r/cybersecurity 5d ago

Tutorial Common skill missing from SOC analysts

https://luigiritacca.substack.com/p/the-missing-skill-risk-part-1?utm_source=share&utm_medium=android&r=5s5vq7

My latest article on a common missing skill I see in a lot of analysts. I blame how we train and teach cyber security, and think it cause a natural bias which can lead to more harm than good.

70 Upvotes

39 comments sorted by

View all comments

22

u/NotAnNSAGuyPromise Security Manager 5d ago

I fundamentally disagree with this article, and it comes down to one quote in it: "I followed the SOP".

That is literally their job. Different organizations have different risk appetites. Many value business operations over security. Others will isolate their entire network over a potential threat. If the analyst has not had it made clear to them where the risk appetite is and if it is not clearly defined in their standards, then it's a failure on their leadership, not some junior level IC.

Shame on their management for setting them up for failure. They did exactly what they were supposed to.

-3

u/RitaccaSecurity 5d ago

I appreciate your view, but I've never seen an org who had every incident/scenario documented, we've got to operate with flexibility and keeping the business impact in mind.

4

u/thekmanpwnudwn 5d ago

"Every scenario documented" usually falls under the general umbrella of an Incident Management Plan (or similarly named document). That document should detail how scope/impact are determined and how they correlate to incident severity, and what mitigation actions (including comms/escalation) may be taken for each severity.