What does SOC readiness mean? Whether your organization could notice a threat as it happens and respond in time to limit the damage. A security operations center, in-house or bought as a service, is how most organizations do that. Readiness is about the capability, not the product.

Ten questions to answer first

  1. Do you know which systems, accounts, and data matter most?
  2. Are logs collected from those systems, and kept long enough to investigate?
  3. Would an unusual sign-in or file transfer generate an alert, and who would see it?
  4. Is someone watching at night and on weekends, or does the alert wait until Monday?
  5. Is there a written incident response plan, and when was it last exercised?
  6. Does each alert have an owner and a next step?
  7. Who decides to isolate a system, and can they do it without a meeting?
  8. Do you know whom to call at your insurer, your counsel, and your regulator?
  9. Are your tools overlapping, with several products alerting on the same thing?
  10. Could you show an auditor or insurer evidence of all of the above?

What the answers usually show

Most organizations find the gap is not the absence of tools. It is ownership: alerts that nobody is assigned to, and a plan that has never been tried. Closing that gap is often cheaper than buying more coverage, and it should come before the buying.

Where an advisor fits

Mapping the gaps and choosing what closes each one are advisory tasks. Running a SOC is operational, and usually belongs with a provider. When we do the advisory part, we disclose how we are paid first, and the recommendation is sometimes that your current provider can close the gap. See how we are paid.

For the wider picture, read cybersecurity compliance, simplified and our security and risk advisory. To talk through your own answers, start a conversation.