SlideShare a Scribd company logo
2
Most read
19
Most read
23
Most read
Future of SOC: More
Security, Less Operations
Dr. Anton Chuvakin
Office of the CISO, Google Cloud
March 2024
https://medium.com/anton-on-security
https://cloud.withgoogle.com/cloudsecurity/podcast/
Inspiration!
[In 2024] “you can’t “ops” your way to
SOC success, but you can “dev” your way
there”
-- Dr. Anton Chuvakin (source: “Kill SOC Toil, Do SOC Eng” blog)
So, which lessons does your SOC need? Operations
excellence or development success?
Outline
● SOC, a reminder
● Do we have to SOC, really?
● SOC automation: the ultimate in “easier said than done”
● SOC or “SOC”?
○ Do we have to engineer anything?
● AI will come and save us… right? RIGHT?
● Recommendations
SOC, SecOps, Security
Operations Reminder
A security operations center provides
centralized and consolidated
cybersecurity incident prevention,
detection and response capabilities.
–Gartner
A Classic SOC View!
SOC is first a TEAM. Next a PROCESS. And it uses TECHNOLOGY too.
“We don’t have enough
skilled engineers to
make everything work”
“Our processes are too
manual, we are too slow
to respond to and
remediate threats”
“We struggle to build
effective detection and
have too many false
positives/negatives”
2003 or 2023? Sec Ops is Ripe for Transformation
“We can’t store and
analyze all data,
resulting in blindspots”
“It takes too long to
investigate alerts”
“It’s cost prohibitive to
ingest all the data we
need”
07
This is How 20+ Years of Progress Look Like! :-(
Organizations were
notified of breaches by
external entities in 63%
of incidents
(Mandiant M-Trends 2023)
Know anybody who does not have
those problems?
Yeah, that’s us :-)
You think you want to know
just how Google does
Detection and Response?
WARNING FOR THOSE
VIEWING ON SLIDESHARE:
NEXT SLIDE IS SKIPPED
Your SOC DNA?
1990s NOC and Help
Center
Security Engineering
Team
Secret 1: Why There is No Door
that Says “SOC” at Google?
It is because of the letter “O”..
… just like “IT Operations” SRE
Q: Would you rather write
threat detection rules in Python
or in Go?
A: Eh…. no?
SRE, DevOps and Modern IT
Future of SOC: More Security, Less Operations
Problem What does Google do? What do most enterprises do?
Efficiency Automation/SRE is a mindset – part of the hiring
process, part of OKRs, and performance reviews
Experimenting with SOAR, full adoption is
tough due to minimal automation culture
Employee
Shortage
Requires coding interviews, attracts the best,
invests in growth
Hires traditional roles, no coding, outsources,
less growth, more stress
Employee
Burnout
40/40/20 between eng, operations, and learning Utilization is almost always >100%
Expensive Investment in efficiency solves for human costs Cost-prohibitive data ingestion, oftentimes
paying SIEM and DIY, increasing cost from
complexity
Efficacy Intel strongly embedded in D&R, mostly utilized
towards proactive work, strong collaboration
across teams & benefits from developer hygiene
CTI team produces great reports, SOC
consistently doing fire drills, >90% false
positive rate, uneven distribution of skill (Tier 3)
Google D&R vs Enterprise “SecOps”
Increase overall tooling footprint
1 Eliminate toil
Embrace change
2
Strive for continuous improvement
3
Bridge all siloes
4
Use service level objectives
5
Avoid hero mentality
6
7 Aim for simplicity
Should:
Restrict hiring to top professionals
Require an engineering-only culture
Aim for only incremental gain
Autonomic
Modern
Security
Operations
Principles
1
2
3
4
Should not:
1 Reduce toil
Create an automation queue
Implement blameless postmortems
Conduct Weekly Incident Reviews
Implement SOAR
Hire Automation Engineer(s)
Train your team on toil and
automation
Implement CD/CR pipelines with metrics
Key activities to reduce toil
02
03
04
05
06
01
07
● Analyst utilization gets optimized
● More creative work, less toil
● Time back to do more proactive
work
● Deeper operationalization of intel
● SecOps can scale with the
business!
Evolve Automation
10X is an Underestimate!
Three phases of SecOps transformation
Tactical
Carries a sense of
urgency and immediacy.
A cautious way of saying
“we’re in trouble and
need an immediate fix
before we go down in
flames.”
Often implies a 3-5 year
vision and a roadmap
how to achieve that
vision.
A major change that
completely reshapes
the organization in
response to, or
anticipation of,
significant changes in
organization’s
environment.
Strategic Transformational
People
Process
Technology
Influence
● Model your D&R on DevOps, not best ops.
● A modern SOC is a team that “engineers” detection and
response for an organization
● Reduce toil in your SOC - shift toil to machines. Evolve
automation in SIEM, SOAR, threat intel, etc
● Magic? Relentless drive to D&R automation powered
by a rapid feedback loop and engineering — led
mentality.
● AI will help change the micro game for the defenders …
but not the macro game.
Recommendations
● WTH is Modern SOC, Part 1
● Kill SOC Toil, Do SOC Eng
● The original ASO paper (2021)
● Google/Deloitte Future SOC papers
● Detection as Code? No, Detection as COOKING!
● Cooking Intelligent Detections from Threat Intelligence (Part 6)
● EP75 How We Scale Detection and Response at Google:
Automation, Metrics, Toil
Resources
Google_logo 2021 | Confidential and Proprietary pg. 23
More Resources
● “Achieving Autonomic Security Operations: Reducing toil”
● “Achieving Autonomic Security Operations: Automation as a Force
Multiplier”
● “Achieving Autonomic Security Operations: Why metrics matter (but not
how you think)”
● “More SRE Lessons for SOC: Simplicity Helps Security”
● “More SRE Lessons for SOC: Release Engineering Ideas”
● EP75 How We Scale Detection and Response at Google: Automation,
Metrics, Toil
● SRE Books

