The Helpdesk is Not a SOC: Why Standard IT Fails Under Fire

The Helpdesk is Not a SOC: Why Standard IT Fails Under Fire

    There is a dangerous and widespread misconception in corporate boardrooms: the belief that a well-staffed, highly competent IT department is inherently equipped to handle a targeted cyberattack. Let me be brutally clear: asking your standard IT helpdesk to fight a professional ransomware syndicate is like asking a commercial airline pilot to fly a fighter jet into combat. They are both sitting in a cockpit, and they both know how to read the instruments, but the mission, the training, […]

Are SIEM’s dead ?

Are SIEM’s dead ?

The SIEM is Dead. And We Killed It. When I first deployed a Security Information and Event Management (SIEM) system back in 2004, it felt revolutionary. Centralized log collection, correlation, and visualization promised a definitive edge in threat detection. But that was an era of limited log sources and rigid perimeters. I warned early on that unbounded data ingestion would eventually choke the system. By 2012, while consulting for a multinational logistics corporation, that nightmare became reality. I was tasked […]

The SOC methodology

The SOC methodology

Take a close look at the SOC workflow extract below. (I have omitted shift handovers and routine administrative tasks to focus on the core mechanics). Remember the fundamental rule: The Security Operations Center (SOC) is built for rapid triage and event processing. If an event is known or structurally simple, the SOC routes it to the responsible operational division (Networking, Server Administration, IT Security). If an event is highly complex, anomalous, or completely unknown, it is immediately escalated to the […]

The CSIRT methodology

The CSIRT methodology

If you have been following my briefings, the article on the C4ISR Methodology will resonate here. Many of those military operational procedures map perfectly onto building a highly functional SOC, CSIRT, and Digital Forensics unit—provided we adapt them correctly. Let’s explicitly define the operational elements: SOC (Security Operations Center) Standard Definition: A centralized unit dealing with organizational and technical security issues. In physical security, it monitors facility access, lighting, and alarms. In IT (often called an ISOC), it is a […]

C⁴ISR: What we can learn from the military

C⁴ISR: What we can learn from the military

C⁴ISR stands for Command, Control, Communications, Computers, Intelligence, Surveillance, and Reconnaissance. Since 2005, I have engineered, reorganized, and optimized Security Operations Centers (SOCs) and Computer Security Incident Response Teams (CSIRTs) for critical infrastructure. This includes deployments for Saudi Telecom, Saudi Aramco, and serving as Global SOC Manager at RadarServices in Vienna, leading up to 30 analysts in a 24/7 “Follow the Sun” operation across three global time zones. What consistently surprised me was the sheer operational chaos within these units: […]