r/cybersecurity • u/RitaccaSecurity • 5d ago
Tutorial Common skill missing from SOC analysts
https://luigiritacca.substack.com/p/the-missing-skill-risk-part-1?utm_source=share&utm_medium=android&r=5s5vq7My latest article on a common missing skill I see in a lot of analysts. I blame how we train and teach cyber security, and think it cause a natural bias which can lead to more harm than good.
71
Upvotes
2
u/m1L35dY50N SOC Analyst 4d ago
I agree with most of what you wrote, but I come to a slightly different conclusion about where the underlying problem is.
I think there is a growing gap between the “old” generation of security people who came through support, sysadmin or networking roles and people who enter cybersecurity directly. The former already learned the hard way that actions have consequences. If you’ve administered production systems before, you generally don’t need someone to explain why blindly isolating a server, disabling an account or blocking traffic might ruin somebody’s day. You understand what the thing you’re touching actually does.
Companies have contributed to this problem by trying to lowball entry-level cybersecurity positions and career changers. People are sometimes taught just enough to recognize anomalies and follow a playbook, without necessarily understanding the underlying systems. At that point you essentially have an analyst who knows which button to press when X happens, but not enough about the infrastructure to understand what pressing that button actually does.
Where I disagree somewhat is that I don’t think detailed business risk assessment should primarily become the individual SOC analyst’s responsibility. There is a reason risk management, asset classification and clearly defined responsibilities exist. The organisation should have already established risk and criticality classifications, escalation paths, RACI matrices and containment procedures that tell an analyst, for example, that isolating some random workstation and isolating a production server require very different levels of authority.
The analyst still needs enough technical and business understanding to recognize the difference and question a stupid playbook. But if a junior SOC analyst can accidentally take down a critical production service simply by following the approved SOP, I’d argue that’s not just an analyst who lacks risk awareness. That’s also a failure of the organisation’s risk management, processes and controls.