I’ve always been drawn to investigative documentaries — the kind where detectives reconstruct an entire crime from fragments of evidence. The breakthrough never comes from a single clue. It comes from connecting everything: movements, relationships, timing, and intent. Miss one piece and the case stalls, or worse, you chase the wrong suspect.

Cybersecurity works the same way.

In one of my previous articles, I wrote that the Security Operations Center (SOC) struggles because of architecture, not headcount. We keep layering AI onto systems that were never designed to give it what it needs: complete, high-fidelity data. Without that foundation, even the most advanced model will fail to deliver on its promise.

What “complete data” actually means

For twenty-five years, “data” in security meant logs and events. But logs are a lossy representation of reality. Security products pre-filter and normalize telemetry before forwarding it, so the logs and alerts that reach the SIEM are roughly 10–20% of what the environment generated. A process-creation event arrives already stripped of its full context and its timing relationship to adjacent events.