Why Staffing, Processes and Incident Response Matter Most
Cybersecurity technology delivers amazing amounts of raw data to healthcare SOC teams. That technology must be matched with both maturity and flexibility on the human side.
For example, a SIEM alert about a Microsoft PowerShell script running on an Active Directory domain controller could be the first sign of a major problem, or it could be nothing out of the ordinary. To differentiate, the SIEM has to provide context, and context has to come from the organization itself. What’s the identity running the script? Is there a change ticket, even an unapproved one, for this server? Are there other alerts for this identity or this server in the same time frame? Is this a critical system, or is it a lab server someone is practicing on for their next certification?
The alert needs to be turned into an incident, with all supporting information and context, before it’s handed over to an analyst. Without these steps, the analyst can’t make decisions — and must gather that information, manually, in a time-consuming and ad-hoc way.
It’s easy to think that more technology is the solution, but that’s the wrong way to think about the problem. The way out is by augmenting your existing technology such that that the human side can jump on things and solve the problem quickly. If teams are siloed by technology or responsibility, if the workflow of an incident is informal instant messages, if the incident can’t be handled until the right person comes on shift with the right institutional memory, then mean time to respond (MTTR) suffers. IT teams might have the capability to solve the problem, but not the capacity to do it in the time frame that matters.
There’s a quote you hear often when security professionals talk about their alert load: If everything is urgent, then nothing is urgent. Solving the problem of too much noise is critical to the effectiveness of any organization’s security team.
Responding to threats also requires a continuing human feedback loop to the technology. SIEMs and XDRs will generate noise, and that noise gets louder as the world gets nastier. IT teams must feed back into security tools to refine correlation rules, update context information, improve filtering of what they see, and update processes based on lessons learned.
All that takes time and will never be fully automated. That final feedback loop to improve the signal-to-noise ratio requires a commitment by IT management, allocating the right people with the right capabilities and the additional time they need to provide a cycle of continuous improvement.
DISCOVER: Ensure healthcare business continuity when IT fails.
Passing the Test: Is SecOps Operationally Ready?
At its simplest, security operations is a four-step cycle: collect logs, enrich incidents, standardize response and — post-incident — provide feedback to improve tools and processes. Technology makes it possible, but in a supporting role; people and processes drive everything.
IT managers can self-audit to see if they’re balancing technology investment with proper processes and human resources. Is the MTTR for incidents measured in minutes and hours, or days and weeks? Are high-priority alerts enriched enough that an analyst’s first step is deciding how to remediate, or must they waste time cross-referencing logs and configuration databases? Is the workflow for most common problems in a playbook, standardized and tested, or does the response vary based on who’s sitting in front of the console? Are major incidents accompanied by a root-cause analysis that feeds back into tuning and informs the incident playbook?
Building a mature SOC requires a human context, meaning people and workflows that define how threats are identified, handled and resolved. Existing investments in security technology support these workflows. Doing this properly isn’t an overnight job; for example, automation starts with incident enrichment and context, pulling information from identity and access management systems, configuration databases with asset and data criticality, patch history, and internet sources such as known vulnerability lists. Once that’s solid, adding automated response and containment is a great next step.
Technology maturity must be matched with organizational maturity: Teams must be on the same page when it comes to isolating a compromised system or taking down a production server. The time to fight over this is before an incident happens, or in a postmortem review, but not when there's a live incident in progress.
With AI-enhanced attackers everywhere, speed of response is the most critical metric. When a threat can be mitigated by automation, it should be. Security technology provides visibility, but having people and processes in place provides velocity.
