Nearly six in 10 security operations center (SOC) analysts spend most of their time handling ransomware and supply chain attacks that often result in a full-on ransomware attack, Cybereason said in a new study.
Four Focus Areas for SOCs
As a result, SOC modernization plans now focus on four areas, all impacted by ransomware:
In a new Cybereason survey, roughly half (49%) of 1,203 security professionals from eight countries and 12 industries said ransomware is the most common incident type they deal with daily, followed closely by supply chain attacks (46%). Some 37% said daily alerts consumed most of their time, and 31% identified targeted attacks as a top daily concern.
Commenting on the findings, Lior Div, Cybereason chief executive and co-founder, said:
“In a post COVID world, the modern SOC needs to be a decentralized, capabilities-based organization that leverages industry-leading detection, prevention, visibility, and automation technologies, all of which are often augmented by managed services.”
A Deeper Dive into the Study
Here are some additional findings from the research:
On resolving an incident:
On alerts:
On how ransomware has influenced SOC skills:
On industries that need better insight into attack story:
On response time: