Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


10:00 AM
Moti Gindi
Moti Gindi

Building a Next-Generation SOC Starts With Holistic Operations

The proper template for a modernized SOC team is one that operates seamlessly across domains with a singular, end-to-end view.

Cybersecurity leaders know a well-built security operations organization involves the right mix of architecture, processes, analytics, and technology attuned to the threat landscape. 

Many security operations centers (SOCs) today separate the handling of email, network, and endpoint alerts. Whether it's all in-house or partially outsourced to a managed security provider, there's a prevailing logic that specializing teams or roles focused on technical domains increases effectiveness. 

Related Content:

Operationalizing Threat Intelligence at Scale in the SOC

Special Report: Understanding Your Cyber Attackers

New From The Edge: Breach Etiquette: How to Mind Your Manners When It Matters

In theory, it's a good approach. But in practice, specializing SOC roles loses the end-to-end view of an attack, which is critically important in high-impact business attacks that cross multiple technical domains. To wit: What happens when a cross-model intrusion occurs, such as the recently rising wave of human-operated ransomware and supply chain compromises? These hands-on keyboard attacks involve human actors with familiarity of systems administration and common security misconfigurations. Their lateral movements destructively jump across gaps in technical silos, from email to endpoint to identity, and it's almost impossible for a segmented SOC to coordinate defenses. 

As attack operators progress through domains, they collect credentials, compromise endpoints, and leverage applications, adapting to what they discover, eventually encrypting organizational data for ransom. The impact includes staggering downtime, financial loss, and interruption to business continuity. (For reference, see Microsoft's guidance for these attacks.) 

Today's reimagined SOCs bring together disparate teams to counteract intrusions, providing everyone with a coordinated, holistic, real-time view. This tactic empowers analysts to head things off, "shifting left" in the cyber kill chain to identify the full scope of the attack while it's happening and quickly block it as far upstream as possible (ideally using automated investigation and response). We see this as the only way for SOCs to address new threats in time to avert major business impacts. It's time to empower your SOC with multidomain, central teams.

It's more than tools differentiating a reactive SOC from an agile, proactive, successful one. Modernizing security operations requires an operational model that drives cross-technology integration to match the attacker's modus operandi. Empowering your SOC to deploy speedy, effective countermeasures means dangerous attackers will be slowed or deterred, reducing damage to your business and saving valuable time and money. 

The proper template for a modernized SOC team operates seamlessly across domains with an end-to-end view. Consider your SOC's opposition: Sophisticated bad actors see the entire picture, know where they're going and who they're engaging, and understand how to exploit weaknesses. They're laser focused on their ultimate goal. Your SOC's operational playbook should be as laser focused on your business value, limiting time required to kick attackers out. 

Close Encounters of a New Kind
Security professionals must evolve to a higher-level holistic stance. If each domain in your enterprise is only trained against one type of intrusion — and if each is unaware of whether other domains are currently affected — then intruders gain the advantage. 

A well-networked defense knows whether to brace for an incident or take preemptive measures. IT teams must have the ability to understand where a violation has traveled, how it gained its advantage, and its objective. For your SOC, it could mean changing the organization's security posture just in time to reduce the attack surface. The benefit of this model is even if cybercriminals rupture your organization, all is not lost. Your SOC can identify, isolate, and stop the assault. 

Everyone in the chain should know how an attack reached their sector and what's happening in real time. When they fully understand an incident, they can coordinate a unified response. 

Similarly, cross-domain SOCs should navigate the journey together. It's a best practice to transparently see all actions taken automatically and manually by protection products, and measure engagement with threats to triage severity across all domains. This builds in more time and budget efficiencies remediating incidents, and provides a view of what might be coming next. 

Stronger Together
An integrated process elevates robust security for your entire ecosystem. Products should extend across security, compliance, and identity, which collectively strengthens your enterprise. 

Why? Because human-operated ransomware campaigns start with commodity malware or unsophisticated attack vectors, triggering multiple alerts. But these are triaged as unimportant and aren't deeply investigated or remediated. Even if initial payloads are halted by antivirus solutions, bad actors deploy them differently or use administrative access to disable the antivirus. Look for next-generation tools delivering out-of-the-box safeguards like cross-domain protections to give your organization comprehensive, ongoing, real-time protection across software and in the cloud. You also want capabilities combining machine learning, big-data analysis, and in-depth threat resistance research to protect your enterprise. Best-of-breed components let you build as your organization grows and evolves. 

Ultimately, your solutions should help SOC staff understand the attack impacts, enabling them to share learnings and practices. This approach saves your enterprise critical reaction time; your business will spend less money on autonomous components, and your SOC is ready to meet challenges by operating at the next level of control. 

Moti Gindi is the Corporate Vice President for Microsoft Defender Advanced Threat Protection (ATP). In his role, he manages an engineering team that is responsible for Microsoft's endpoint security, specifically Microsoft Defender ATP (recently recognized as a leader in ... View Full Bio

Recommended Reading:

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-04-10
Valve Steam through 2021-04-10, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one click.
PUBLISHED: 2021-04-10
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.
PUBLISHED: 2021-04-09
Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat softw...
PUBLISHED: 2021-04-09
Use after free in screen sharing in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
PUBLISHED: 2021-04-09
Use after free in V8 in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.