Safety operations groups are managing environments that change nearly as shortly because the threats they’re designed to detect. New cloud providers, information sources, detections, and automatic processes are launched frequently, whereas methods upstream of the safety stack can change with little warning.
That creates an issue that’s simple to miss. A change doesn’t should be malicious and even significantly vital to trigger injury. A routine infrastructure replace can disrupt a detection pipeline, probably leaving safety groups with gaps in visibility earlier than anybody realizes one thing has stopped working.
Fig Safety is aiming at that drawback with an expanded platform that covers what the corporate describes as the complete engineering lifecycle for Safety Operations (SecOps). The strategy brings CI/CD-style practices to SecOps, permitting engineers to construct, ship, and observe modifications whereas repeatedly checking that detection operations stay purposeful.
The broader concept is to make resilience a part of the way in which safety infrastructure is engineered moderately than one thing groups have to deal with after a failure.
A Full Engineering Lifecycle for SecOps
At its core, Fig is giving SecOps one thing it has by no means had: a whole engineering lifecycle for detections and configurations.
The workflow begins with an engineer describing the detection or configuration they need to create. Fig then evaluates the stay atmosphere and proposes a change based mostly on its understanding of the prevailing infrastructure.
Earlier than deployment, proposed modifications are simulated and examined to find out their anticipated affect. As soon as permitted, engineers can deploy them with model management and rollback capabilities, whereas steady observability displays detection flows to confirm that they proceed working as supposed.
The method is designed to carry software program engineering disciplines into safety operations, giving groups a structured strategy to testing and deploying modifications moderately than relying totally on guide validation.
Understanding the Infrastructure Behind Detection
The muse of this workflow is Fig’s safety information lineage, which the corporate describes as a deterministic graph mapping detections, information sources, and the connections between them throughout the SecOps stack.
This creates a broader view of the infrastructure surrounding every detection. As an alternative of evaluating modifications in isolation, Fig can use the relationships mapped throughout the atmosphere to evaluate how a proposed replace might have an effect on different elements.
That visibility additionally issues when modifications happen outdoors the safety crew’s instant management. An upstream system can evolve and unintentionally have an effect on a downstream detection, whereas a change additional alongside the pipeline can create an issue that’s troublesome to hint again to its supply.
Fig says its steady verification capabilities are designed to assist determine these points earlier than they undermine detection protection.
Sooner Responses and Shorter Tasks
The platform’s expanded capabilities prolong past particular person infrastructure modifications. Fig says safety groups can translate risk studies into detections and queries sooner, serving to organizations implement protections with out prolonged improvement cycles.
The corporate can also be focusing on large-scale initiatives corresponding to SIEM migrations. In response to Fig, organizations can full these transitions in weeks as a substitute of months whereas conserving safety operations totally operational in the course of the course of.
Knowledge administration is one other space coated by the platform. Groups can acquire management over information ingestion and storage prices via the info airplane with out disrupting stay detections.
Collectively, the capabilities are supposed to scale back the engineering burden related to sustaining safety operations and permit SecOps groups to spend extra time on the logic behind their defenses.
Constructing Velocity With out Sacrificing Confidence
Fig argues that sooner safety operations are usually not sufficient if groups can’t belief the infrastructure supporting them. Its workflow is due to this fact constructed round validating modifications earlier than manufacturing and monitoring them after deployment.
Jayme Hancock, Head of Safety Operations and Engineering at AppLovin, described the expertise by saying, “With Fig we construct and ship correct detection modifications in minutes as a substitute of weeks, with out the limitless plumbing.” He added, “My crew builds with a confidence we’ve by no means had, and yeah, we’ve even began ‘vibe parsing.’”
The suggestions speaks to the central proposition behind the platform: engineering groups can transfer sooner once they have higher visibility into the modifications they’re making and confidence that these modifications will proceed working.
Resilience as a Core Working Precept
The most recent platform growth builds on Fig’s broader deal with Safety Operations Resilience. The corporate has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital, was named an RSAC Innovation Sandbox finalist, and says its expertise has been deployed throughout dozens of Fortune 500 firms.
Fig was based by veterans of Google SecOps and Siemplify, and the corporate says its strategy was formed by expertise with a number of the world’s largest and most advanced safety operations environments.
Gal Shafir, Co-Founder and CEO of Fig, stated safety groups mustn’t should commerce velocity for confidence. “Safety groups shouldn’t have to decide on between shifting shortly and sustaining confidence of their SecOps Infrastructure,” he stated.
“Fig offers SecOps Engineers the identical fashionable engineering workflow that software program builders have lengthy relied on. They’ll design modifications with full context, show these modifications work earlier than deployment, and repeatedly confirm that their safety operations stay resilient as their environments evolve.”
As safety infrastructure continues to develop and alter, Fig is betting that the following evolution of SecOps will rely upon engineering each change for resilience from the beginning.









