Writing · Pillar
Economics & measurement.
The cost optimization paradox in security data, the storage-media economics under the bill, and the cloud-versus-on-prem case for security telemetry. Why vendor benchmarks are the only benchmarks, and what to do about it.
Depth tier for ch1 (Manageability) and ch3 (benchmarking honesty) · 8 essays
Listed from the front door down to the measured evidence. Start here marks the entry essay. The reading-level tag says whether you are about to read the frame (Orientation), the argument (Depth), or the narrowest first-party finding (Evidence). The durability tag flags whether a number is durable architecture or an Evidence-pinned result tied to a version or price and meant to be re-run.
- Start here OrientationDurable
The two cultures: evidence and marketing.
Data engineering built a culture of evidence — public benchmarks, open architectures, documented failures, quantified trade-offs — while security decides on vendor marketing, analyst reports, anecdote, and compliance checklists. The five principles of modern data architecture framed for a security reader, and what they become when you build them for security.
Read →
- DepthEvidence-pinned
Why modern data stacks haven't replaced SIEMs.
The technical case for the modern data stack is settled and the SIEM persists anyway, because the barrier was never technical. The four real barriers to leaving — risk aversion and 2am blame, a skills-timeline mismatch, the migration rebuild itself, status-quo bias — and why the team defending the SIEM is a rational actor managing operational risk, not a laggard, plus what actually moves it.
Read →
- DepthEvidence-pinned
The write endurance security data never spends.
Drive media is the majority of a security data platform's bill, which makes the NVMe endurance tier a first-order cost decision. The contrarian read: mixed-use and write-intensive drives are sold at a premium a write-once-read-rarely security lake almost never consumes, and the industry stopped publishing the data that would let you check.
Read →
- DepthDurable
How to run a benchmark that doesn't lie to you.
Rule zero, learned the hard way: verify the answer before you trust the clock, because one engine returned a filtered count tens of rows short over byte-identical Parquet and a timing-only run would have published it as a win. Then the rest of the method — report the CV, scale until the signal clears the noise, register identical bytes, isolate the run, control the power plan, hash logical rows not file bytes.
Read →
- DepthEvidence-pinned
The repatriation case for security data.
Cloud repatriation is well-covered macro ground. The narrower, stronger claim: security telemetry is the textbook workload to bring home — steady-state, write-heavy, retained for years, increasingly bound by sovereignty rules — exactly the profile cloud's variable pricing overcharges. The cheap, correctly-specced on-prem media is what closes the math.
Read →
- DepthDurable
The storage is moving, the engine isn't (yet).
The loud off-Splunk story says the open lakehouse is replacing the SIEM analytics engine at scale, now. The quieter, better-sourced read: storage and pipeline are moving fast and measurably while the engine stays put, and the gap between the two is where a buyer gets oversold.
Read →
- DepthEvidence-pinned
The cost optimization paradox in security data.
Cost optimization in security data often makes the overall security posture worse. The patterns where tighter budgets degrade detection coverage, and the patterns that release headroom.
Read →
- EvidenceEvidence-pinned
The index pays twice.
A hot search index stores 4.2× the bytes at 3.5× the price per byte, so it costs about 14.8× a warm Iceberg-on-S3 lakehouse for the same events. At thirty days the gap is a rounding error; at the seven-year retention horizon a regulated firm has to plan for, it is the difference between a line item and a project. A measured storage floor, Tier B and first-party single-host, explicitly not a TCO model.
Read →