New York, USA, July 21st, 2026, FinanceWire
Security teams are adding more technology to their environments than ever before. Data sources multiply, cloud services change, detections are updated, and automation becomes a larger part of the response process. But every addition or modification introduces another dependency that can affect the systems security teams rely on to detect threats.
That creates a challenge that goes beyond identifying the right threats. Organizations must also ensure that the infrastructure supporting their detection and response operations continues functioning as the environment around it changes.
Fig's latest platform expansion focuses on that problem. The company says it now provides a complete engineering lifecycle for Security Operations (SecOps), enabling SecOps Engineers to build, ship, and observe changes through a workflow modeled on continuous integration and continuous delivery (CI/CD).
The broader objective is to make security operations more resilient by treating changes as an engineering process that can be tested, controlled, and continuously verified.
A New Workflow for Detection Engineering
At its core, Fig is giving SecOps something it has never had: a complete engineering lifecycle for detections and configurations.
The workflow starts with the engineer. Instead of manually navigating multiple systems to build a detection or configuration, the engineer describes the desired change. Fig then analyzes the existing environment and proposes an implementation based on the infrastructure and relationships already in place.
The proposed change is simulated and tested before production deployment, allowing its expected impact to be evaluated in advance. Once approved, the update can be deployed with version control and rollback capabilities.
The process does not end after deployment. Continuous observability is designed to confirm that detection flows continue working as intended, including both existing pipelines and newly introduced changes.
For security operations teams, the model represents a shift from treating infrastructure updates as isolated tasks to managing them as part of an ongoing engineering lifecycle.
Connecting the Pieces Through Data Lineage
The foundation of the workflow is Fig's security data lineage, which the company describes as a deterministic graph mapping detections, data sources, and the connections between them across the SecOps stack.
That mapping gives the platform a broader view of the environment in which a change is being made. Rather than evaluating a detection or configuration independently, Fig can assess its relationship with other components of the infrastructure and consider how changes may affect the wider detection pipeline.
This is particularly relevant in environments where dependencies can extend across multiple systems. An update made upstream may affect a downstream detection without an obvious indication that anything has gone wrong.
Fig's continuous verification approach is intended to reduce that risk by monitoring detection flows as infrastructure evolves.
Speeding Up Projects That Often Take Months
The platform's expanded capabilities also target several areas where SecOps teams can spend significant time.
Fig says threat reports can be transformed into detections and queries more quickly, allowing teams to implement protections without lengthy development cycles. SIEM migrations are another focus, with the company saying organizations can complete those projects in weeks instead of months while remaining fully operational during the transition.
Teams can also gain greater control over the data plane, allowing them to manage data ingestion and storage costs without disrupting live detections.
The underlying idea is to remove some of the operational plumbing that can slow security engineering work, allowing teams to concentrate on the logic behind their detections.
The Case for Confidence Over Speed Alone
While faster deployment is a key part of the announcement, Fig's positioning goes beyond productivity. The company is emphasizing the ability to make changes without sacrificing confidence in the security infrastructure supporting them.
Jayme Hancock, Head of Security Operations and Engineering at AppLovin, said, "With Fig we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing." He added, "My team builds with a confidence we've never had, and yeah, we've even started 'vibe parsing.'"
The comment highlights the distinction between simply accelerating a workflow and creating a process in which changes can be validated before deployment and monitored afterward.
Resilience as an Engineering Discipline
Fig's latest announcement builds on its broader Security Operations Resilience strategy. The company has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital, was named an RSAC Innovation Sandbox finalist, and says its platform has been deployed across dozens of Fortune 500 companies.
The company was founded by veterans of Google SecOps and Siemplify, who Fig says drew on experience maintaining some of the world's largest and most complex security operations environments.
Gal Shafir, Co-Founder and CEO of Fig, said the company's approach is intended to eliminate a long-standing tradeoff in security operations. "Security teams shouldn't have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure," he said. "Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve."
For Fig, the larger shift is about making resilience part of the engineering process itself. As security infrastructure becomes more dynamic, the company is betting that the ability to safely manage change will become just as important as the ability to detect the threats those systems are designed to find.
About TVC Partners
TVC Partners is an independent technology research and advisory firm providing market analysis, strategic insights, and industry expertise across cybersecurity, artificial intelligence, cloud infrastructure, and enterprise technology. Through in-depth research and executive engagement, TVC Partners helps technology leaders navigate emerging trends and make informed business decisions.