More Related Content

What's hot (20)

PDF
SOC2 Intro and Mindfulness
EmilyGladstoneCole
 
PPT
ISMS implementation challenges-KASYS
Reza Teynia ISMS, ITSM, MSc
 
PDF
Cyber Threat Intelligence - It's not just about the feeds
Iain Dickson
 
PDF
SOC Architecture - Building the NextGen SOC
Priyanka Aash
 
PPTX
SOC Architecture Workshop - Part 1
Priyanka Aash
 
PPTX
Security Operation Center - Design & Build
Sameer Paradia
 
PPTX
To Build Or Not To Build: Can SOC-aaS Bridge Your Security Skills Gap?
NetEnrich, Inc.
 
PDF
Governance of security operation centers
Brencil Kaimba
 
PDF
Rothke secure360 building a security operations center (soc)
Ben Rothke
 
PDF
Threat Intelligence Workshop
Priyanka Aash
 
PDF
Building Security Operation Center
S.E. CTS CERT-GOV-MD
 
PPTX
Cyber threat Intelligence and Incident Response by:-Sandeep Singh
OWASP Delhi
 
PPTX
The CIS Critical Security Controls the International Standard for Defense
EnclaveSecurity
 
PDF
Security Automation and Machine Learning
Siemplify
 
PPSX
Next-Gen security operation center
Muhammad Sahputra
 
PPTX
SOAR and SIEM.pptx
Ajit Wadhawan
 
PDF
From OSINT to Phishing presentation
Jesse Ratcliffe, OSCP
 
PPTX
Security Operations Center (SOC) Essentials for the SME
AlienVault
 
PDF
Building A Security Operations Center
Siemplify
 
SOC2 Intro and Mindfulness
EmilyGladstoneCole
 
ISMS implementation challenges-KASYS
Reza Teynia ISMS, ITSM, MSc
 
Cyber Threat Intelligence - It's not just about the feeds
Iain Dickson
 
SOC Architecture - Building the NextGen SOC
Priyanka Aash
 
SOC Architecture Workshop - Part 1
Priyanka Aash
 
Security Operation Center - Design & Build
Sameer Paradia
 
To Build Or Not To Build: Can SOC-aaS Bridge Your Security Skills Gap?
NetEnrich, Inc.
 
