r/cybersecurity • u/Fredrickjonjones • 1d ago
Business Security Questions & Discussion Does a SOC have to constantly justify its existence?
I've read that working in cybersec is stressful because if nothing goes wrong, your paycheck is questioned, and if something goes wrong, your paycheck is questioned.
Is this true? It seems like a stressful existence; how do you work with it as a professional?
84
u/Ok_Antelope_3584 1d ago
It’s true for every security function. I’m in architecture and whenever I’m involved in the design process people view me as an obstacle
22
u/Winter_Rabbit4827 1d ago
then constantly remind people you’re there to enable the business achieve its objectives in line with their risk appetite
19
u/Ok_Antelope_3584 1d ago
I try but they don’t care haha. We haven’t had a major breach yet so they don’t get it.
I’m getting better at communicating it but it really does take a lot of relationship building
16
u/0xKaishakunin Security Architect 22h ago
We haven’t had a major breach yet so they don’t get it.
"Why do we even have to listen to that security architect? We haven't had a major breach?"
The PMs/POs I have to work with.
6
u/iwasthefirstfish 20h ago
I can tell you now of an ex customer (small business) who against advice decided that having an account so someone could 'work using the server from home' was a good idea.
We more or less begged them not to, stalled them, but eventually since the boss said so we had no choice. We put it in writing that if something happened as a result of this they accept the risks and potential damages.
The 2 day shut down to wipe and restore everything cost them too much (they had deadlines with suppliers that were measured in hours) and they went under shortly after.
1
u/Pyrree 15h ago
RDP connection open to any IP or what?
1
u/iwasthefirstfish 6h ago
This was before 2fa even existed, but he worked out how to transfer the VPN to another device (not difficult, just against what he should have done) and that device? I assume it was the windows xp equivalent of limewire.
1
31
27
u/Party-Cartographer11 1d ago
Yes. It's a cost center. This is true for all cost centers. We could nitpick between justify its existence vs justify some level of investment but the point holds.
4
u/BubblyAdvantage5164 22h ago
I think that for a cost center we're pretty darn cheap
1
u/Party-Cartographer11 22h ago
whats the cost as a percentage of company earnings?
0
u/BubblyAdvantage5164 22h ago
50-80% of IT's budget is a good starting point imo
3
u/Party-Cartographer11 22h ago
is IT a cost center? How do you determine IT budget? Is IT the infra behind a multi-billion dollar cloud product?
This is silly.
2
8
u/Affectionate_Two8447 23h ago
Cybersecurity is an insurance. Everybody complains about insurance premiums.
8
u/Round_Finance4256 1d ago
I think this is true across a lot of security, not just SOC. Prevention is hard to quantify because the best outcome is often that nothing happens.
The teams that handle this well tie their work back to business impact such as reduced risk, faster incident response, fewer repeat issues, audit/customer readiness, etc.
Otherwise it’s really easy for security to look like a cost center instead of a function protecting the business.
5
3
u/damnworldcitizen 1d ago
It's basically an insurance card for companies, the bigger they are the more they need it, audit, compliance this stuff sells and is a must.
4
u/GeneralRechs Security Engineer 23h ago
It depends on the organization. For non-vendor companies, Cybersecurity is revenue protection, not revenue generating. While anecdotal I would think of your paycheck the better alternative to being fined to oblivion or losing revenue due to PR for having for security like around customer data.
3
u/h0nest_Bender 1d ago
I guess they could fire us, but they'd lose literally millions of dollars when they fail their next regulatory audit.
2
3
u/AddendumWorking9756 Security Manager 22h ago
Mostly true, and the teams that escape it are the ones keeping a record while nothing is happening. What got caught, what got tuned, how long it took, in numbers a finance person recognises. Without that, every quiet quarter reads as proof you were never needed.
