Google Security Operations
Google Cloud's cloud-based security operations platform for retaining, analyzing, and searching enterprise security telemetry and responding to cyber threats.
Last updated August 31, 2026
Overview
Google Security Operations, also known as Google SecOps, is a Google Cloud cybersecurity offering focused on enterprise security operations. It provides a cloud service through which organizations can retain, search, analyze, and interpret large volumes of security and network telemetry. The platform is designed to help security teams identify threats, investigate suspicious activity, and support responses to cyber incidents. The offering originated under the Chronicle name and was subsequently incorporated into Google Cloud. Its architecture is described as a specialized layer built on Google's core infrastructure. The service is intended for external enterprise customers, while drawing on security engineering principles and infrastructure approaches used by Google to protect its own global systems, offices, and data centers. This positioning connects the product with Google's large-scale data-processing capabilities without making it a general-purpose consumer security service. A central element of the platform's development was the combination of telemetry analysis with threat intelligence. Chronicle announced Backstory at the RSA Conference in March 2019. Backstory was presented as a system for capturing and analyzing logs and extracting useful signals from security telemetry. It was designed to work with threat-intelligence resources, including information about malicious IP addresses and URLs. The broader Chronicle family was associated with services and technologies such as VirusTotal and UpperCase, which contributed threat-intelligence capabilities. In June 2019, Google Cloud chief executive Thomas Kurian announced that Chronicle would be merged into Google Cloud. The integration placed Chronicle's security analytics capabilities within Google's cloud business and linked them with other Google Cloud technologies. The resulting Autonomic Security Operations approach has been described as incorporating Chronicle-related capabilities together with VirusTotal, Looker, and BigQuery. These integrations support a broader model in which security data is collected and analyzed at cloud scale, enriched with threat intelligence, and made available for investigation and operational reporting. On April 25, 2024, Google Chronicle Security Operations was rebranded as Google Security Operations. The new name presents the offering as part of Google Cloud's broader security portfolio rather than as a standalone Chronicle-branded company. The platform's stated scope remains enterprise security operations, including threat detection, telemetry analysis, investigation, and response support. The available reference material does not establish a separate consumer product line, independent public-company status, or a distinct corporate headquarters separate from Google and Google Cloud.
History
Google Security Operations developed from Chronicle, a cybersecurity product and company associated with Google's security technology efforts. The available historical account identifies January 2018 as the point at which the product became its own company. Its purpose was to create tools that businesses could use to prevent and investigate cybercrime affecting their platforms. Chronicle's early direction centered on applying Google's infrastructure and large-scale data-handling expertise to enterprise security. Rather than functioning as a conventional endpoint or consumer security product, it was designed as a specialized cloud layer for handling the substantial volumes of security and network telemetry generated by large organizations. The service was also described as using the same general systems and principles that Google applies to protecting its own infrastructure, including offices and data centers, although it was commercialized for external customers. A significant product milestone came in March 2019, when Chronicle announced Backstory at the RSA Conference. Backstory expanded the Chronicle family with log capture and analysis. Its stated purpose was to extract security signals from collected telemetry and use those signals to identify threats quickly. Backstory was intended to operate alongside threat-intelligence capabilities, including data on known malicious IP addresses and URLs. The broader set of associated capabilities included VirusTotal and UpperCase, which supplied or supported threat-intelligence functions. In June 2019, Thomas Kurian announced that Chronicle would be merged into Google Cloud. This organizational change moved Chronicle from a separately presented company into Google's cloud business and connected its security operations capabilities with the wider Google Cloud platform. Chronicle-related capabilities were subsequently described as part of an Autonomic Security Operations approach that also included VirusTotal, Looker, and BigQuery. The combination linked security telemetry, threat intelligence, analytics, visualization, and cloud data-processing tools. The brand later moved away from the Chronicle name. On April 25, 2024, Google Chronicle Security Operations was rebranded as Google Security Operations. The rebrand aligned the product more directly with Google Cloud's security portfolio and established Google SecOps as a common short name. Under the current identity, the offering remains focused on enterprise security operations: collecting and retaining security data, searching and analyzing telemetry, enriching investigations with threat intelligence, and helping organizations detect and respond to cyber threats. Google Security Operations is therefore best understood as a Google Cloud security platform and brand rather than an independent publicly listed company. Its corporate ownership is within Google Cloud and Alphabet, while its commercial role is to provide external organizations with cloud-based security operations capabilities derived from Google's large-scale security infrastructure and operating experience.