Governance of security operation centers
Brencil Kaimba
 
Rothke secure360 building a security operations center (soc)
Ben Rothke
 
Threat Intelligence Workshop
Priyanka Aash
 
Building Security Operation Center
S.E. CTS CERT-GOV-MD
 
Cyber threat Intelligence and Incident Response by:-Sandeep Singh
OWASP Delhi
 
The CIS Critical Security Controls the International Standard for Defense
EnclaveSecurity
 
Security Automation and Machine Learning
Siemplify
 
Next-Gen security operation center
Muhammad Sahputra
 
SOAR and SIEM.pptx
Ajit Wadhawan
 
From OSINT to Phishing presentation
Jesse Ratcliffe, OSCP
 
Security Operations Center (SOC) Essentials for the SME
AlienVault
 
Building A Security Operations Center
Siemplify
 

Similar to Future of SOC: More Security, Less Operations (20)

PPTX
SOC Lessons from DevOps and SRE by Anton Chuvakin
Anton Chuvakin
 
PPTX
10X SOC - SANS Blue Summit Keynote 2021 - Anton Chuvakin
Anton Chuvakin
 
PPTX
Meet the Ghost of SecOps Future by Anton Chuvakin
Anton Chuvakin
 
PPTX
Modern SOC Trends 2020
Anton Chuvakin
 
PDF
Modern Security Operations - Building and leading modern SOC
Security Bootcamp
 
PDF
Tampa BSides - The No BS SOC (slides from April 6, 2024 talk)
Mark Simos
 
PDF
Bridging the Gap Between Alert and Action with SOAR Services India
manoharparakh
 
PPTX
SOCstock 2020 Groovy SOC Tunes aka Modern SOC Trends
Anton Chuvakin
 
PDF
What is a Security Operation Center(SOC)?
BORNSEC CONSULTING
 
PPTX
A Deeper Dive into SOC Operations and Roles
wininlifeacademy5
 
PPTX
Cybersecurity Operations: Examining the State of the SOC
Fidelis Cybersecurity
 
PPTX
Dragos S4x20: How to Build an OT Security Operations Center
Dragos, Inc.
 
PPTX
Introduction-to-Security-Operations-Center (SOC)
sumank281995
 
PPTX
Security Operations Cloud vs On Prem ISC2 Bangalore SlideShare.pptx
Vikas Singh Yadav
 
PDF
Rethinking Security Operations - Modern SOC.pdf
Haris Chughtai
 
PDF
Security automation system
Siemplify
 
PDF
Security Operations Center (SOC) by aadit technologies
sumank281995
 
PDF
ATT&CKcon 5.0 Keynote - From Ticket Closers to Practitioners- How Great Secu...
MITRE ATT&CK
 
PDF
10-essential-capabilities-of-a-modern-soc1.pdf
reflandahartanto00
 
PDF
Nazar Tymoshyk - Automation in modern Incident Detection & Response (IDR) pro...
NoNameCon
 
SOC Lessons from DevOps and SRE by Anton Chuvakin
Anton Chuvakin
 
10X SOC - SANS Blue Summit Keynote 2021 - Anton Chuvakin
Anton Chuvakin
 
Meet the Ghost of SecOps Future by Anton Chuvakin
Anton Chuvakin
 
Modern SOC Trends 2020
Anton Chuvakin
 
Modern Security Operations - Building and leading modern SOC
Security Bootcamp
 
Tampa BSides - The No BS SOC (slides from April 6, 2024 talk)
Mark Simos
 
Bridging the Gap Between Alert and Action with SOAR Services India
manoharparakh
 
SOCstock 2020 Groovy SOC Tunes aka Modern SOC Trends
Anton Chuvakin
 
What is a Security Operation Center(SOC)?
BORNSEC CONSULTING
 
A Deeper Dive into SOC Operations and Roles
wininlifeacademy5
 
Cybersecurity Operations: Examining the State of the SOC
Fidelis Cybersecurity
 
Dragos S4x20: How to Build an OT Security Operations Center
Dragos, Inc.
 
Introduction-to-Security-Operations-Center (SOC)
sumank281995
 
Security Operations Cloud vs On Prem ISC2 Bangalore SlideShare.pptx
Vikas Singh Yadav
 
Rethinking Security Operations - Modern SOC.pdf
Haris Chughtai
 
Security automation system
Siemplify
 
Security Operations Center (SOC) by aadit technologies
sumank281995
 
ATT&CKcon 5.0 Keynote - From Ticket Closers to Practitioners- How Great Secu...
MITRE ATT&CK
 
10-essential-capabilities-of-a-modern-soc1.pdf
reflandahartanto00
 
Nazar Tymoshyk - Automation in modern Incident Detection & Response (IDR) pro...
NoNameCon
 
Ad

More from Anton Chuvakin (20)

