How we built it: the Expel SOC-in-the-Sky
ID: 4cde493d-14b8-5099-a9d4-dbd3c573c9a9
STIX ID: report--4cde493d-14b8-5099-a9d4-dbd3c573c9a9
Feed Name: Expel Blog
**Executive summary:** Expel describes establishing a temporary "SOC-in-the-Sky" during a company kickoff in Miami to maintain 24×7 coverage for customers, outlining the physical setup, staffing, tooling, and operational workflow. The post highlights scale and performance metrics—processing approximately 2.5–3.5 billion events daily from 100+ integrations, automation by detection and orchestration bots (Josie™ and Ruxie™), handling roughly 10–15 security incidents per day (account takeover, ransomware-related access, cloud misconfigurations, and authorized red teams), and investigating about 1,000 suspicious emails daily—while emphasizing the integration of people and platform rather than reporting any single security incident.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
