Mimecast Limited (NASDAQ: MIME), a leading email and data security company, today released the latest report from the Cyber Resilience Think Tank (CR Think Tank) highlighting four trends for building and operating a Security Operating Center (SOC). In the report titled, Transforming the SOC: Building Tomorrow’s Security Operations, Today, CR Think Tank members weigh the benefits and challenges of keeping a SOC in-house versus outsourcing it. The group also lays out key actionable tips to build a successful model for any size organization.
As an independent group of securityleaders dedicated to understanding the cyber resilience challenges facing organizations across the globe, the CR Think Tankprovidesprescriptive guidance based on lessons learned and decades of expertise.This latest report digs into the human element of team organization, various cybersecurity strategies, and the tools and technology underpinning SOCs. The CR Think Tank agreed that what works for one organization may not work for another and has identified the following trends as key factors to consider when building out a strategy for your organization:
In the report, all Think Tank members highlighted the importance of ensuring SOC analysts and engineers are tuned into the company’s cybersecurity strategy, business processes and overall business. Malcolm Harkins, Chief Security and Trust Officer at Cymatic, believes team structures can help with upskilling: “I believe structure drives behavior,” Harkins said. “We’ve had creative ways of getting people out of their day jobs, such as job rotations between teams, and factory tours for security and management at just the cost of time and travel, because when people understand the criticality and unique needs of a function, they’re usually impressed.”
When an outsourced relationship becomes a cyber security partnership, an external SOC team can be a key partner in addressing issues and shaping the organization’s long-term security needs.However, a lack of physical presence in the office can cause miscommunication or trust issues, which are detrimental to the business.
CR Think Tank members highlights, that no matter if the SOC team is internal or external, the onus is on the CISO to showcase the SOC team’s value. As that team function is not often seen as a core competency, building relationships with the senior executive leadership team will ensure CISOs have what they need for success.
The report highlights the potential of automation in the SOC but does warn against the over-use of it as it can make an organization’s actions easier to predict and therefore more vulnerable to threat actors. “Automation itself is a form of vulnerability,” said Sam Curry, Chief Security Officer at Cybereason. “You have to check your blind spot at pseudo-random intervals to see who’s hiding there because the machine will become predictable and therefore exploitable. So, the mission is not to automate for the sake of it, but to make the humans more effective, improving the value of their output without weakening the whole.”
The CR Think Tank agreed that businessand security need to be in lockstep to be proactive whenever possible and avoid the security chase.
Seating location within an office can make a big difference – many companies opt to put their tech and security teams next to each other to foster creativity, agility and better communication. For example, seating SOC teams next to the product team can improve efficiencies in terms of how they iterate and build new tools. However, for employees who work remotely, communicating with internal teams frequently to ensure alignment on priorities and objectives is key.
No matter what an organization’s SOC setup is, the most important factor is relationships. SOC teams, whether internal or external, need to be invested in the organization’s mission and its core targets. With talented individuals in short supply, training, upskilling and using technology for efficiency gains are key to transform your SOC team.
Download the full report: Transforming the SOC: Building Tomorrow’s Security Operations, for more insights from the CR Think Tank.