
Cloud Security Podcast by Google EP263 SOC Refurbishing: Why New Tools Won't Fix Broken Processes (Even With AI)
14 snips
Feb 16, 2026 Daniel Lyman, VP of Threat Detection and Response at Fiserv, who designs SOC processes and federated detection strategies. He discusses translating board goals into daily operations. He covers federated versus centralized SOC tradeoffs. He warns that swapping tools without changing processes is not transformation. He explores AI’s role in correlating telemetry and the value of application logs and containment metrics.
AI Snips
Chapters
Books
Transcript
Episode notes
Align Tech With Process And People
- Do treat objectives as people, process, and technology problems, not just a tooling purchase.
- Do design and enforce processes so new tools actually change behavior and scale outcomes.
Tool Swap Isn't Transformation
- Replacing an old SIEM with a shiny new one isn't SOC transformation if processes stay the same.
- True modernization requires changing workflows to exploit faster searches and new capabilities.
Federation Versus Coordination
- A federated SOC can mean location-based sub-SOCs or tool-specialist teams that focus on different telemetry.
- The core challenge is coordinating those teams so cross-tool correlations aren't missed.



