

    July 26, 2026

    I’ve had very few problems with any inflatable sleeping pad I’ve tested. Some have lost…

    AT&T bets its fiber and 600 MHz on agentic AI traffic

    July 26, 2026

    Stranded in the Slow Zone – O’Reilly

    July 26, 2026

    Data Science Case Study: The SCOPE Framework Guide

    July 26, 2026
    Stay In Touch
    • Facebook
    • Instagram
    About Us

    At GeekFence, we are a team of tech-enthusiasts, industry watchers and content creators who believe that technology isn’t just about gadgets—it’s about how innovation transforms our lives, work and society. We’ve come together to build a place where readers, thinkers and industry insiders can converge to explore what’s next in tech.

    Our Picks

    The Best Backpacking Sleeping Pads, Tested on the Trail (2026)

    July 26, 2026

    AT&T bets its fiber and 600 MHz on agentic AI traffic

    July 26, 2026

    Subscribe to Updates

    Please enable JavaScript in your browser to complete this form.
    Loading
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 Geekfence.All Rigt Reserved.

    Type above and press Enter to search. Press Esc to cancel.