
Daute Delgado
CEO & Co-founder, Primedefence
Daute Delgado is CEO and co-founder of Primedefence. He spent more than a decade defending airlines, managed SOCs and international organizations, first as an operator and later leading security teams.
He is an Associate C|CISO and a Silver Winner at the 2021 Cyber Security Excellence Awards. He also founded Unihackers, Primedefence's sister cybersecurity school, where SOC analysts train on the same premise: what gets measured gets better.
At Primedefence he leads every SOC-CMM assessment: scope, interviews, calibration and the executive readout. Primedefence is listed as a Silver Support Partner in the official SOC-CMM report, operates no SOC and sells no tooling.
- Associate C|CISO
- Silver Winner, Cyber Security Excellence Awards 2021
- 10+ years in security operations
Articles by Daute Delgado
All articlesPrivate AI for business: a practical decision guide
Define the control you need, compare deployment options and build an evidence-based investment decision before choosing infrastructure.
2026-09-09Private inferenceOn-premises LLM vs private cloud: a deployment decision
Compare access, capacity, maintenance, recovery and exit. Server location answers only part of the enterprise architecture question.
2026-09-09Private inferencePrivate inference cost: an enterprise budgeting method
Budget implementation, capacity and operation, then calculate cost per accepted task with an explicit worked example.
2026-09-09Private inferencePrivate AI vendor assessment: an enterprise checklist
Align business, IT and security around exclusion requirements, supplier evidence, pilot acceptance, operating commitments and exit.
2026-09-09Private inferenceSelf-hosted LLM vs API: an enterprise decision framework
Compare complete operating models against one workload. An API can also be the interface to a private inference environment.
2026-09-09Private inferencePrivate LLM security: controls and acceptance tests
A model inside your network still needs permissions, limits and recovery. Test the complete application and retain evidence of the result.
2026-09-09Private inferencePrivate AI data residency, access and retention
Follow a request through the interface, model, logs, backups and support. Location alone does not describe the data boundary.
2026-09-09Private inferenceLLM inference capacity planning: memory, load and latency
A memory estimate can reject an unsuitable configuration. A representative load test can establish an acceptable operating range.
2026-09-09Private inferencePrivate AI pilot evaluation: evidence for a production decision
A pilot should end with a decision and reproducible evidence, including the conditions in which the system must not be used.
2026-09-09SOC-CMMSOC Maturity Report 2026: the numbers that matter
The second annual SOC-CMM report in figures: domain and regional averages, the 0.6-point self-assessment gap, analyst retention, automation versus AI, and the real state of SOC certification.
2026-06-09Private inferenceEnterprise LLM model selection for private inference
Choose against the task, languages, licence and operating environment. Parameter count cannot replace system evaluation.
2026-09-09Private inferencePrivate LLM operations: monitoring, change and recovery
Endpoint availability is only part of the job. The service must also preserve quality, permissions and a tested recovery path.
2026-09-09MSSP selectionIndependent MSSP and MDR selection: the buyer-side playbook
An eight-step, evidence-led process for choosing and overseeing an MSSP or MDR provider from the buyer's side.
2026-06-12Private inferencePrivate inference architecture example for internal documents
An illustrative walkthrough from scope to a production decision. This is not a customer deployment or a claim of Primedefence results.
2026-09-09Board & exec10 Board Questions About the SOC Every Director Should Ask
A short list of questions that separates a prepared CISO from one who is improvising.
2026-06-12AI governanceEU AI Act high-risk checklist: readiness before August 2026
What providers and deployers of high-risk AI systems must have in place before the August 2026 deadline, item by item, with the evidence each obligation requires.
2026-06-12EU regulationNIS2 vs DORA: 7 differences that matter for your SOC
They overlap in intent but diverge in scope, precedence, governance, third parties, testing, reporting and penalties. How to sequence them without duplicating work.
2026-06-12MethodologySOC-CMM vs CMMI for Cyber: an honest comparison
Two maturity models, two adoption curves. Which one your board will actually defend.
2026-06-12MethodologySOC-CMM vs SIM3: SOC maturity versus CSIRT maturity
Two similar-looking models for different problems. How not to confuse a CSIRT with a SOC, and how to pick the right model for each team.
2026-06-12SOC-CMMSOC-CMM 2026: the complete guide to the five domains, continuous scoring and certification
What SOC-CMM v2.4 measures, how it scores maturity and capability, what the 2026 benchmark data shows, and how to turn the questionnaire into a board-defensible roadmap and a certification path.
2026-01-19SOC-CMMCyber insurance evidence pack 2026: what to include
What an underwriting evidence pack contains, why an independent SOC-CMM assessment strengthens your underwriting and claims position, and how to maintain it year over year.
2026-06-12SOC-CMMCommon SOC-CMM assessment mistakes and how to avoid them
The patterns that erode assessment quality and board confidence. How to catch them before the report is written.
2026-06-12EU regulationDORA Article 26 TLPT: scope, cycle and SOC readiness
Who must run threat-led penetration tests under DORA, on what cycle, how TIBER-EU shapes the exercise, and why SOC maturity decides whether the test is useful.
2026-06-12SOC-CMMSOC Metrics 2026: What Matters to a CISO, What Does Not
Beyond MTTD and MTTR. How to build a dashboard a CISO can defend in front of the board.
2026-06-12