That philosophy is being tested in real time as AI, via SecurityHQ's own AXCEL platform, takes on more of the triage, investigation, and enrichment work inside the SOC. Hambleton is emphatic that acceleration isn't the same as replacement: attackers are already using AI to move faster, and defenders have to as well, but he believes the industry's real blind spot isn't speed, it's judgment. In this conversation, he discusses the most common mistakes organizations make before, during, and after a cyber incident, why he treats prevention and response as one connected discipline rather than competing budget lines, and why he believes every incident should leave an organization measurably stronger than it was before.
My background has always been in cybersecurity and forensics, including intelligence, incident response, and SOC operations. More recently, supporting technical sales and leading advisory services exposed me directly to customer problems and how security needs to be communicated.
That combination has shaped my approach at SecurityHQ: services should solve a clear customer problem, work together rather than sit in silos, and translate technical capability into outcomes that customers can understand and measure. That’s the backbone of our Security Performance Engineering approach, with services engineered around each customer’s environment and continuously improved over time.
Before an incident, organizations often invest heavily in controls without testing whether their people can make decisions under pressure. During an incident, the biggest mistake is acting before establishing reliable context, or assuming technology alone will provide the answer.
Afterward, teams often restore operations without using what they learned to improve detections, playbooks, and response processes. Incident response should be a continuous learning loop. Every event should leave the organization stronger and better prepared.
Security Performance Engineering means moving beyond monitoring coverage and continuously improving how security performs. It combines security engineered around the individual customer, ongoing accountability, and intelligence gathered across our global operations.
In practice, that means improving signal quality, detection accuracy, response speed, and control maturity over time.
It is a better model because organizations should not only ask whether they are protected today. They should be able to demonstrate that their security program is becoming more effective.
Prevention and response should not be treated as separate priorities competing for investment. Threat intelligence helps organizations understand where attacks are most likely to come from, while exposure management proactively identifies and closes weaknesses before they become incidents. Detection and response remain essential for the threats that still get through. The strongest programs connect all three, using intelligence to focus preventive action, exposure data to reduce risk early, and lessons from incidents to strengthen future defenses.
My priority is to bring our products and services together as one connected offering rather than a collection of isolated capabilities. A major part of that is using AI to close the speed gap between attackers and defenders, without removing human judgment. AXCEL can accelerate triage, investigation, and enrichment, while experienced analysts remain responsible for sensitive decisions.
The opportunity is to give customers faster answers, clearer context, and someone accountable at the moment they need help most.
The industry should stop obsessing over whether AI can remove people from security operations and focus on how it can make experienced people more effective. Attackers are already using AI to move faster, so defenders need to use it as well. But speed without judgment is not enough. AI should reduce noise, connect evidence, and accelerate detection. When a serious incident occurs, customers still need a person who understands their environment, can interpret the situation, and is accountable for what happens next.