Fig Extends Platform Coverage to the Entire SecOps Engineering Lifecycle, Setting Resilience as the Default

Related

Share

The modern security operations center is built on a growing collection of detections, data sources, cloud services, and automated workflows. While these technologies strengthen an organization’s defenses, they also create a new challenge: ensuring that every component continues working as changes are introduced across the environment.

Fig‘s latest product announcement is aimed squarely at that problem. The company has expanded its platform to deliver what it calls a complete engineering lifecycle for Security Operations (SecOps), enabling engineers to build, ship, and observe changes through a workflow modeled after continuous integration and continuous delivery (CI/CD).

According to Fig, the objective is to give security teams the same level of confidence in deploying operational changes that software developers have come to expect when releasing code.

From Manual Processes to Automated Workflows

At its core, Fig is giving SecOps something it has never had: a complete engineering lifecycle for detections and configurations. Engineers begin by describing the detection or configuration they want to create, after which Fig evaluates the existing environment and generates a proposed change.

Before deployment, every recommendation is simulated and tested to determine its expected impact. Once approved, the change can be deployed with version control and rollback support, while continuous observability verifies that detection pipelines remain healthy after implementation.

Instead of relying on manual validation throughout the process, the platform is designed to automate much of the engineering workflow while maintaining visibility into how each change affects the broader security infrastructure.

A Single View of the SecOps Environment

Central to the platform is Fig’s security data lineage, which maps every detection, data source, and connection across the SecOps stack into a deterministic graph.

The company says this unified view gives Fig the context needed to understand infrastructure at a detailed level, allowing it to evaluate proposed changes before they reach production. Because relationships across the environment are continuously mapped, the platform is also intended to identify issues caused by changes occurring elsewhere in the infrastructure.

For security teams, that means updates can be introduced with a clearer understanding of their potential impact on detection coverage.

Reducing Friction Across Common Security Projects

The expanded platform is designed to support several activities that frequently consume security engineering resources.

Fig says organizations can turn threat reports into detections and queries much faster than traditional workflows allow, helping security teams respond to emerging threats more quickly. The platform also aims to shorten SIEM migration timelines while keeping security operations fully functional during the transition.

Another capability focuses on the data plane, enabling teams to manage ingestion and storage spending without interrupting production detections or modifying existing security logic.

Together, these capabilities are intended to reduce operational complexity while allowing engineers to focus on improving detection quality.

Designed Around Confidence

While speed is one benefit of the new workflow, Fig places equal emphasis on confidence. By validating changes before deployment and continuously verifying them afterward, the company says security teams can make updates without worrying that unseen infrastructure changes have weakened their defenses.

Jayme Hancock, Head of Security Operations and Engineering at AppLovin, said the platform has significantly changed how his team approaches detection engineering. “With Fig we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing,” he said. “My team builds with a confidence we’ve never had, and yeah, we’ve even started ‘vibe parsing.'”

His comments reflect the company’s broader focus on reducing uncertainty throughout the deployment process rather than simply accelerating development.

Building on a Larger Vision

The launch represents another step in Fig’s strategy around Security Operations Resilience. Since emerging from stealth, the company has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital, been named an RSAC Innovation Sandbox finalist, and says its technology is now used by dozens of Fortune 500 companies.

Founded by veterans of Google SecOps and Siemplify, Fig says its platform was created after years of observing how seemingly routine infrastructure changes could quietly undermine even the most mature security operations centers.

Co-Founder and CEO Gal Shafir said the company’s goal is to eliminate the tradeoff between speed and reliability in security operations. “Security teams shouldn’t have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure,” he said. “Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve.”

As organizations continue to expand their security infrastructure, Fig is positioning its platform around a straightforward premise: resilient security operations require not only effective detections, but also disciplined engineering practices that ensure those detections continue working through constant change.

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.