Part III · Chapter 16

SOC and IRT, detection and response

An attack nobody detects continues until the attacker chooses to show themselves. Detection and response decide whether an incident becomes a disruption or a disaster. This chapter sorts out the difference between a SOC and an IRT, works through what a security centre actually does, and takes on the question every organisation faces, whether the capability should be built or bought.

  • CISOs and security leads

Last reviewed

The time from intrusion to detection is still measured in weeks rather than hours at many organisations. Three weeks is not unusual. During that time the attacker moves freely through the environment, maps it, escalates privileges, extracts data and prepares what eventually becomes visible to everyone. This chapter is about shortening that time, and about what it costs to do so.

It begins by separating the SOC from the IRT, the continuous monitoring from the function that takes over once something has actually happened. They are often conflated, with the result that neither role is done properly. Then follows a review of what a security centre does in practice, beyond the marketing descriptions, and a maturity model that makes it possible to place your own capability on a scale rather than guess. After that comes the centre of gravity of the chapter, the choice between building in house, buying as a service or combining the two in a hybrid, with the trade offs in cost, competence supply and control that belong to each. The IRT is treated separately, with questions of staffing, structure and readiness outside office hours. One section works through what the Cybersecurity Act actually requires on detection, which is less specific than many assume but binding nonetheless. Another deals with sizing, matching the capability to the real needs of the operation rather than to the level of ambition. What happens once an alert is confirmed is covered in chapter 17 on incident response, and who you are defending against in chapter 2.

The question has been sharpened by the reporting requirements. An organisation that has to give early warning within 24 hours must first have detected that something is under way, which assumes a capability that cannot be improvised during the incident itself. Whoever buys the service still needs to be able to receive an alert and decide on action, and that is a capability that cannot be outsourced.

This page shows what the chapter covers and why detection and response belong together. The maturity model, the decision model and the sizing are in chapter 16 of the book.

Detection without response is worthless. Response without exercise is wishful thinking.

Key insights

  • A SOC detects, an IRT handles. Confusing the roles means neither of them gets done properly.
  • Detection without a decided response process yields logs of how the damage occurred, not less damage.
  • The choice between in house capability, bought service and hybrid is decided by size and requirements, not by ambition.
  • Capability should be sized against the need. Round the clock monitoring nobody can act on is the wrong investment.
  • Exercise is what separates a plan from a capability.

Tools that belong to this chapter

The templates and interactive tools are in the Toolbox, free of charge.

Read on

Next step

Where does your organisation stand?

The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.