Safety operations groups are managing environments that change nearly as rapidly because the threats they’re designed to detect. New cloud companies, knowledge sources, detections, and automatic processes are launched regularly, whereas techniques upstream of the safety stack can change with little warning.
That creates an issue that’s simple to miss. A change doesn’t should be malicious and even notably vital to trigger injury. A routine infrastructure replace can disrupt a detection pipeline, probably leaving safety groups with gaps in visibility earlier than anybody realizes one thing has stopped working.
Fig Safety is aiming at that downside with an expanded platform that covers what the corporate describes as the complete engineering lifecycle for Safety Operations (SecOps). The strategy brings CI/CD-style practices to SecOps, permitting engineers to construct, ship, and observe modifications whereas repeatedly checking that detection operations stay purposeful.
The broader thought is to make resilience a part of the best way safety infrastructure is engineered relatively than one thing groups have to handle after a failure.
A Full Engineering Lifecycle for SecOps
At its core, Fig is giving SecOps one thing it has by no means had: a whole engineering lifecycle for detections and configurations.
The workflow begins with an engineer describing the detection or configuration they wish to create. Fig then evaluates the dwell surroundings and proposes a change primarily based on its understanding of the prevailing infrastructure.
Earlier than deployment, proposed modifications are simulated and examined to find out their anticipated affect. As soon as authorised, engineers can deploy them with model management and rollback capabilities, whereas steady observability displays detection flows to confirm that they proceed working as supposed.
The method is designed to deliver software program engineering disciplines into safety operations, giving groups a structured strategy to testing and deploying modifications relatively than relying totally on handbook validation.
Understanding the Infrastructure Behind Detection
The inspiration of this workflow is Fig’s safety knowledge lineage, which the corporate describes as a deterministic graph mapping detections, knowledge sources, and the connections between them throughout the SecOps stack.
This creates a broader view of the infrastructure surrounding every detection. As an alternative of evaluating modifications in isolation, Fig can use the relationships mapped throughout the surroundings to evaluate how a proposed replace may have an effect on different elements.
That visibility additionally issues when modifications happen outdoors the safety crew’s instant management. An upstream system can evolve and unintentionally have an effect on a downstream detection, whereas a change additional alongside the pipeline can create an issue that’s tough to hint again to its supply.
Fig says its steady verification capabilities are designed to assist establish these points earlier than they undermine detection protection.
Quicker Responses and Shorter Tasks
The platform’s expanded capabilities prolong past particular person infrastructure modifications. Fig says safety groups can translate menace experiences into detections and queries quicker, serving to organizations implement protections with out prolonged growth cycles.
The corporate can be concentrating on large-scale tasks corresponding to SIEM migrations. Based on Fig, organizations can full these transitions in weeks as an alternative of months whereas holding safety operations totally operational in the course of the course of.
Knowledge administration is one other space lined by the platform. Groups can acquire management over knowledge ingestion and storage prices by the info aircraft with out disrupting dwell detections.
Collectively, the capabilities are supposed to scale back the engineering burden related to sustaining safety operations and permit SecOps groups to spend extra time on the logic behind their defenses.
Constructing Pace With out Sacrificing Confidence
Fig argues that quicker safety operations aren’t sufficient if groups can’t belief the infrastructure supporting them. Its workflow is subsequently constructed round validating modifications earlier than manufacturing and monitoring them after deployment.
Jayme Hancock, Head of Safety Operations and Engineering at AppLovin, described the expertise by saying, “With Fig we construct and ship correct detection modifications in minutes as an alternative of weeks, with out the limitless plumbing.” He added, “My crew builds with a confidence we’ve by no means had, and yeah, we’ve even began ‘vibe parsing.’”
The suggestions speaks to the central proposition behind the platform: engineering groups can transfer quicker once they have better visibility into the modifications they’re making and confidence that these modifications will proceed working.
Resilience as a Core Working Precept
The most recent platform enlargement builds on Fig’s broader deal with Safety Operations Resilience. The corporate has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital, was named an RSAC Innovation Sandbox finalist, and says its know-how has been deployed throughout dozens of Fortune 500 firms.
Fig was based by veterans of Google SecOps and Siemplify, and the corporate says its strategy was formed by expertise with a number of the world’s largest and most advanced safety operations environments.
Gal Shafir, Co-Founder and CEO of Fig, mentioned safety groups shouldn’t should commerce velocity for confidence. “Safety groups shouldn’t have to decide on between transferring rapidly and sustaining confidence of their SecOps Infrastructure,” he mentioned.
“Fig offers SecOps Engineers the identical trendy engineering workflow that software program builders have lengthy relied on. They’ll design modifications with full context, show these modifications work earlier than deployment, and repeatedly confirm that their safety operations stay resilient as their environments evolve.”
As safety infrastructure continues to increase and alter, Fig is betting that the subsequent evolution of SecOps will depend upon engineering each change for resilience from the beginning.







