The CSIRT methodology

The CSIRT methodology

If you have been following my briefings, the article on the C4ISR Methodology will resonate here. Many of those military operational procedures map perfectly onto building a highly functional SOC, CSIRT, and Digital Forensics unit—provided we adapt them correctly. Let’s explicitly define the operational elements: SOC (Security Operations Center) Standard Definition: A centralized unit dealing with organizational and technical security issues. In physical security, it monitors facility access, lighting, and alarms. In IT (often called an ISOC), it is a […]

C⁴ISR: What we can learn from the military

C⁴ISR: What we can learn from the military

C⁴ISR stands for Command, Control, Communications, Computers, Intelligence, Surveillance, and Reconnaissance. Since 2005, I have engineered, reorganized, and optimized Security Operations Centers (SOCs) and Computer Security Incident Response Teams (CSIRTs) for critical infrastructure. This includes deployments for Saudi Telecom, Saudi Aramco, and serving as Global SOC Manager at RadarServices in Vienna, leading up to 30 analysts in a 24/7 “Follow the Sun” operation across three global time zones. What consistently surprised me was the sheer operational chaos within these units: […]