Review your SOC: boosting efficiency and response
Fujitsu / July 24, 2024
In today's rapidly evolving threat landscape, organizations must adopt a proactive approach to cyber security. An effective strategy for a robust security posture is ensuring close collaboration between the Security Operations Center (SOC) and the broader security team.
One of the things I find surprising in some organizations is the engagement of the security lead with the SOC. The daily operation of the SOC is often presented as dashboarded data and more unusual or worrisome incidents get called out, but on the whole the security lead is often too distant from the SOC. I find it hard to understand why, particularly as within my role I review my SOC's casework weekly and couldn't do without the insight that I get from that 90 minute meeting with my team.
I am lucky enough to have a direct relationship with my SOC but note that even if you buy SOC services from a third-party you should still be able to push for a relationship with the SOC team!
In this blog, I will explore why I value it so much.












