Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Podcasts
    • Photo Galleries
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementTechnologies & SolutionsSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

The way forward with Risk Operations Centers

By Atul Vashistha 
Creating the GSOC: 4 Leading Examples of Successful Security Operations Centers
July 31, 2020

In recent years, Enterprise Risk Management has become increasingly focused on cybersecurity risks. In a pre-COVID 2019 survey report by Harvard Business Review (HBR) Analytic Services and pwc, survey respondents were asked what the CISO/cybersecurity leader’s principal responsibilities should be in the next three years. The top two responses were to build an organization-wide cybersecurity culture (63 percent) and formulate strategy for cybersecurity (51 percent). Next, tied with build and maintain threat-resistant systems, was work with the risk management function to integrate cyber risk with broader risk strategy (47 percent).

While this focus on cyber is understandable, the current COVID crisis has demonstrated that the unpredictable nature of cascading risks requires viewing risk through a much wider risk aperture. One way forward to successfully navigate this new risk frontier is the establishment of a Risk Operations Center (ROC). The ROC enables enterprise and technology leaders to have the continuous monitoring they require to proactively mitigate all cyber issues. Additionally, it fully supports the CISO/cybersecurity leader's principal responsibilities identified by the HBR survey.

 

Why cascading risks require a wider risk aperture

It's important for enterprise risk and technology leaders to consider risks that go beyond a singular cyber focus. As the current pandemic progressed, we witnessed many location events quickly cascading into financial and people risks before becoming significant technology and cyber issues.

For instance, the original location-based Wuhan epidemic risk quickly spread around the globe and cascaded into absenteeism risks and regulatory risks as governments enacted massive shutdowns. The shutdowns resulted in an unprecedented and previously unimagined rapid shift to work from home. This shift resulted in considerable technology and cybersecurity challenges, including technology and hardware shortages, poor internet bandwidth, the volume of remote logins and increased cybersecurity risks related to remote work. Looking forward as this crisis is prolonged, more suppliers' financial stability will be under threat. As a result, solutions maturity risks will increase that could result additional technology and cyber susceptibility issues.

Staying ahead of the curve requires continuously monitoring a broad risk framework that includes location-based risks like epidemics, natural disasters and social unrest as well as third-party risks like people, financial, solutions maturity, governance, regulatory and compliance risks. But it's not enough to anticipate what's coming next - enterprises need the structure to proactively act on this intelligence in order to effectively mitigate business disruption risks.

 

Presenting the Risk Operations Center (ROC)

The ROC proactively stays ahead of cascading risks by continuously monitoring for changes across the enterprise’s entire risk landscape.  But it also assesses the potential impact, identifies risk mitigation actions, tracks incident resolution and identifies risk trends. As the risk landscape changes, it can be staffed up or down as needed but is always active, capturing real-time risk intelligence, fully prepared and ready to act proactively to enable faster, more effective risk mitigation responses. 

The ROC is comprised of four components: the Risk Intelligence Monitoring Post to continuously collect real-time risk intelligence, a Workflow Tool to route relevant information to the right people, the Response Center to assess the intelligence for relevance and trigger internal and external actions, and a Feedback Loop to track risk mitigation actions until incident resolution. The ROC is staffed through a combination of technology, tools, analytics and people.

Within the ROC's Response Center, multiple specialized workstreams are assigned different areas of responsibility such as incident progression, workforce, technology, location, finance, authority, facility, third party and communications. This specialization creates subject matter experts with unique strategic insights. The workstreams communicate with each other and across the enterprise's business functions to share relevant risk intelligence, risk trends, anticipated cascading risks, expert guidance and risk mitigation action steps for both third-party and internal responses.

 

ROC benefits for CISO and technology leaders

In the same 2019 HBR/pwc survey report, the respondents were asked which leadership skills are most important for the success for CISO/cybersecurity leaders. Ranked most important was the ability to educate and collaborate across the business (84 percent), followed by the ability to communicate (82 percent), and tied for third the ability to make data driven decisions/take smart risks and strategic insight and ability (79 percent). All of these critical leadership abilities are supported by the ROC.

At its very core, the ROC functions to enable communication across the business functions for risk education and mitigation collaboration. As a result, integration of cybersecurity culture into the broader risk strategy should be a given. The ROC identifies the risks and provides risk intelligence and strategic insight. Security and technology leaders can thereby focus their attention on risk mitigation strategies and actions instead of risk identification. A ROC provides the risk intelligence and strategic insights that enterprise and technology leaders will need to successful navigate the challenges of ever-increasing security threats and risks.

KEYWORDS: COVID-19 cyber security information security operational security risk management Security Operation Centers

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Atul vashistha

Atul Vashistha is recognized globally as a leading expert on globalization, governance, and risk. He has authored three best-selling books: The Offshore Nation, Globalization Wisdom and Outsourcing Wisdom. Atul pioneered the global sourcing advisory space in 1999 when he founded Neo Group and is also founder and Chairman of Supply Wisdom. Founded in 2012 as an early warning service for business disruption risk, today, Supply Wisdom® is the market leading patented real-time and continuous risk intelligence and monitoring solution. Atul serves on the  boards of the US Department of Defense Business Board (Vice Chair), IAOP, Shared Assessments, and Zemoga.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

The Lourve

The Lourve Heist: What Was the State of the Museum’s Security?

The 2025 Security Benchmark Report

The 2025 Security Benchmark Report

Office supplies

Security Leaders Share Why 77% Organizations Lose Data Due to Insider Risks

American Airlines

Security Leaders Discuss Cyberattack on American Airlines Subsidiary

Going Down with the Ship

Going Down with the Ship

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

November 13, 2025

Inside the 2025 Security Benchmark Report

The 2025 Security Benchmark Report unveils the top trends CSOs and enterprise security executives are facing in today’s current climate and how each of these trends could potentially impact the enterprise’s global reputation with the public, governments, and business partners. 

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • ransomware cyber

    Security’s new standard: Always-on protection and prevention

    See More
  • kubernetes-freepik

    The way forward for Kubernetes security: Eliminate standing privileges

    See More
  • Cybercrime on the rise: Plotting a way forward

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Risk Analysis and the Security Survey, 4th Edition

  • operations center.jpg

    Security Operations Center Guidebook

See More Products

Events

View AllSubmit An Event
  • December 3, 2024

    The Ultimate Two-Way Radio Webinar

    ON DEMAND: In this webinar, you will learn about the different radio communications solutions and the latest innovations. 
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing