Fig broadens its platform throughout the entire SecOps engineering lifecycle, establishing resilience as the standard.
Security operations environments are in a state of constant change. Regular introductions of new cloud services, data sources, automations, and detections occur, while upstream systems may change unexpectedly. While these updates aim to enhance security, they can inadvertently disrupt detection pipelines and create visibility gaps for organizations.
Fig contends that the issue lies not in generating more detections but in safely managing change. To tackle this challenge, the company has launched what it describes as the industry’s first comprehensive SecOps engineering lifecycle, providing a CI/CD-style workflow for Security Operations (SecOps) Engineers. This enables them to build, deploy, and continuously monitor changes across their environments.
Integrating Software Engineering Principles into the SOC
At its essence, Fig offers SecOps something it has historically lacked: a full engineering lifecycle for detections and configurations. Instead of having engineers manually create detections and configurations, the platform allows them to specify the desired outcome. Fig evaluates the live environment, suggests necessary modifications, and assesses their potential impact before they are implemented in production.
According to the company, every suggested update is simulated and tested prior to deployment. Once approved, changes can be implemented with version control and rollback options, while ongoing observability ensures that both new and existing detection workflows function as intended.
Instead of adding another standalone security tool, Fig employs practices common in software development, such as testing, validation, and controlled deployment, to enhance the everyday operations of security teams.
A Foundation Grounded in Security Data Lineage
Supporting this workflow is what Fig refers to as a deterministic graph of security data lineage. This platform maps every detection, data source, and connection across the SecOps infrastructure into one cohesive operational perspective.
This detailed comprehension of the environment allows Fig to assess proposed changes within context, helping to determine how updates could influence the wider detection pipeline. The company maintains that continuous verification guarantees these pipelines function properly, even as infrastructure evolves upstream or downstream.
The primary aim is to mitigate the risk of unnoticed failures that can arise as security environments grow increasingly complex.
Accelerating Routine Security Engineering Tasks
The enhanced platform aims to expedite multiple routine yet time-consuming security engineering tasks.
Fig asserts that security teams can rapidly transform threat reports into detections and queries at a pace much faster than conventional workflows permit, allowing organizations to react more swiftly to emerging threats. The platform is also designed to streamline SIEM migrations, enabling organizations to remain fully functional throughout the transition and reducing timelines from months to mere weeks.
Moreover, organizations can exercise greater control over the data plane, simplifying the management of data ingestion and storage costs without compromising live detections or disrupting existing workflows.
Customer Feedback
Jayme Hancock, the Head of Security Operations and Engineering at AppLovin, noted that the platform has greatly transformed his team’s approach to detection engineering. He remarked, “With Fig, we build and ship accurate detection changes in minutes rather than weeks, without the endless plumbing. My team operates with a confidence we've never had, and yes, we’ve even begun ‘vibe parsing.’”
This experience embodies Fig’s overarching objective of decreasing engineering overhead while providing teams with increased assurance that deployed changes will perform as expected.
Broadening the Vision for Security Operations Resilience
The recent announcement enhances Fig’s comprehensive focus on Security Operations Resilience. Since emerging from stealth mode, the company has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital, has been named a finalist in the RSAC Innovation Sandbox, and asserts that its platform has been embraced by numerous Fortune 500 companies.
Founded by former Google SecOps and Siemplify veterans, Fig designed the platform around the principle that every infrastructure modification should be fully contextualized, validated before deployment, and continuously monitored thereafter. The leadership team previously held significant roles in global security architecture for Google Cloud Security.
As Co-Founder and CEO Gal Shafir explained, “Security teams should not have to choose between acting quickly and maintaining confidence in their SecOps infrastructure. Fig provides SecOps Engineers with the same modern engineering workflow that software developers have relied on for years. They can design changes with complete context, validate those changes prior to deployment, and continuously ensure that their security operations remain robust as their environments evolve.”
By incorporating modern engineering workflows into the SOC, Fig aims to aid security teams in effectively managing increasingly dynamic environments while ensuring that essential detection and response capabilities remain intact amid all changes.
Otros artículos
Fig broadens its platform throughout the entire SecOps engineering lifecycle, establishing resilience as the standard.
Fig implements a CI/CD-style engineering lifecycle for security operations, enabling SecOps teams to design, simulate, deploy, and continuously monitor detection modifications, complete with full context and rollback options.
