How SOCaaS Can Help
Many organizations lack the IT bench strength to run an effective SOC. “Most people think that you can run a SOC purely with off-the-shelf software, but it’s not really the case. You have to be able to author detections and manage your threat intelligence,” says Dan Schiappa, president of technology and services at Arctic Wolf.
As CDW’s white paper points out, staffing an in-house SOC with 24/7 coverage requires at least five to eight full-time employees. This can be a challenge in today’s landscape, where there is high demand for skilled cybersecurity experts and a shortage of qualified people to fill those open roles. SOCaaS can help to close that gap.
With SOCaaS, “you have a team of security experts monitoring your business. They’re factoring your unique context into those decisions and they’re doing it on your behalf, with their expertise,” Schiappa says. “The biggest benefit is you get to sleep at night.”
EXPLORE: Find out how security has changed and why it should matter to your organization.
There’s a potential budgetary win as well. “It costs about $5 million to really set up a true SOC,” Schiappa says. An “as a service” approach turns that capital expenditure into an operational expenditure. And in terms of outcomes, “it’s roughly 15 times more safe to have SOC as a Service as opposed to just running a standard security function inside a company.”
For the human cyber defenders, SOCaaS can cut down on alert fatigue by highlighting only real and serious threats. “It sees an alert from the network detection response tool and it matches it up with threat intelligence,” Kissel says. If it’s not an exploitable alert, “it could eliminate that alert from the queue.”
Pivoting Toward SOCaaS
In an enterprise looking to pivot toward SOCaaS, IT leaders can take steps today to start moving in that direction. First, it helps to know what you’re defending. “Take an inventory every month of your devices, your appliances and your users,” Kissel says.
IT leaders should also take stock of their human talent. “What expertise do you have, and what do you want to have? And where is it better to rely on others?” Schiappa says. By taking an honest look, leaders can start to spot gaps and build the business case for a managed services approach.
From there, it makes sense to do a formal proof of concept. “Have three or four vendors come in and take a certain number of IP addresses, and you give them a very specific trial: We want you to look at these 40 alerts that we got from our SIM and tell us what further insights we should get from them,” Kissel says.
A proof of concept will be especially important here because the tools perform differently in different industries. For example, “some tools work really well with a technology-focused environment, some tools seem to do better with hospitality,” he says.
A proof of concept can help identify the most effective solution for a given enterprise, and that can help drive success in a SOCaaS environment.
