Friday SIEM post: BlackHat edition
Back at BlackHat after a long pause. It was great catching up in person with peers, prospects and customers.
Full impressions post next week. Right now I am past 24 hours on the road thanks to canceled flights.
First time attending as a vendor, but also as an analyst and researcher of this space. Two different lenses on the same show floor.
First observation. The expo is frown a lot. Maybe even bigger than RSAC, and shorter, so you do not get enough time to walk it properly and see everyone.
Second observation. AI SOC dominated. 40 plus vendors positioning directly in the category. Add 13 SIEM vendors that now claim AI SOC capability and were loud about it. Add EDR vendors. Add NDR vendors, and there were enough of them claiming it that we added a dedicated AI SOC capability field for NDR on our tracker. Put it together and we are close to 60 companies advertising AI SOC in some shape or form. If you want the nuances, you know where to find them SecOps Unpacked.
Now the SIEM part, because this is the SIEM post.
SIEM did not have strong presence at least not as a headline. One of the most widely deployed technologies in security, and it was not heavily advertised. Some rip and replace messaging, as always.
My take. You can break SIEM apart. You can decouple storage, pipeline, detection, search. But what you end up with is still SIEM, just a different deployment model. SIEM is not a product category anymore, it is the core of the SOC.
AI SOC was the theme of this Black Hat. It will be even louder at the next RSAC. Because it is the thing driving the largest transformation of the SOC in the last decade.
And if you walked some of those booths and still cannot make sense of the messaging, the full evaluation framework is on SecOps Unpacked.
More next week.
Originally posted on LinkedIn on 7 August 2026.
Read the original post and the comments.