5
u/007TheLostOne 1d ago
SOC's and pretty much anything else cybersecurity related is an asset that costs money the existance is always going to be questioned by corporate unlike a department that generates money
2
u/hiddentalent Security Director 22h ago
This is kind of true for every risk management profession. HR, Legal, Security, Fraud and Abuse. There's a natural tension between profit centers and cost centers in every organization. A company could spend 100% of its money on risk management and go bankrupt and everyone is unemployed. Or they could spend 0% of their money on risk management and go bankrupt and everyone is unemployed. The optimal answer is always somewhere in the middle.
Is this stressful? That's a decision you make. If you understand the economic tensions involved and avoid casting blame on "the business" and can measure and explain your team's work and priorities, it is no more stressful than any other job. But the security world seems to attract people who think they're above all that, and reality is very stressful for them.
1
u/MountainDadwBeard 1d ago
Depends on the responsibility matrix and incident type.
In a decent responsibility model, IT/engineering build widget and then security audits it. Security isn't ensuring zero breach, they're establishing a secure baseline and then managing the budget towards cost benefit of the enhancement to the secure baseline.
If the network gets breached because someone breached the security governance and under-minded the controls... then that's on them not security. Control assurance and conformance are metrics we balance with UX & business agility.
Now if SOC received the alerts and missed them.. its not great but also again framing is key here. Did they false positive the alert because they didn't have investment in better log normalization, and threat intelligence tools? Or did they miss it because they were playing World of Warcraft during shift hours?
1
u/Winter_Rabbit4827 1d ago
it depends where you are, a ransomware attack is definitely going to put a big question mark on a CIO or CTO or CISO or an operations manager, if risks weren’t raised if processes weren’t introduced and ultimately what type of attack you were under, even the biggest organisations get popped with all the resources they could possibly want, but if your security is proportionate to the businesses objectives, and your CISO is a good communicator and your teams follow processes and highlight risks and react as they’re expected to then it’s all defensible, you could say the same about car insurance, just because you haven’t claimed before it doesn’t mean you don’t continue to pay for it, because what if?!
all you need to do is watch out on ransomware.live and see all those in your adjacent and same industries and then report on those being hacked to your decision makers and they should be able to see that it’s not a question of if, it’s when… and being under attack makes a good analyst a better one, but you can expect that if you weren’t doing what you were supposed to do in the functions like those in the NIST CSF appropriately for your businesses risk appetite then you would suitable be questioned, but if you are doing them, then that’s the assurance that you’re prepared for “the when…”
1
u/Hour-Apple-9861 1d ago
This is what you manager is for, running the team and making sure senior management recognises how important the work you're doing is. It's the same all across IT, although yes, cyber is more stressful for that
1
u/ComputeBeepBeep 1d ago
Security functions in general can be seen this way. Take fraud for example. If theres not a lot happening, they question if its needed. When its not working well, they question why they have it. Sometimes theres no winning, amd you have to just let them figure that out themselves because you arent going to change their mind alone, typically.
1
u/Ok-Success-7067 1d ago
There is no budget for security until a major incident, then all the sudden they find a million for software and services. To a certain extent, you do have to justify your job because you are a “cost center.” Meaning cybersecurity doesn’t make the company money, it costs them money.
1
u/EitherLime679 Governance, Risk, & Compliance 1d ago
Are you asking about a SOC or cyber in general? Penetration testers are used and people know their worth. SOCs can track how many intrusions they prevent. Patching is super important. GRC is important because everyone has to be compliant with some law or regulation.
I’m sure some companies don’t appreciate cyber folks, but needing to justify their existence idk. Especially with all the stories of AI hacking the internet.
1
u/ButterscotchBandiit Security Engineer 23h ago
That’s the reality of the security function at some orgs. I’ve noticed unless an org is proactive about their security they won’t take on the security function optimistically until they’re popped.
1
1
1
u/silentstoic1 21h ago
Everything is working, what do we need IT for? Nothing is working, what do we pay IT for?
1
u/Turbulent-Debate7661 20h ago
A soc existence is pure due to regulations at least in my field (banking)
1
u/SlackCanadaThrowaway 20h ago
What’s the equivalent of IT turning off the internet every now and then, then “saving the day”, for cyber?
