Recent blog posts

SOC Metrics for Finance: From Security Operations to Risk Insight and Business Impact
Catherine Southwick 28/04/2026

SOC Metrics for Finance: From Security Operations to Risk Insight and Business Impact

SOC metrics like alerts triaged and threats detected only tell part of the story, especially in financial services where performance is measured in risk, exposure, and business impact. This article explores how to reframe key metrics such as MTTR, containment time, and risk reduction to better align with financial outcomes,...

Locked Shield 26 | Supporting NATO on a multinational exercise
SBT Content Engineers 01/05/2026

Locked Shield 26 | Supporting NATO on a multinational exercise

Locked Shields is as close as it gets to a real-world cyber war without it actually happening. This post breaks down what it’s like to support NATO’s largest live-fire exercise, the scenarios we built, and what training at that scale really looks like when pressure, complexity, and realism all come...

All posts

Building a SOC That Scales Without Burning People Out
Joshua Beaman 26/01/2026

Building a SOC That Scales Without Burning People Out

Burnout in SOCs is rarely about individual resilience and more often about how work is designed and sustained. This article explores how alert noise, context switching, and constant vigilance quietly erode performance over time, and what resilient SOCs do differently to protect judgement, focus, and long-term capability.

What I Wish I’d Known Before My First SOC Role
Joshua Beaman 16/01/2026

What I Wish I’d Known Before My First SOC Role

Starting your first SOC role can feel overwhelming, even with prior training and labs behind you. This blog breaks down the realities of day-to-day SOC work, from alerts that arrive with little context to investigations that rarely end with clean answers. It highlights why judgement, documentation, and communication matter as...

The Real Skill Gap in SOCs Isn’t Technical, It’s Judgement
Joshua Beaman 07/01/2026

The Real Skill Gap in SOCs Isn’t Technical, It’s Judgement

Many of the challenges that slow investigations and increase escalations in SOCs are not caused by missing tools or technical skills. They stem from uneven judgement under uncertainty. This article explores why judgement is harder to build than knowledge, how it affects escalation and closure, and what SOC managers can...

5 Ways Ransomware Training Boosts Your Career
Tati Laskivska 05/01/2026

5 Ways Ransomware Training Boosts Your Career

Ransomware training helps cybersecurity professionals move beyond technical response to become trusted contributors during high-pressure incidents. By understanding attacker behavior, business impact, negotiation dynamics, and the full incident lifecycle, practitioners gain credibility across technical, legal, and executive teams. This practical, real-world knowledge builds confidence, expands career options across multiple security...

Meet Alaina & Dora: SBT’s Creative Powerhouse Duo
Duncan Whitley 26/11/2025

Meet Alaina & Dora: SBT’s Creative Powerhouse Duo

Say hello to Alaina and Dora, the brilliant creative duo behind Security Blue Team’s distinctive look and feel. As our design team, they craft everything from course interfaces to BTLO illustrations, blending deep cybersecurity knowledge with serious artistic flair. Discover how they keep SBT’s cybersecurity training visually stunning yet brilliantly...

Meet David Elliott: SBT’s Principal Defensive Content Engineer Forging Cybersecurity Mastery
Duncan Whitley 29/10/2025

Meet David Elliott: SBT’s Principal Defensive Content Engineer Forging Cybersecurity Mastery

Step into the world of David Elliott, Security Blue Team’s Principal Defensive Content Engineer, whose creative flair and technical expertise shape cutting-edge cybersecurity training. From building realistic scenarios to mentoring talent, David’s work strengthens SBT’s technical team, helping clients master cyber defences. Dive into his story, from RAF roots to...