Preventing Silent Failures with Nir Loya Dahan

Preventing Silent Failures with Nir Loya Dahan

🎙 SANS Institute 👥 70K 📅 June 19, 2026 ⏱ 55 min 👁 211 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

telemetry healthsilent failureslog pipelineSOCdetection

Summary

In this episode of the Blueprint podcast, host John Hubbard interviews Nir Loya Dahan, co-founder and CPO of Fig Security, about the challenge of preventing silent failures in security operations. They discuss the complexity of modern SOC infrastructure, where logs from various sources flow through pipelines, undergo parsing, enrichment, and normalization before reaching detection rules. Silent failures occur when this pipeline breaks without triggering alerts, often due to configuration changes, schema drift, or misconfigurations. Nir emphasizes that attackers may exploit these gaps, and that AI-driven SOCs are only as reliable as the data foundation they rely on. The conversation covers common failure points, such as typos in references, changes in log schemas, and timestamp issues, and suggests practical steps like enforcing schema health and focusing on critical detections. The episode is sponsored by Fig Security, and includes references to SANS courses and resources.

143 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into a critical but often overlooked aspect of security operations: telemetry health. Nir’s arguments are well-structured and grounded in real-world experience, with concrete examples of how silent failures manifest and impact detection capabilities. The discussion is practical, offering actionable advice for SOC teams, such as starting with critical detections and enforcing schema health. The argumentation is solid, though it relies primarily on anecdotal evidence rather than formal studies or data.

84 words

Title / Content Match

The title accurately reflects the content, focusing on the problem of silent failures in security operations and how to prevent them.

Quality & Reliability

8/10

The discussion is grounded in practical experience from a security operations perspective, with concrete examples and references to industry practices. The claims are plausible and align with known challenges in SOC operations, but lack formal citations or empirical data.

Key Moments

Cited Sources

  • Blueprint Podcast — Podcast website for feedback, reviews, and guest pitches.
  • SANS LDR551 — Course on building and leading security operations centers.
  • SANS SEC450 — Course on SOC analyst training and applied skills.
  • Fig Security — Sponsor and company of the guest, focusing on security operations resilience.
  • John Hubbard LinkedIn — Host's LinkedIn profile for connection.

Concurring Sources

  • SANS SEC450 — Course content likely covers log pipeline and detection engineering.
  • SANS LDR551 — Course on SOC leadership, relevant to resilience.

Contribution & Novelties

The video provides a comprehensive overview of silent failures in security operations, a topic that is often under-discussed. It offers practical insights into the complexity of log pipelines and the importance of telemetry health. The discussion with an industry expert adds credibility and real-world perspective.

Pour aller plus loin :

114 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, with a moderate technical level. The overall reliability is high, reflecting the expert nature of the discussion. The profile suggests a well-rounded, informative episode with practical value.

Reliability 8/10

💬 No comments were provided for analysis.