We spoke at the Baltic Security Conference at BTU last week on building and running a security operations centre for a company spread across eight countries and two cloud regions.
The talk covered our detection engineering process and the follow-the-sun handover. The questions afterwards were about none of that, and were more useful.
The most common question, asked four separate times: how do you stop the SOC becoming the team that says no? Our answer is that the SOC does not own risk decisions. It owns detection, triage and response. Whether to accept a risk is a business decision made by someone with the authority to accept it, recorded in writing. Confusing those two things is how security teams become obstacles.
The second most common: how do you staff 24/7 without burning people out? Honestly — we do not fully, yet. We have European and Americas coverage and an on-call bridge for the gap. Genuine 24/7 with humans awake requires a headcount we do not have, and claiming otherwise would be a lie that eventually shows up in an incident timeline.
Slides are on the events page. We recruit heavily from BTU and several of the questions came from people who now work here.