Many organizations are investing in their security operations centers (SOCs), but most SOCs still experience performance issues, according to the second-annual "SOC Performance Report" from data analytics and security company Devo Technology.
Key findings from Devo's report include:
Although many organizations recognize the importance of SOCs, 78 percent of IT security practitioners said working in the SOC is "painful," the Devo report revealed.
Poor Visibility, Silo Issues Hinder SOC Performance
The Devo report highlighted some of the biggest SOC pain points, such as:
In addition, the Devo report revealed the following factors may limit SOC efficiency:
Most IT security practitioners believe automating security analyst workflows and implementing advanced analytics or machine learning would help improve SOC performance, according to the Devo report. These capabilities enable SOCs to eliminate repetitive tasks and reduce security analyst workloads.
What Is a Highly Effective SOC?
The Devo report indicated there are several factors that define a highly effective SOC, including:
Highly effective SOCs have organizational support and resources to fuel their operations, the Devo report showed. By investing in their SOC operations, organizations are better equipped than ever before to help their SOCs quickly identify and address cyberattacks.