The Long Tail of Tuning: Optimising SOC Planning and Execution
Dan Haagman
CISO & Cyber Strategist | CEO - Chaleit | Former co-founder of Cyber firms NotSoSecure & 7Safe (both acquired) | Designer of Cyber MSc(s) | Commercial Helicopter & Aeroplane Pilot | JetPack Pilot | Sat-Radio Nerd
In previous newsletters, I discussed the effectiveness of the security operations centre (SOC) and explained some of the “grey areas” that allow attackers to bypass core security controls.
Today, I want to develop another critical aspect of SOC management that often goes overlooked: the long tail of tuning and optimisation.
Here’s what happens: When companies invest in a SOC, they tend to view it as a "one-and-done" solution, but this couldn't be further from the truth.
Initially, many stakeholders, ranging from architecture groups to extended sign-off chains, come together to operationalise the SOC. However, the long tail of this process extends well beyond the initial setup, demanding continuous tuning and validation.
While vendors may provide support for a limited period, the organisation is responsible for ensuring that the SOC remains effective.
The reality is that many organisations fail to consider the configuration and long-tail maintenance after implementation. While a SOC comes with powerful detection capabilities, it's not automatically fit for purpose right out of the box. It needs continuous investment, tuning, and validation to remain effective against evolving threats.
The lack of ongoing attention creates a perfect storm when combined with misconfigurations. We've seen cases where SOCs appear to be working well—generating alerts and seeming productive—until a purple team exercise or worse, a real attack, exposes their vulnerabilities.?
So, what can we do to address this issue? Here are a few key points to consider:?
领英推荐
?
Remember, by neglecting the long tail of SOC tuning, you create blind spots that skilled attackers can exploit.
Let’s shift the narrative around SOC management. Organisations must understand that a SOC is not a set-it-and-forget-it solution but a living system that requires ongoing attention to remain effective.
At Chaleit, we help organisations navigate these challenges by focusing on continuous improvement and validation. Our approach allows us to build more resilient security operations that truly deliver on their promise to protect critical assets.
?In future articles, I’ll focus more on the relevance, impact, and effectiveness of our security practices. If you haven't already, subscribe to the Cyber Securi-Tea newsletter and let’s continue the conversation in the comments.
#CISO #DigitalTransformation #TechTrends #Cybersecurity #CyberResilience #Informationsecurity #Cyber #SOC #CybersecurityThreats #BusinessPreparedness #CyberSecurityDefense
Cyber Communicator I Co-Founder Murfin Group I AI Product Creator/Trainer
4 个月A clear vision of what success looks like is the beginning. You can work backwards and build on the milestones when you have that success clearly articulated. I believe this allows you to best assign the limited resources, skills and time you have to bring to life the vision or 'Destenation Postcard.'
Senior Security Program Manager | Leading Cybersecurity Initiatives | Driving Strategic Security Solutions| Cybersecurity Excellence | Cloud Security
4 个月?It's clear that sustainable cybersecurity outcomes require more than just purchasing solutions—they demand ongoing commitment, strategic consolidation, and accountability. Balancing initial investments with ongoing attention is crucial for achieving real ROI and reducing risk effectively. Dan Haagman
Cybersecurity Influencer | Advisor | Author | Speaker | LinkedIn Top Voice | Award-Winning Security Leader | Awards Judge | UN Women UK Delegate to the UN CSW | Recognised by Wiki & UNESCO
4 个月Absolutely agree, Dan! It feels like we're all racing to buy the shiniest new tech toys without thinking about what it takes to keep them running smoothly. It's like getting a puppy because it's cute but not being ready for early morning walks and vet visits. We need to slow down, think about what we really need, and invest in making those solutions work for us over time. Otherwise, it's just money down the drain.
Global Head of Audit at ION
4 个月Many thanks Dan Haagman, great posting. From an audit perspective, I still see homework not being done, incomplete or even ignored. Thorough asset management, clear ownership and consistent risk-based methodlogies - it sounds so easy. But it takes understanding, time, and - management commitment.
I save companies from evil cyber villains | Bridging humanity and technology | The hype person YOU need in your life | High ENERGY speaker!!!
4 个月Dan!!!?Your BRILLIANT posts ALWAYS leave my brain upgraded with extra doses of wisdom injected AWESOMENESS!!!!!!!!! Keep spreading the knowledge and inspiration like it's PB&J!!!