I joined Terravek in February to build a security operations function that did not exist. The company had good engineers, decent hygiene and no detection capability worth the name. Seven months later we have four people in Tallinn, coverage across the European working day, and a plan for 24/7.

The first thing that worked: starting with logging rather than tooling. We spent the first ten weeks making sure that the things we would want to investigate were actually being recorded, and recorded somewhere we could query. Buying a SIEM before you have logs worth putting in it is a well-documented way to spend a budget and achieve nothing.

The second thing that worked: writing the incident response process before we had incidents, and then running it as a tabletop with the executive team. The value was not the document. It was discovering that three people believed they had the authority to take a production system offline and one of them was wrong.

What I would do differently: I under-invested in the relationship with IT operations for the first quarter. Security operations and IT operations have overlapping remits and genuinely different incentives, and pretending otherwise wastes a lot of goodwill. Tomasz and I now have a standing weekly slot and a short written list of who decides what.

We are hiring. If detection engineering in a company where the security team is small enough that you will be personally accountable for things appeals to you, the vacancies are on the careers page.