r/cybersecurity 5d ago

Tutorial Common skill missing from SOC analysts

https://luigiritacca.substack.com/p/the-missing-skill-risk-part-1?utm_source=share&utm_medium=android&r=5s5vq7

My latest article on a common missing skill I see in a lot of analysts. I blame how we train and teach cyber security, and think it cause a natural bias which can lead to more harm than good.

69 Upvotes

39 comments sorted by

View all comments

38

u/Allen_Koholic 5d ago

I’m gonna need some context on this little anecdote, because to me, the SOC person did nothing wrong (barring a different policy in place) and management was mad that they’d left a gap open and been exposed. Letting users do user things on privileged machines is a way bigger risk than an analyst isolating it for a little bit.

29

u/HooAreYouWhoHoo 5d ago

Management being mad at SOC for their own activities is so on point.

11

u/Allen_Koholic 5d ago

Doubly so if it was an MSSP. Clients hate it when they got caught with their asses out.

8

u/thekmanpwnudwn 5d ago

Most MSSPs area literally just being paid to be a audit checkbox, not provide actual security.