Why people are key to successful security operations centres
Don’t rely on technology alone, say telecoms cyber chiefs
Talented people and proper processes are more important than technology when it comes to running a successful security operations centre (SOC), delegates at Infosecurity Europe 2017 in London were told yesterday.
Emma Smith, technology security director at Vodafone, said that organisations should not get "swept up" in the flood of tools hitting the market.
She said that process, behaviour and culture can deliver "more bang per buck" that technology ever could. Smith added that it was more important to "attract and retain the right people".
A clear career path offered by firms was key to attracting the right people to an IT organisation, she said.
Close Brothers CISO Chris Gibson if organisations gave people interesting jobs it would "keep them interested".
O2 Telefonica director of business operations, Adrian Gorham said that having the right processes in place was vital to managing an effective SOC, as the operations centre cannot run in isolation from other parts of the organisation.
Gorham said such an operations centre "monitors and picks up alerts" but needs good relationships with the rest of the business and this also means needing to "work with business analysts and system architects".
Head of information security at the London Metal Exchange, Russell Wing, said that an SOC needed the right metrics in place as well as response processes to quickly close down any attacks. He added that you "cannot secure what you don't measure" and what "happens in your environment you need to know".
What you need to know about migrating to SAP S/4HANA
Factors to assess how and when to begin migrationDownload now
Your enterprise cloud solutions guide
Infrastructure designed to meet your company's IT needs for next-generation cloud applicationsDownload now
Testing for compliance just became easier
How you can use technology to ensure compliance in your organisationDownload now
Best practices for implementing security awareness training
How to develop a security awareness programme that will actually change behaviourDownload now