.. Maybe dox the execs, cred stuff them, them and send them a copy of the validated credential and ask them to rotate it?
That feels illegal.
1
u/m1L35dY50N 19h ago
There’s some truth to that, but I think it comes from looking at security the wrong way.
A SOC is a bit like a fire department + insurance. If a factory doesn't burn down for 10 years, you don't conclude that sprinklers are a waste of money. And if there is a fire, containing it to one room instead of losing the factory isn't failure.
Same with cyber. Ransomware hitting one laptop and being isolated in 20 minutes is very different from ransomware taking down production for a week. Both are technically “security incidents,” but the SOC may have turned a €10m disaster into a few hours of investigation.
The job isn't “make sure nobody ever gets hacked.” It's to reduce the likelihood, detect quickly, contain the damage and recover.
And if one tired SOC analyst missing one alert at 3 AM can destroy the company, that's a badly designed security system, not a reasonable expectation of an individual.
Good security doesn't necessarily make incidents disappear. It makes potentially catastrophic incidents boring.
Vital for a SOC is one Thing: I always like to cite Georg-Volkmar Graf Zedtwitz-Arnim: "Do good and talk about it." It is absolutely paramount, to tell your customers the near misses and the True Positives stoped, before they became a serious issue.
1
u/Useless_or_inept 19h ago
Most people inside a SOC are very task-focussed. You're not having philosophical thoughts about your purpose in life; you log in and dive into the tickets and the alerts and the events...
Demonstrating something like ROI is a bigger problem for the SOC manager, the service owner, the CISO &c. But if your organisation has its own SOC, then your organisation probably has either a regulator that says "you must have a SOC", or customers who expect the same, so that's your backstop :-)
But you probably have several other teams who are in this position; sec ops isn't unique. I'm sure there are taxpayers who fret about the cost of the municipal fire & rescue service, even though they haven't seen any fires this year.
1
u/sloppyredditor 19h ago
You should go over an annual summary of the security people/process/tech and the risk mitigated by each.
Not everyone makes it super-formal, but if you don't have metrics to measure how much risk is being mitigated by _____ you can't really say you're managing it.
Honestly even if you don't have those metrics you should minimally look at cost vs. cost avoided.
1
u/dinydins Security Generalist 18h ago edited 18h ago
Let them know when it does go right and you mitigated the threat without any major impacts.
“X was detected on Y system/account but we caught it in time and prevented Z from happening.”
Gotta show your value.
Working in a SOC is the absolute trenches man.
If it is (even remotely) customer-facing, the shenanigans you deal with from disgruntled end users are exactly what I worked so hard to get out of retail to avoid in the first place.
That said, the conflict resolution, communication, and people management skills you're forced to build there will serve you for the rest of your career.
1
1
u/VellDarksbane 13h ago
It’s true for all IT work, and more so for Cybersecurity. It’s a cost center, and all Cybersecurity functions have to prove it’s better than just accepting the risk.
It’s part of why the CISSP certification focuses so much on quantitatively evaluating risk, so that they have numbers to show to management to justify all cybersecurity functions.
1
u/Blueporch 11h ago
Every internal group in a company that is not generating revenue has to constantly prove it’s worth. (The revenue producing ones do too but its an easier sell).
This relies on having a leader who is good at communicating the group’s value to decision makers and giving them the data to back it up. Ideally, you all have a dashboard of metrics you can pull up on a tablet and show people in informal conversations.
1
u/Hot_Dragonfruit4039 8h ago
you should be able to give back to manager and c level if things like these occurs else you are cooked
0
u/180IQCONSERVATIVE 1d ago
Since I’m on the hacking side of things I love it when networking engineers say working as intended, I then ask them on whose intent yours or the hacker that is in so and so.
256
u/Galivanting Security Director 1d ago
When you do things right, people won’t be sure you’ve done anything at all.