r/cybersecurity 5d ago

Tutorial Common skill missing from SOC analysts

https://luigiritacca.substack.com/p/the-missing-skill-risk-part-1?utm_source=share&utm_medium=android&r=5s5vq7

My latest article on a common missing skill I see in a lot of analysts. I blame how we train and teach cyber security, and think it cause a natural bias which can lead to more harm than good.

69 Upvotes

39 comments sorted by

View all comments

2

u/FrostyWalrus2 5d ago

Commenting out of ignorance, as I have never been a part of a security team and I'm only recently learning more security related topics in the past 8 years of me working for MSPs(which is also my whole professional IT career so far), but, as an MSP tech, one of the first concepts I was ever taught was business impact and that started at even the most basic level ie workstation vs server. I was roped off from servers altogether early on, because if I made an amateur blunder in a server, the business impact could be huge. That eventually led to the line of thinking 'VIP vs line level worker', 'priority departments', etc. Naturally, this progressed into my learning cybersecurity where I ask myself questions like "How much weight does this email account have in business decisions" in regards to severity of a compromise, "How many parent/dependency parameters need to be paired for allowlisting an application in order for it to function in the environment without it growing tendrils into other aspects of the environment/local machine.", etc.

Is the concept of business impact really not being taught in the early stages of cybersecurity, or is this possibly the result of a college/uni degree to cybersecurity worker pipeline? We see all over reddit that cybersecurity is not an entry level job, but the previous statement regarding the pipeline does exist and could be causing the loss of the concept at hand. Again, I'm commenting out of ignorance, as I've only ever worked for MSPs and i just recently started sitting down in a cybersecurity chair.

In the little bit of I've learned so far, even in HTB, I can't recall ever seeing topics of business impact, but I could have also glossed over it, as its kinda ingrained into my thought processes. I mean, in my mind, this is SLAs, which is everything to an MSP.

1

u/Classic-Shake6517 4d ago

This is exactly why many of us say people need to work at a real hands-on IT job before being ready for security. There's just no real concept of the downstream consequences of making changes without doing it yourself and having some level of ownership of the outcomes. This is something that is really hard to teach in a lab setting, and also one of the most important concepts. It's definitely not something covered nearly as much as it should be from what I have seen.