Outsourced SOCs and MDR services – Mind the MDR expectation gap
Thomas Murray
Global Risk Intelligence | Safeguarding clients and their communities since 1994
The lack of cyber security talent is well documented. Organisations have responded in various ways, with many of them opting to plug the supply gap by leveraging elements of an external monitoring service, such as a security operations centre (SOC) or managed detection and response (MDR) provider.
These third parties provide capacity and expertise and form a critical component of cyber security within an organisation’s control framework. But resource constraints can lead to a lack of oversight, and testing of these services presents a significant risk to businesses.
There are many benefits to leveraging such a service, but providers often operate quietly in the background and give their clients limited insights into just how effectively their services are running. Instead, they usually present abstract KPIs in a manner that can result in false confidence in the service’s effectiveness.
Our experience has shown us that these critical services are frequently misconfigured and do not operate as desired. The broader business impact is that the investment is, essentially, under optimised. In terms of risk management, however, an organisation’s cyber risk significantly increases, and it is presented with an additional, unmanaged level of risk. This could occur for many reasons: ?
Our team regularly needs to provide forensics and incident response assistance where a third party is already providing an MDR service, and the service provider has either not detected a threat or failed to respond appropriately to one. This is something we have coined the “MDR expectation gap.” This expectation grows over time as the ongoing service decay continues to impact the coverage, and thus increase the risk facing the business.
At Thomas Murray, we recognise the importance of addressing the expectation gap as well as optimising the significant investment organisations make in these external services.
We have developed a service that provides insights into this critical area by leveraging our experiences of:
We enable clients to identify and address issues in a proactive manner, for example before a breach occurs.
领英推荐
Thomas Murray’s approach allows us to:
The combination of our experience, technical insights, and wider industry knowledge combine to form the basis of our SOC testing and validation services. It is, however, our focus on threat intelligence that makes this service so valuable and unique.
It has never been more important to test existing SOC and MDR services. Adopting a robust testing approach will ensure the accuracy and effectiveness of this critical service area. At Thomas Murray, we accurately simulate both common and industry-specific threat actors in a manner that is aligned to the client’s risk appetite.
Did you know?
Cyber Risk
We bring the best of our collective experience, energy and creative power to fiercely safeguard our clients and fortify their communities. Learn more.