
In the first of two articles, Richard Orange at Exabeam makes the case for modernising Security Operations Centres
Organisations across every sector of the modern connected economy have built Security Operations Centres (SOCs) to keep their infrastructure operating effectively and without the huge disruption and costs associated with a breach. Whether it’s protecting against insider threats, data exfiltration attempts or malware attacks, the SOC is there to detect, investigate and remediate and return systems to their fully functional, secure state.
Examining some of the issues that occur on a daily basis within many SOCs, however, reveals a worrying set of challenges that are putting the work of SOCs – and the committed professionals that run them – under increasing pressure. They also highlight a fundamental requirement that SOCs everywhere must address if they are to keep pace with the challenges they face – the need for modernisation.
In the contemporary SOC, there is a pervasive mentality focused on ‘logging everything’. This is driven by a range of factors, with compliance playing a major role in shifting the mentality to log all data – even if it’s not useful.
As a result, many organisations are now working with hyperscalers to log and store all the data in their environment, without necessarily knowing how they will draw insight from that data. This ‘store now, use later’ mindset, however, ignores some crucial questions that security teams should be asking in advance:
Without the insight that answering these questions will bring, the blinkered ‘log everything’ approach almost inevitably creates a massive scale challenge. Granted, it’s great to be able to look back at all the data during an incident, but organisations should also consider the cost of storing that data – and more importantly – the ability to analyse and use it effectively.
Security teams everywhere employ an array of tools that are significantly adding to the levels of technical and operational complexity they must contend with on a daily basis. Indeed, many have layered SIEM on top of SIEM, often frustrating their efforts to create useful insight into security trends and incidents.
The result is security teams have a multitude of different data points and systems that they must log into – then, when they look at the data, nothing is consolidated.
There are several reasons why these organisations have become saturated with SIEMs. Some will have been bought to address tactical objectives around specific applications, which over time create technical debt in the SOC. Others are inherited through acquisition. It is not uncommon, for instance, for today’s most acquisitive businesses to have purchased 50+ companies over a 5-year period, most of which will have some sort of SIEM in place already.
Exacerbating this issue is the move to the cloud. Many organisations now have an environment split down the middle, half in the cloud and half on-premises. Because both environments are very different, many organisations have developed two distinct security strategies – with two security organisations looking at multiple tools. The problem is, very few tools are bridging this infrastructure gap.
In this context, security teams must decide how to manage risk in a newly acquired company’s SOC. Lots of the traditional tooling is very slow to deploy, so identifying risk quickly – without slowing the business down – is a significant challenge.
For an organisation that has acquired several businesses, it’s virtually impossible to understand them well enough to have one SIEM with different correlation rules for each part of the different business, particularly given individual cultures and business practices.
There is also a common perception that it will take too much time, be too expensive and increase the risk to rip and replace existing SIEMs. This can be the case for SIEM inherited through an acquired business, but also for an existing SIEM within the same business.
Complexity is at the core of both perceptions. Some businesses may be in year two or three of a SIEM deployment and are yet to see any ROI. This creates the perception that, since they have spent so much already, pressing ‘reset’ would be a waste of time and resources.
Compounding this further are considerations around resourcing. In both situations, the SOC team will have been built around the SIEM deployment(s), with training and certifications geared specifically towards the incumbent technology. Pressure from vendors or partners – with assurances that eventually the technology will deliver what they need – can also influence the decision not to take a modernisation approach.
Responsibility for broader security modernisation – including SOC modernisation – is increasingly distributed across the organisation. As Gartner explains, “The scope, scale and complexity of digital business make it necessary to distribute cyber-security decisions, responsibility, and accountability across the organisation units and away from a centralised function.” C-level executives that are not in cyber (CFOs, etc) increasingly have cyber-risk as part of their KPIs and job specs.
In many ways, the increased visibility of cyber-security at the board level is a positive shift, transforming how security is perceived, democratising it across the organisation, and making the broader organisation accountable.
The inherent challenge in this shift, however, is how the CISO and security team manages the new political landscape for security within the organisation – balancing reducing risk against reducing cost.
In the current situation – logging more data, with multiple SIEMs delivering limited insight – SOC teams are struggling, spending huge amounts of time, and getting nowhere. With a broader set of additional stakeholders involved, true modernisation is becoming increasingly challenging. It’s viewed as too expensive, and organisations are reluctant to invest in additional tools to run on top of their existing infrastructure when the tools they have already invested in are not delivering what they need.
Richard Orange is VP of EMEA at Exabeam. In his second article, to be published next month, Richard considers the key SOC stakeholders and the importance of their perspectives in building a modern security strategy
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543