There is a framework for thinking about what you know and don't know about the security state of your environment that I find consistently useful. It comes from intelligence practice: known knowns, known unknowns, and unknown unknowns.
Alert-based security operations handle known knowns well. Coverage gap work addresses known unknowns. Unknown unknowns are the hard problem - and they are the category where many significant intrusions originate. The adversary who finds an unknown unknown in your environment has found a path where no defender is watching.
| Threat Matrix Category | Operational Focus | Primary Defensive Capability |
| Known Knowns | Expected threat signatures and rules. | Reactive alert queues and legacy SIEM correlation. |
| Known Unknowns | Identified telemetry & visibility gaps. | Systematic threat modeling and coverage expansion. |
| Unknown Unknowns | Novel TTPs, stealth drift, and hidden paths. | Continuous security monitoring and exploratory analytics. |
Situational awareness is the operational capability that addresses unknown unknowns. It means developing and continuously maintaining an analytically grounded understanding of your environment - what is in it, what is normal, what is changing - that creates the context needed to recognize anomalies that don't match any known threat pattern.
Situational awareness does not come from alert queues. It comes from exploratory analytics on the full telemetry set, guided by current threat model knowledge and genuine investigative curiosity.
It means regularly asking open-ended questions of the data:
These questions require two things that most security programs don't have together: an analytical infrastructure fast enough to support exploratory query without scheduling overnight jobs, and analyst time protected from alert queue pressure to actually run the exploration.
At Netenrich, the sub-second retroactive search on BigQuery across years of UDM-normalized telemetry was built specifically to make situational awareness operationally practical. When a hypothesis can be tested in seconds, analysts test hypotheses. When a query takes hours, hypotheses wait for a slow day.
The discipline of protecting analyst time for exploratory work is a leadership decision. The most important findings from our customers' situational awareness work - the active intrusions found weeks before detection would have fired, the exposures that created serious risk before any adversary had exploited them - came from analysts with the time and the tools to look.
Ready to eliminate unknown threats across your enterprise? Partner with Netenrich to deploy an Agentic SOC that automates your reactive alert queues, giving your team the sub-second analytics and protected time they need to hunt down hidden, sophisticated adversaries.
*Part of my ongoing series on data science and the future of security operations.*