Story image

The ultimate guide to building a security operations centre with limited resources

11 Dec 17

Ransomware, fileless malware, WannaCry, credential theft…Keeping up with the growing volume and complexity of cyber threats is no easy task – and it’s made even harder for organisations that don’t have a security operations centre (SOC).

Security IT decision-makers know that accelerating threat detection requires a SOC, yet the number of companies that don’t have a SOC in place is alarming.

Unfortunately, many companies cannot afford a 24x7 SOC.

The expense of having well-trained analysts on site – at all times – outweighs the benefit for most organisations.

This means many companies either make do with an informal SOC made up of small number of analysts, or, worse, they don’t have one at all and rely on borrowing people from other roles when needed.

Neither of these options are going to cut it today. Operating without a SOC means your company could experience major delays in detecting and responding to incidents.

It means you are at a far greater risk of falling victim to a cyber attack.

Ultimately, it means you not only risk losing money - but you risk falling behind the competition.  

However, for organisations caught between the prohibitive cost of a formal SOC and the inadequate protection from an informal SOC, there is hope: building a SOC that automates as much of the SOC work as possible.

This means establishing a solution that takes full advantage of the technology to minimise the number of people needed. 

LogRhythm has created the ultimate guide for building a SOC with limited resources.

Thanks to LogRhythm, getting a SOC up and running in your company can be done in as little as 7 steps – so what are you waiting for?

JASK prepares for global rollout of their AI-powered ASOC platform
The JASK ASOC platform automates alert investigations, supposedly freeing the SOC analyst to do what machines can’t. 
Pitfalls to avoid when configuring cloud firewalls
Flexibility and granularity of security controls is good but can still represent a risk for new cloud adopters that don’t recognise some of the configuration pitfalls.
CERT NZ highlights rise of unauthorised access incidents
“In one case, the attacker gained access and tracked the business’s emails for at least six months. They gathered extensive knowledge of the business’s billing cycles."
Report finds GCSB in compliance with NZ rights
The Inspector-General has given the GCSB its compliance tick of approval for the fourth year in a row.
Securing hotel technology to protect customer information
Network security risks increase exponentially as hotels look to incorporate newer technologies to support a range of IoT devices, including smart door locks.
Why total visibility is the key to zero trust
Over time, the basic zero trust model has evolved and matured into what Forrester calls the Zero Trust eXtended (ZTX) Ecosystem.
Gartner names Proofpoint Leader in enterprise information archiving
The report provides a detailed overview of the enterprise information archiving market and evaluates vendors based on completeness of vision and ability to execute.
WatchGuard appoints new channel distributors in A/NZ
The appointments will enable WatchGuard to expand its regional channel reseller footprint.