惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
有赞技术团队
有赞技术团队
Simon Willison's Weblog
Simon Willison's Weblog
人人都是产品经理
人人都是产品经理
L
LINUX DO - 最新话题
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
A
Arctic Wolf
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
小众软件
小众软件
Jina AI
Jina AI
The Cloudflare Blog
P
Palo Alto Networks Blog
AWS News Blog
AWS News Blog
阮一峰的网络日志
阮一峰的网络日志
C
Cybersecurity and Infrastructure Security Agency CISA
Know Your Adversary
Know Your Adversary
T
Threat Research - Cisco Blogs
L
Lohrmann on Cybersecurity
NISL@THU
NISL@THU
G
GRAHAM CLULEY
Project Zero
Project Zero
博客园_首页
博客园 - 三生石上(FineUI控件)
罗磊的独立博客
Spread Privacy
Spread Privacy
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
Latest news
Latest news
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Cisco Blogs
C
Cyber Attacks, Cyber Crime and Cyber Security
T
Tor Project blog
S
Securelist
V
Vulnerabilities – Threatpost
T
The Exploit Database - CXSecurity.com
C
CERT Recently Published Vulnerability Notes
IT之家
IT之家
Google DeepMind News
Google DeepMind News
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Last Watchdog
The Last Watchdog
T
Tenable Blog
宝玉的分享
宝玉的分享
S
Secure Thoughts
P
Privacy & Cybersecurity Law Blog
量子位
大猫的无限游戏
大猫的无限游戏
J
Java Code Geeks
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Security Archives - TechRepublic
Security Archives - TechRepublic

Insight Partners

How companies are building and scaling the FDE bench CEO Jan Inge Pedersen on building Kabal into an industry-defining logistics platform Client Challenge Demystifying the forward deployed engineer Client Challenge Behind the investment: Higharc and the AI-native future of homebuilding According to Root.io, your security backlog is a problem that only AI can fix Client Challenge Client Challenge Command Zero is betting big on AI-native defense compressing response time Client Challenge How AI is rebuilding America's primary care system How Skyflow ends the false choice of block or unblock for Agent data How Trustmi uses AI to make sure every dollar goes where it should How Tamnoon is tackling the cloud security backlog with autonomous remediation The next generation of analytics: Why we invested in Golden Analytics How Mate Security is building the AI teammates that security operations centers have been waiting for Brinqa is building the context layer that enterprise security is missing The SaaS GTM glossary that no one has written yet What top-performing CMOs say about success in 2026 Client Challenge How Healthie is building the critical infrastructure behind accessible, longitudinal care GovWell Raises $25M Series A Led by Insight Partners to Build the AI Operating System for Modern Government Devicie is building endpoint security for an AI-driven world Why Delinea focuses on privileged access to prevent breaches from humans and AI Agents Inside Semperis: Response and recovery after identity system attacks Cloudsmith Raises $72M Series C Led by TCV and Insight Partners to Control and Secure the AI-Powered Software Supply Chain Covera Health and Medmo Combine to Deliver the First Platform That Manages the Complete Radiology Journey: From Imaging Order to Accurate Diagnosis From software to hardware: Where Nest founder Tony Fadell thinks AI will go next The skills gap cybersecurity leaders are facing right now Client Challenge Stop selling to enterprises. Start building with them. Behind the Investment: Linx Why we invested in Rocketlane How agentic AI is rearchitecting enterprise workflows Linx Security Raises $50M Series B as Identity Becomes Security’s Biggest Failure Point ScaleOps Raises $130M Series C at Over $800M Valuation to Lead the Future of Autonomous Cloud and AI Infrastructure Resource Management Rocketlane Raises $60 Million Series C to Redefine Professional Services for the AI Era Supercharging financial advisors: How AI is reshaping wealth management How Pictor Labs is turning tissue into data to revolutionize diagnosis
How Devo built agentic Strike48 to kill the SOC alert
Insight Partners · 2026-05-12 · via Insight Partners

Security operations teams have faced the same trade-off for years. Either collect every log and blow your budget, or reduce the amount of data you store and hope your blind spots don’t get exploited.

The problem starts with security information and event management (SIEM). This is the central nervous system of most enterprise security. SIEM platforms ingest log data from across the business, from firewalls and endpoints to cloud services and applications, then use it to detect threats and trigger alerts.

As businesses have moved to the cloud, deployed dozens of SaaS tools, and now started to use AI, the volume of this data has exploded. And because most SIEM platforms charge by the amount of data ingested, so has the cost of storing it. As a result, the number of blind spots has increased, and each one is a potential vulnerability.

“Organizations are dealing with a challenge of ‘What data am I going to put in this thing?’ because [they] only have so much money in [their] budget to be able to allocate toward it,” says Jason Mical, Field CTO at Devo and Strike48. “It’s introduced a gap in their visibility…[they] get the bill at the end of the month and [they] have to rip it out.”

Devo was founded to solve this problem by handling data at scale and helping security operations centers (SOCs) operate more efficiently.

