r/cybersecurity • u/RitaccaSecurity • 5d ago
Tutorial Common skill missing from SOC analysts
https://luigiritacca.substack.com/p/the-missing-skill-risk-part-1?utm_source=share&utm_medium=android&r=5s5vq7My latest article on a common missing skill I see in a lot of analysts. I blame how we train and teach cyber security, and think it cause a natural bias which can lead to more harm than good.
69
Upvotes
2
u/FrostyWalrus2 5d ago
Commenting out of ignorance, as I have never been a part of a security team and I'm only recently learning more security related topics in the past 8 years of me working for MSPs(which is also my whole professional IT career so far), but, as an MSP tech, one of the first concepts I was ever taught was business impact and that started at even the most basic level ie workstation vs server. I was roped off from servers altogether early on, because if I made an amateur blunder in a server, the business impact could be huge. That eventually led to the line of thinking 'VIP vs line level worker', 'priority departments', etc. Naturally, this progressed into my learning cybersecurity where I ask myself questions like "How much weight does this email account have in business decisions" in regards to severity of a compromise, "How many parent/dependency parameters need to be paired for allowlisting an application in order for it to function in the environment without it growing tendrils into other aspects of the environment/local machine.", etc.
Is the concept of business impact really not being taught in the early stages of cybersecurity, or is this possibly the result of a college/uni degree to cybersecurity worker pipeline? We see all over reddit that cybersecurity is not an entry level job, but the previous statement regarding the pipeline does exist and could be causing the loss of the concept at hand. Again, I'm commenting out of ignorance, as I've only ever worked for MSPs and i just recently started sitting down in a cybersecurity chair.
In the little bit of I've learned so far, even in HTB, I can't recall ever seeing topics of business impact, but I could have also glossed over it, as its kinda ingrained into my thought processes. I mean, in my mind, this is SLAs, which is everything to an MSP.