What would be the benefits and drawbacks of giving up my 24x7 Security Operations Center in favor of signing on with a SOCaaS vendor?

2.7k views1 Upvote5 Comments
Sort By:
Oldest
CISO in Softwarea year ago
Many companies have found the ROI higher and the costs lower when switching to SOCaaS as the full time employee staffing costs and retention can be very difficulty in some businesses.  The one disadvantage is that some SOCaaS do not easily have the full environment context, knowledge or experience to provide a holisitc monitoring view of the business. 
1
CISOa year ago
I've run both type of environments.  Before SOCaaS you didn't have any choice but build out a global, follow-the-sun organization.  I wouldn't even consider that today.  Managing a global team of SOC staff is very difficult.  It can be very mundane work that requires a highly skilled person that results in significant turnover.  

When you use an outsourced provider don't just wash your hands thinking they "have it".  It takes a lot of oversight.  Make sure you have your own ability to monitor their activities and output.  I've had instances when they reported everything was OK and when we looked under the hood it was anything but OK.  Keep in mind they are motivated to use minimal resources to increase profitability.  You need to stay diligent on your oversight that the service doesn't slip over time.

I'll typically use them for level 1 and 2 problem/alert handling and level three would be insourced on my staff.   It often takes internal knowledge on how the systems work and the criticality of the system to properly diagnose and eradicate the threat as needed.

Hope this helps.

Best Regards,
James
3 1 Reply
Chief Information Security Officer in Healthcare and Biotecha year ago

Thanks for posting this. We are considering a SOCaaS as it would be impossible for us to be able to afford and find staff to do it on our own. We are healthcare and there is one SOCaaS that receives high marks from other health orgs that use them. Hoping we can pull the trigger on hiring them as this is a real blindspot for us.

2
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
CIO in Governmenta year ago
As a local government, we have access to MS-ISAC’s SOC for free. Funded by DHS. Naturally, they have thousands of members, and overload is a concern, but it has worked for us so far. We could never staff one ourselves. 
Chief Information Security Officer in Healthcare and Biotecha year ago
Benefits:
1. No need manage the cyber Security talent and retention.
2. Cost is less for small set up.
3. Basic standards can be achieve quickly.

Disadvantage: 
1. Business fraud risk can't be managed by SOCaaS.
2. Customisation will be challenges always.
3. For BFSI regulatory issues can come up.   
 

Content you might like

IT Manager in Construction5 days ago
Hello,
I had a look and it seems available for free can be easily find European and global market but there are a bunch of company with commercial reports for UK. I will search more.
2k views1 Comment

TCO19%

Pricing26%

Integrations21%

Alignment with Cloud Provider7%

Security10%

Alignment with Existing IT Skills4%

Product / Feature Set7%

Vendor Relationship / Reputation

Other (comment)

View Results
5.7k views3 Upvotes1 Comment
Head of Enterprise Architecture MERCK Group in Healthcare and Biotecha year ago
Strategy & Architecture
Read More Comments
39k views5 Upvotes34 Comments
CISO in IT Services7 days ago
look for Plaid I know I looked at them last year
925 views1 Comment

Human Factors (fears, mental health, physical spacing)85%

Technical / IT Factors (on-premise tools, pivoting back away from remote)14%

3.7k views3 Upvotes2 Comments