Latest News

Fig Bets on Resilience by Default When Every Change Can Break Detection

Ask anyone who runs a security operations center what keeps them up at night, and a surprising amount of it comes down to plumbing. Data sources shift. A cloud service updates. An upstream system changes a field, and somewhere downstream a detection stops firing without anyone noticing. The threat coverage a team believes it has and the coverage it actually has can quietly drift apart.

Fig is building for exactly that drift. Today the company announced the full SecOps engineering lifecycle, a workflow that lets Security Operations engineers build, ship, and observe every change with confidence, and which it calls the first true CI/CD for security operations.

Why the SOC Keeps Breaking Quietly

The core difficulty is constant motion. New data sources, detections, automations, and cloud services arrive daily. Upstream systems change without warning. Even minor updates can silently break detection pipelines, leaving gaps that stop teams from detecting and responding to threats. None of this is dramatic in the moment. That is the danger. A broken pipeline does not announce itself, and a coverage gap can sit open until an incident exposes it.

The Fix Is a Map of Everything

Fig’s answer starts with what it calls security data lineage. The platform maintains a deterministic graph of every detection flow across the entire SecOps stack, a ground-truth map of how data moves and where detections depend on it. The company says the lineage is why Fig knows the infrastructure down to the inch. Every detection and data source is mapped into a single flow, and the graph keeps all parts of the pipeline running as intended through any change, upstream or downstream.

On top of that map sits the workflow. An engineer describes a change. Fig reads the live environment and proposes it. The proposal is simulated and tested to prove its impact before production. Deployment happens in a click, with version control and rollback if something needs to come back. Continuous observability then verifies that every detection flow, old and new, still works.

Speed Without the Usual Trade-Off

The point of all this structure is speed that does not cost you confidence. Threat reports turn into detections and queries that protect the environment today, not next quarter. SIEM migrations that used to take months finish in weeks and stay operational the whole way through. Teams gain full control over the data plane, which lets them dictate ingest and storage spend without disturbing live detections.

For practitioners, the change shows up as fewer hours lost to setup. Jayme Hancock, Head of Security Operations and Engineering at AppLovin, put it plainly. “With Fig, we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing,” he said. “My team builds with a confidence we’ve never had, and yeah, we’ve even started ‘vibe parsing.'”

A Category Fig Wants to Own

Fig calls its focus Security Operations Resilience, the idea that detection and response should keep working through constant change instead of breaking under it. The company’s founders come out of Google SecOps and Siemplify, where they modernized some of the world’s largest and most complex SOCs and saw what silently breaks inside them. They pitch the platform as their answer, a SOC where every change is designed with context, proven before production, and continuously verified after. Agile by design, resilient by default.

Gal Shafir, Co-Founder and CEO of Fig, framed the release around a trade-off he wants to eliminate. “Security teams shouldn’t have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure,” he said. “Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve.”

Where Fig Stands Now

The announcement is the next step in a plan the company set out only months ago. Fig has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital. It was named an RSAC Innovation Sandbox finalist. It is now deployed across dozens of Fortune 500 companies.

The larger claim is about the SOC’s place in the stack. As threats accelerate, the SOC is the last line of defense, and its resilience has never mattered more. Fig’s bet is that treating resilience as the default, rather than something to be repaired after the fact, is what lets security teams change fast and stay covered at the same time.

 

Comments

TechBullion

FinTech News and Information

Copyright © 2026 TechBullion. All Rights Reserved.

To Top

Pin It on Pinterest

Share This