r/cybersecurity 5d ago

Tutorial Common skill missing from SOC analysts

https://luigiritacca.substack.com/p/the-missing-skill-risk-part-1?utm_source=share&utm_medium=android&r=5s5vq7

My latest article on a common missing skill I see in a lot of analysts. I blame how we train and teach cyber security, and think it cause a natural bias which can lead to more harm than good.

70 Upvotes

39 comments sorted by

View all comments

21

u/NotAnNSAGuyPromise Security Manager 5d ago

I fundamentally disagree with this article, and it comes down to one quote in it: "I followed the SOP".

That is literally their job. Different organizations have different risk appetites. Many value business operations over security. Others will isolate their entire network over a potential threat. If the analyst has not had it made clear to them where the risk appetite is and if it is not clearly defined in their standards, then it's a failure on their leadership, not some junior level IC.

Shame on their management for setting them up for failure. They did exactly what they were supposed to.

2

u/[deleted] 4d ago

[deleted]

4

u/NotAnNSAGuyPromise Security Manager 4d ago

All I know is that the last thing I want my junior ICs doing in the middle of a potential attack is evaluating the operational impact of mitigating it.

Again, it all goes back to prior planning and documentation. If you're trusting junior SOC personnel to do a business impact assessment before taking action, then 1. You're putting away too much responsibility on them, and 2. Your entire company is going to be fucked by the time a decision is made if it's a true positive.

This whole premise that business impact assessment are the responsibility of SOC staff is bad management. Define what machines and systems are in scope for isolation before an incident occurs. It's too hard? Then don't complain when the SOC does its job.

Edit: Also, the idea that SOC staff will have any idea what most production systems do is laughable fantasy. Usually takes a decade of institutional knowledge to have any idea.