The economics of seeing everything

Devo was founded in Spain in 2011 and moved to the United States in 2018. Since then, the company has raised over $500M across six funding rounds, with Insight Partners leading its Series B and C, reaching a $2B valuation at its Series F in 2022.

From the start, Devo was designed to be different from legacy SIEM solutions. Where traditional platforms had organizations choose between data coverage and cost, Devo allowed its customers to retain far more data in a searchable, or “hot” state.

But now Devo is allowing businesses to bypass that trade-off.

“What we’re seeing is a paradigm shift,” explains Mical. By unifying a company’s logs and combining them with AI’s ability to search massive amounts of data, full log coverage becomes economically viable. “I only need the data hot in the SIEM for alerting for a week, and then I could take the rest of that data and put it into an S3 bucket or a storage bin, where I can keep that for seven years if I want to. And my Agent can still search it…just as effectively.”

“AI is really going to help to eliminate a lot of the blind spots.”

This is the idea behind Strike48, Devo’s new product brand launched in January 2026. Strike48 unifies log data across cloud, on-premise, SaaS, and data lake environments into a single operational layer that AI Agents can reason with, regardless of where the data lives.

“[It’s] built to be a horizontal engine across all aspects of an organization,” says Mical. Traditionally, OT security issues required IT to step in — creating friction and delays. AI Agents are now dissolving that boundary, enabling faster, more autonomous resolution.

Agents in security operations are only as useful as what they can see. If your Agents can’t access all of your log data, they can’t do useful work. Strike48 makes sure they can.

The first line of defense

The visibility problem, however, is only half the story. Even when security teams can see what’s happening, they often lack the capacity to respond.

Mical has spent more than 30 years in cybersecurity, so he has seen every sort of fatigue and every sort of promise to fix it. “Alert fatigue…analyst burnout…threat intelligence burnout, and now SOAR burnout,” he says.

SOAR — security orchestration, automation, and response — tools were supposed to solve this problem by coordinating separate security tools and automating repetitive tasks. Instead, they just created another management layer for security analysts to keep up to date. “Everything they have to deal with every day is never-ending.”

One of the big challenges organizations face is the volume of data generated by endpoint detection and response (EDR) software. This is software that monitors end-user devices, such as laptops and servers, for threats. Most organizations can only afford to send their alerts to their SIEM, not the full telemetry.

“If I have an EDR that fires or triggers an alert that something suspicious is occurring, I only have the data in the SIEM of what suspicious activity occurred, but it doesn’t give me the visibility into what happened before [or after],” says Mical.

“So now I’ve got to pivot back into the console of the EDR or the firewall or all those different technologies to figure out what happened.”

One solution to this volume problem was to outsource it, organizations hiring managed service providers to act as their first line of defense. “But then they pass the buck back to the organization,” says Mical. “They say, ‘Well, we validated that this is bad. Now you guys have got to go and clean it up.’ And then the organization is like, ‘Well, how do we clean it up? How do I know what my blast radius is, or where’s my patient zero?’”

Moving at agentic speed

This is made worse by attackers using AI to quickly adapt their techniques, making the static, rule-based detection models that most SIEM solutions use ineffective.

“We’re dealing with agentic adversaries, and they have come up with the ability to know and quickly be able to identify what the rule is there and change their approach on the fly,” says Mical.

“You’ve got to use AI to be just as dynamic as the adversaries are.”

Strike48’s answer is Prospector Studio, a no-code platform for building and deploying AI Agents across security and IT operations. Rather than replacing analysts, these Agents handle the tasks that burn teams out, such as triaging alerts, detecting threats, collecting forensics, and compiling reports, all at machine speed.

“You can put these instructional prompts into the Agents you build, to say, ‘These are the steps I need you to follow if you see something bump in the night,’ and it does it at machine speed, not human speed,” says Mical.

The goal is what Devo calls “alertless SOC,” where Agents handle triage and investigation autonomously, escalating to humans only when human judgment is required.

Making a “single pane of glass” a reality

Agents can compress investigations from hours to minutes, but they lack the kind of contextual reasoning that humans take for granted.

“[AI] doesn’t take into consideration what’s the impact to the business, like a human would,” says Mical. “If I shut off my CEO’s user account, that might have a little bit of an impact.”

This is why Devo’s approach with Strike48 is augmentation, not replacement. Analysts can build Agents with deterministic guardrails to constrain what the Agent can do and get a full audit trail of every action, so the Agent can respond at the same speed the threats operate, while keeping the human in the loop for high-impact decisions.

“[AI] gives you the ability to quickly uncover anomalies and…investigate them at speeds that no human, or even team of humans, could ever even dream of accomplishing.”

The result, Mical believes, is what the industry has promised forever. “I always laugh. Being in the industry since its birth, we’ve always heard the promise of a single pane of glass…and no one has ever been able to truly deliver it,” he says. “Now, with the agentic ecosystem that we have, I truly think there’s a light at the end of the tunnel.”


*Note: Insight Partners has invested in Devo.