PPTX
Detection Engineering Maturity - Helping SIEMs Find Their Adulting Skills
Anton Chuvakin
 
PPTX
SOC Meets Cloud: What Breaks, What Changes, What to Do?
Anton Chuvakin
 
PPTX
SANS Webinar: The Future of Log Centralization for SIEMs and DFIR – Is the En...
Anton Chuvakin
 
PPTX
Hey SOC, Look LEFT! by Anton Chuvakin RSA 2023 Booth
Anton Chuvakin
 
PPTX
20 Years of SIEM - SANS Webinar 2022
Anton Chuvakin
 
PPTX
SOCstock 2021 The Cloud-native SOC
Anton Chuvakin
 
PPTX
Anton's 2020 SIEM Best and Worst Practices - in Brief
Anton Chuvakin
 
PPTX
Generic siem how_2017
Anton Chuvakin
 
PPTX
Tips on SIEM Ops 2015
Anton Chuvakin
 
PPTX
Five SIEM Futures (2012)
Anton Chuvakin
 
PPTX
RSA 2016 Security Analytics Presentation
Anton Chuvakin
 
PPTX
Five Best and Five Worst Practices for SIEM by Dr. Anton Chuvakin
Anton Chuvakin
 
PPTX
Five Best and Five Worst Practices for SIEM by Dr. Anton Chuvakin
Anton Chuvakin
 
PPTX
Practical Strategies to Compliance and Security with SIEM by Dr. Anton Chuvakin
Anton Chuvakin
 
PPTX
SIEM Primer:
Anton Chuvakin
 
PPTX
Log management and compliance: What's the real story? by Dr. Anton Chuvakin
Anton Chuvakin
 
PPTX
On Content-Aware SIEM by Dr. Anton Chuvakin
Anton Chuvakin
 
PPTX
Making Log Data Useful: SIEM and Log Management Together by Dr. Anton Chuvakin
Anton Chuvakin
 
PPTX
PCI 2.0 What's Next for PCI DSS by Dr. Anton Chuvakin
Anton Chuvakin
 
PPTX
How to Gain Visibility and Control: Compliance Mandates, Security Threats and...
Anton Chuvakin
 
Detection Engineering Maturity - Helping SIEMs Find Their Adulting Skills
Anton Chuvakin
 
SOC Meets Cloud: What Breaks, What Changes, What to Do?
Anton Chuvakin
 
SANS Webinar: The Future of Log Centralization for SIEMs and DFIR – Is the En...
Anton Chuvakin
 
Hey SOC, Look LEFT! by Anton Chuvakin RSA 2023 Booth
Anton Chuvakin
 
20 Years of SIEM - SANS Webinar 2022
Anton Chuvakin
 
SOCstock 2021 The Cloud-native SOC
Anton Chuvakin
 
Anton's 2020 SIEM Best and Worst Practices - in Brief
Anton Chuvakin
 
Generic siem how_2017
Anton Chuvakin
 
Tips on SIEM Ops 2015
Anton Chuvakin
 
Five SIEM Futures (2012)
Anton Chuvakin
 
RSA 2016 Security Analytics Presentation
Anton Chuvakin
 
Five Best and Five Worst Practices for SIEM by Dr. Anton Chuvakin
Anton Chuvakin
 
Five Best and Five Worst Practices for SIEM by Dr. Anton Chuvakin
Anton Chuvakin
 
Practical Strategies to Compliance and Security with SIEM by Dr. Anton Chuvakin
Anton Chuvakin
 
SIEM Primer:
Anton Chuvakin
 
Log management and compliance: What's the real story? by Dr. Anton Chuvakin
Anton Chuvakin
 
On Content-Aware SIEM by Dr. Anton Chuvakin
Anton Chuvakin
 
Making Log Data Useful: SIEM and Log Management Together by Dr. Anton Chuvakin
Anton Chuvakin
 
PCI 2.0 What's Next for PCI DSS by Dr. Anton Chuvakin
Anton Chuvakin
 
How to Gain Visibility and Control: Compliance Mandates, Security Threats and...
Anton Chuvakin
 
Ad

Recently uploaded (20)

PPTX
Machine Learning Benefits Across Industries
SynapseIndia
 
PPTX
PCU Keynote at IEEE World Congress on Services 250710.pptx
Ramesh Jain
 
PDF
Alpha Altcoin Setup : TIA - 19th July 2025
CIFDAQ
 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
PPTX
Agile Chennai 18-19 July 2025 | Workshop - Enhancing Agile Collaboration with...
AgileNetwork
 
