Sitemap

Automated SOCs — Musings from Industry Analysts (and Ex-analysts)

9 min readMar 21, 2021

--

Press enter or click to view image in full size
Figure 1 — Typical phases of threat detection, investigation, and response in SOCs
Press enter or click to view image in full size
Press enter or click to view image in full size
Figure 2 — Tactical maturity model and metrics for SOCs based on speeds and feeds — timing, log ingestion and volume
Press enter or click to view image in full size
Figure 3 — Content for end-to-end, full lifecycle of a use case
Press enter or click to view image in full size
Figure 4 — Proper maturity model based on outcomes, use case complexity and coverage

--

--

Gorka Sadowski
Gorka Sadowski

Written by Gorka Sadowski

30+ years in cybersecurity | Former Gartner, Splunk, Exabeam exec | Board Advisor to startups | Exploring Board of Directors opportunities