Companies are increasingly exposed to cyber attacks, but there are solutions to ensure and preserve confidential data. Security is a process, requiring digital transformation, a change in awareness that implies that reactive action with mutually unrelated technological solutions is no longer sufficient. Cloud-based analytics, monitoring, and correlation of information along with automation and orchestration is the path to achieving this goal. Setcor, as a company specialized in secure cloud, is in an ideal position to apply the awareness and expertise gained through years of specialization in cybersecurity to each of our users through a new managed SOC as a service, explains Vedran Vujasinović, Head of the Cybersecurity Department at Setcor.
As Vujasinović states, more and more companies are seeking solutions in specialized Security Operations Centers (SOC) which are recognized as a key measure for effective protection against cyber attacks. A Security Operations Center is a centralized unit that addresses security issues at both organizational and technical levels, integrating all available technological solutions, people, and processes. It is a central place from where security analysts monitor the security situation 24/7, conduct investigations on assigned cases, classify alerts, prevent and resolve security threats using technology, expertise, and accepted processes to arrive at a concrete solution to the situation.
– As a primary goal, the SOC is tasked with preventing attacks at this stage for the largest number of threats through early detection, i.e., indicators of possible malicious activity enriched with contextual information, so that the secondary goal of monitoring intrusions and eliminating threats, known as malware hunting which has found its way into the user’s local infrastructure, can be conducted for a smaller number of critical events that can be managed – as they often imply rebuilding part or all of the systems from scratch or from backups, thus causing unavailability and damage. For this to be achievable, the SOC must have visibility of all security events and incidents from the moment of arrival to all boundaries of the company, whether through the employee’s endpoint, email, internet, or cloud applications, and through monitoring further lateral movement through the local infrastructure. Once the SOC receives all necessary alerts and integrates with all key control points, it arrives at information that describes the event, i.e., the context around each alert. Through analysis, we arrive at a precise and concrete context based on which it is possible to conclude whether it is a critical alert, a new threat that poses a risk, or something irrelevant to the user’s environment, and based on that we can conclude whether to open a detailed investigation or close the incident. With rapid detection and focused response, it is possible to prevent most threats, reduce downtimes and risks to IT systems – explains Vujasinović.