- 2024Google Chronicle Security Operations is renamed Google Security Operations
The Chronicle-branded security operations offering was rebranded as Google Security Operations on April 25, 2024.
- 2019Backstory is announced
Chronicle announced Backstory at the RSA Conference in March 2019, adding log capture and analysis to its security operations and threat-intelligence offering.
- 2019Chronicle joins Google Cloud
In June 2019, Thomas Kurian announced that Chronicle would be merged into Google Cloud.
- 2018Chronicle becomes an independent company
Chronicle became its own company in January 2018 after originating as a product associated with Google's security efforts.
Products and positioning
An enterprise-focused security operations platform positioned around cloud-scale telemetry analysis, threat intelligence, and AI- and analytics-assisted threat detection and investigation.
Google Security OperationsSecurity operations platform2024
The current Google Cloud security operations offering, commonly called Google SecOps. It is a cloud service for enterprise customers that retain, search, and analyze security and network telemetry. Its intended uses include threat detection, investigation, threat-intelligence enrichment, and support for incident response.
ChronicleSecurity analytics platform2018
The former name of the security operations offering that preceded Google Security Operations. Chronicle was developed as a specialized cloud layer for handling large volumes of enterprise security data and was later integrated into Google Cloud.
BackstorySecurity log analysis2019
Backstory was announced as part of Chronicle in 2019. It focused on capturing and analyzing logs and combining security telemetry with threat intelligence to help identify threats.
Autonomic Security OperationsIntegrated security operations solution
An integrated Google Cloud security operations approach described as combining Chronicle-related capabilities with VirusTotal, Looker, and BigQuery. The combination brings together threat intelligence, security telemetry analysis, data processing, and reporting functions.
Flagship businesses
- Google SecOps
- Chronicle
- Backstory
- Autonomic Security Operations
Brand decisions
- 2024Rebrand Chronicle Security Operations as Google Security OperationsStrategy
The Chronicle-branded security operations offering had become part of Google Cloud's security portfolio.
What changed. On April 25, 2024, Google changed the name Google Chronicle Security Operations to Google Security Operations, also known as Google SecOps.
Aftermath. The rebrand positioned the service more directly under the Google Cloud security brand while retaining its enterprise security operations focus.
- 2019Move Chronicle into Google CloudM&A
Chronicle had developed security analytics and threat-intelligence capabilities for enterprise customers, including the Backstory service.
What changed. In June 2019, Thomas Kurian announced that Chronicle would be merged into Google Cloud.
Aftermath. The security offering became part of Google's cloud organization and was later presented alongside other Google Cloud security and data-analysis services.
Recent events
- 2024Google Chronicle Security Operations is rebranded as Google Security Operations
On April 25, 2024, Google Chronicle Security Operations adopted the Google Security Operations name, also commonly shortened to Google SecOps.
Product generation - 2019Chronicle announces Backstory security analytics service
Chronicle announced Backstory at the RSA Conference in March 2019. The service was presented as a way to capture and analyze security logs, combine them with threat intelligence, and identify meaningful signals in enterprise security telemetry.
Product launch - 2019Chronicle is merged into Google Cloud
In June 2019, Thomas Kurian announced that Chronicle would be merged into Google Cloud, bringing the security analytics business into Google's cloud organization.
M&A
Sources
Cite this profile: Cite the canonical profile. /brand-wiki/google-security-operations · Editorial policy · How profiles are compiled