PPTX
Earn Agentblazer Status with Slack Community Patna.pptx
SanjeetMishra29
 
PPTX
Simple and concise overview about Quantum computing..pptx
mughal641
 
PPTX
The Future of AI & Machine Learning.pptx
pritsen4700
 
PDF
OpenInfra ID 2025 - Are Containers Dying? Rethinking Isolation with MicroVMs.pdf
Muhammad Yuga Nugraha
 
PDF
Integrating IIoT with SCADA in Oil & Gas A Technical Perspective.pdf
Rejig Digital
 
PPTX
python advanced data structure dictionary with examples python advanced data ...
sprasanna11
 
PPTX
The Yotta x CloudStack Advantage: Scalable, India-First Cloud
ShapeBlue
 
PDF
visibel.ai Company Profile – Real-Time AI Solution for CCTV
visibelaiproject
 
PDF
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
PPTX
AI Code Generation Risks (Ramkumar Dilli, CIO, Myridius)
Priyanka Aash
 
PDF
introduction to computer hardware and sofeware
chauhanshraddha2007
 
PDF
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
PDF
Market Insight : ETH Dominance Returns
CIFDAQ
 
PDF
Market Wrap for 18th July 2025 by CIFDAQ
CIFDAQ
 
PDF
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
Machine Learning Benefits Across Industries
SynapseIndia
 
PCU Keynote at IEEE World Congress on Services 250710.pptx
Ramesh Jain
 
Alpha Altcoin Setup : TIA - 19th July 2025
CIFDAQ
 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
Agile Chennai 18-19 July 2025 | Workshop - Enhancing Agile Collaboration with...
AgileNetwork
 
Earn Agentblazer Status with Slack Community Patna.pptx
SanjeetMishra29
 
Simple and concise overview about Quantum computing..pptx
mughal641
 
The Future of AI & Machine Learning.pptx
pritsen4700
 
OpenInfra ID 2025 - Are Containers Dying? Rethinking Isolation with MicroVMs.pdf
Muhammad Yuga Nugraha
 
Integrating IIoT with SCADA in Oil & Gas A Technical Perspective.pdf
Rejig Digital
 
python advanced data structure dictionary with examples python advanced data ...
sprasanna11
 
The Yotta x CloudStack Advantage: Scalable, India-First Cloud
ShapeBlue
 
visibel.ai Company Profile – Real-Time AI Solution for CCTV
visibelaiproject
 
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
AI Code Generation Risks (Ramkumar Dilli, CIO, Myridius)
Priyanka Aash
 
introduction to computer hardware and sofeware
chauhanshraddha2007
 
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
Market Insight : ETH Dominance Returns
CIFDAQ
 
Market Wrap for 18th July 2025 by CIFDAQ
CIFDAQ
 
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 

Future of SOC: More Security, Less Operations

  • 1. Future of SOC: More Security, Less Operations Dr. Anton Chuvakin Office of the CISO, Google Cloud March 2024 https://medium.com/anton-on-security https://cloud.withgoogle.com/cloudsecurity/podcast/
  • 2. Inspiration! [In 2024] “you can’t “ops” your way to SOC success, but you can “dev” your way there” -- Dr. Anton Chuvakin (source: “Kill SOC Toil, Do SOC Eng” blog) So, which lessons does your SOC need? Operations excellence or development success?
  • 3. Outline ● SOC, a reminder ● Do we have to SOC, really? ● SOC automation: the ultimate in “easier said than done” ● SOC or “SOC”? ○ Do we have to engineer anything? ● AI will come and save us… right? RIGHT? ● Recommendations
  • 5. A security operations center provides centralized and consolidated cybersecurity incident prevention, detection and response capabilities. –Gartner A Classic SOC View! SOC is first a TEAM. Next a PROCESS. And it uses TECHNOLOGY too.
  • 6. “We don’t have enough skilled engineers to make everything work” “Our processes are too manual, we are too slow to respond to and remediate threats” “We struggle to build effective detection and have too many false positives/negatives” 2003 or 2023? Sec Ops is Ripe for Transformation “We can’t store and analyze all data, resulting in blindspots” “It takes too long to investigate alerts” “It’s cost prohibitive to ingest all the data we need”
  • 7. 07 This is How 20+ Years of Progress Look Like! :-( Organizations were notified of breaches by external entities in 63% of incidents (Mandiant M-Trends 2023)
  • 8. Know anybody who does not have those problems? Yeah, that’s us :-)
  • 9. You think you want to know just how Google does Detection and Response? WARNING FOR THOSE VIEWING ON SLIDESHARE: NEXT SLIDE IS SKIPPED
  • 10. Your SOC DNA? 1990s NOC and Help Center Security Engineering Team
  • 11. Secret 1: Why There is No Door that Says “SOC” at Google? It is because of the letter “O”..
  • 12. … just like “IT Operations” SRE
  • 13. Q: Would you rather write threat detection rules in Python or in Go? A: Eh…. no?
  • 14. SRE, DevOps and Modern IT
  • 16. Problem What does Google do? What do most enterprises do? Efficiency Automation/SRE is a mindset – part of the hiring process, part of OKRs, and performance reviews Experimenting with SOAR, full adoption is tough due to minimal automation culture Employee Shortage Requires coding interviews, attracts the best, invests in growth Hires traditional roles, no coding, outsources, less growth, more stress Employee Burnout 40/40/20 between eng, operations, and learning Utilization is almost always >100% Expensive Investment in efficiency solves for human costs Cost-prohibitive data ingestion, oftentimes paying SIEM and DIY, increasing cost from complexity Efficacy Intel strongly embedded in D&R, mostly utilized towards proactive work, strong collaboration across teams & benefits from developer hygiene CTI team produces great reports, SOC consistently doing fire drills, >90% false positive rate, uneven distribution of skill (Tier 3) Google D&R vs Enterprise “SecOps”
  • 17. Increase overall tooling footprint 1 Eliminate toil Embrace change 2 Strive for continuous improvement 3 Bridge all siloes 4 Use service level objectives 5 Avoid hero mentality 6 7 Aim for simplicity Should: Restrict hiring to top professionals Require an engineering-only culture Aim for only incremental gain Autonomic Modern Security Operations Principles 1 2 3 4 Should not:
  • 18. 1 Reduce toil Create an automation queue Implement blameless postmortems Conduct Weekly Incident Reviews Implement SOAR Hire Automation Engineer(s) Train your team on toil and automation Implement CD/CR pipelines with metrics Key activities to reduce toil 02 03 04 05 06 01 07
  • 19. ● Analyst utilization gets optimized ● More creative work, less toil ● Time back to do more proactive work ● Deeper operationalization of intel ● SecOps can scale with the business! Evolve Automation 10X is an Underestimate!
  • 20. Three phases of SecOps transformation Tactical Carries a sense of urgency and immediacy. A cautious way of saying “we’re in trouble and need an immediate fix before we go down in flames.” Often implies a 3-5 year vision and a roadmap how to achieve that vision. A major change that completely reshapes the organization in response to, or anticipation of, significant changes in organization’s environment. Strategic Transformational People Process Technology Influence
  • 21. ● Model your D&R on DevOps, not best ops. ● A modern SOC is a team that “engineers” detection and response for an organization ● Reduce toil in your SOC - shift toil to machines. Evolve automation in SIEM, SOAR, threat intel, etc ● Magic? Relentless drive to D&R automation powered by a rapid feedback loop and engineering — led mentality. ● AI will help change the micro game for the defenders … but not the macro game. Recommendations
  • 22. ● WTH is Modern SOC, Part 1 ● Kill SOC Toil, Do SOC Eng ● The original ASO paper (2021) ● Google/Deloitte Future SOC papers ● Detection as Code? No, Detection as COOKING! ● Cooking Intelligent Detections from Threat Intelligence (Part 6) ● EP75 How We Scale Detection and Response at Google: Automation, Metrics, Toil Resources
  • 23. Google_logo 2021 | Confidential and Proprietary pg. 23 More Resources ● “Achieving Autonomic Security Operations: Reducing toil” ● “Achieving Autonomic Security Operations: Automation as a Force Multiplier” ● “Achieving Autonomic Security Operations: Why metrics matter (but not how you think)” ● “More SRE Lessons for SOC: Simplicity Helps Security” ● “More SRE Lessons for SOC: Release Engineering Ideas” ● EP75 How We Scale Detection and Response at Google: Automation, Metrics, Toil ● SRE Books