Skip to main content

SOC Unlocked · security-operations-center-soc

Testing, Learning, Evolving: How Practice and Precision Strengthen the SOC with Marty McDonald

Marty McDonald of Optiv talks with host Mick Leach about modernizing the SOC through automation, metrics, and continuous learning—and how small, practical improvements and tabletop testing drive long-term resilience.

All EpisodesOct 9, 2025

In this episode of SOC Unlocked, host Mick Leach talks with Marty McDonald, Principal Domain Advisor at Optiv, about what it takes to modernize today’s SOCs for an AI-driven world.

Marty shares how forward-looking teams are automating repetitive, level-one work with SOAR and agentic frameworks freeing analysts to focus on higher-value investigations. He also explains how UEBA and entity analytics help analysts tell better data stories, transforming telemetry into actionable insight for executives and boards alike.

The conversation underscores a timeless truth—modernization starts with fundamentals. From refining metrics to running effective tabletop exercises, small, consistent improvements drive lasting transformation.

Insights

  • Modernizing the SOC starts with a holistic view of people, processes, and tools—not just new technology.

  • Context-rich analytics turn raw telemetry into stories that make threats and risks easier to understand.

  • Metrics must align with the audience, from analyst efficiency to executive-level risk reduction.

  • Small, consistent improvements build maturity faster than tackling massive, all-at-once transformations.

Interested in being on the podcast?

Contact us at SOCUnlockedPodcast@abnormalsecurity.com

See Abnormal in Action

See how behavioral AI detects the attacks that legacy defenses miss.