Detection – Auditing and Monitoring
Although organizations already try to harden their environments, only a few take into account that auditing and monitoring are two of the most important things when it comes to securing your environment.
For many years while working at Microsoft, I have preached the protect, detect, and respond approach. Most companies try to just protect their devices, but that’s where they stop. To detect and respond, there needs to be not only a working Security Operations Center (SOC) in place but also infrastructure and resources.
Those people and resources require money – a budget that many companies don’t want to spend in the first place, unless they have been breached.
When working with customers, I saw only a few environments with a working SOC in place, as well as the infrastructure to host a Security Information and Event Management (SIEM) system. I was really happy that when I left those customers, most of them started...