Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementPhysicalSecurity NewswireCybersecurity News

4 Trends for Building and Operating a Security Operations Center

SEC0119-Cover-Feat-slide1_900px
April 28, 2020

Mimecast Limited, email and data security company, released the latest report from the Cyber Resilience Think Tank (CR Think Tank) highlighting four trends for building and operating a Security Operating Center (SOC). In the report titled, Transforming the SOC: Building Tomorrow’s Security Operations, Today, CR Think Tank members weigh the benefits and challenges of keeping a SOC in-house versus outsourcing it. The group also lays out key actionable tips to build a successful model for any size organization.

The CR Think Tank agreed that what works for one organization may not work for another and has identified the following trends as key factors to consider when building out a strategy for your organization:

  1. The human element - upskilling is key
    While the skill gap is clearly a challenge and it seems unlikely that any organization will be fully staffed, the shortage does reveal an opportunity to upskill companies’ existing workforces through training academies or job rotations. “The primary driver for us are skills,” said Claus Tepper, head of cybersecurity operations Absa Group. “And I think South Africa is, as everywhere else, fundamentally challenged to getting the right people on board.” To solve for that, Absa jumpstarted an academy to develop and train talent recognizing that it takes years for a team to become fully SOC-efficient.

    In the report, all Think Tank members highlighted the importance of ensuring SOC analysts and engineers are tuned into the company’s cybersecurity strategy, business processes and overall business. Malcolm Harkins, Chief Security and Trust Officer at Cymatic, believes team structures can help with upskilling: “I believe structure drives behavior,” Harkins said. “We’ve had creative ways of getting people out of their day jobs, such as job rotations between teams, and factory tours for security and management at just the cost of time and travel, because when people understand the criticality and unique needs of a function, they’re usually impressed.”
     
  2. In-house versus outsourced – relationships matter
    Dependent on business needs, 3rd party providers, like in other areas of the business, can be extremely valuable or, conversely, hinder progress.

    When an outsourced relationship becomes a cyber security partnership, an external SOC team can be a key partner in addressing issues and shaping the organization’s long-term security needs. However, a lack of physical presence in the office can cause miscommunication or trust issues, which are detrimental to the business.

    CR Think Tank members highlights, that no matter if the SOC team is internal or external, the onus is on the CISO to showcase the SOC team’s value. As that team function is not often seen as a core competency, building relationships with the senior executive leadership team will ensure CISOs have what they need for success.
     
  3. Technology and automation – avoid the security chase
    Automation has the potential to transform the life of a SOC analyst. Notably by increasing productivity and decreasing Mean Time to Resolution (MTTR). The experts recommend building automation into every project to make it part of the organization’s structure. When it is thought about early on, automation becomes a natural part of every process. Shawn Valle, Chief Information Security Officer at Rapid7 agreed, stating: “Software developers build based on APIs, and then build UI on top of APIs, which is worthy of exploration in SecOps teams. That strategy of building automation from the beginning, we believe, makes analysts stronger and better versus using fewer people.”

    The report highlights the potential of automation in the SOC but does warn against the over-use of it as it can make an organization’s actions easier to predict and therefore more vulnerable to threat actors. “Automation itself is a form of vulnerability,” said Sam Curry, Chief Security Officer at Cybereason. “You have to check your blind spot at pseudo-random intervals to see who’s hiding there because the machine will become predictable and therefore exploitable. So, the mission is not to automate for the sake of it, but to make the humans more effective, improving the value of their output without weakening the whole.”

    The CR Think Tank agreed that business and security need to be in lockstep to be proactive whenever possible and avoid the security chase.
     
  4. Processes and Efficiency – seating plans as the key to success?
    Finally, the report highlights the importance of physical proximity when dealing with tech teams.

    Seating location within an office can make a big difference - many companies opt to put their tech and security teams next to each other to foster creativity, agility and better communication. For example, seating SOC teams next to the product team can improve efficiencies in terms of how they iterate and build new tools. However, for employees who work remotely, communicating with internal teams frequently to ensure alignment on priorities and objectives is key.

No matter what an organization’s SOC setup is, the most important factor is relationships, notes the report, and SOC teams, whether internal or external, need to be invested in the organization’s mission and its core targets. With talented individuals in short supply, training, upskilling and using technology for efficiency gains are key to transform your SOC team, says the CR Think Tank. 

Download the full report: Transforming the SOC: Building Tomorrow’s Security Operations, for more insights from the CR Think Tank.

KEYWORDS: cyber security outsourcing risk management Security Operations Center (SOC)

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • security leader salary

    Building a security operations center (SOC) on a budget

    See More
  • How the Security Operations Center Can Create Customer Confidence

    4 Trends Driving Security Operations Centers

    See More
  • University of Central Florida Police Department

    Building a Permanent Emergency Operations Center at UCF

    See More

Related Products

See More Products
  • operations center.jpg

    Security Operations Center Guidebook

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Physical Security and Safety: A Field Guide for the Practitioner

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing