CISO Middle East Issue 03 | Page 26

f

e

a

t

u

r

e

Eliad Kimhy, Senior Security Researcher at Acronis playbooks, allowing security teams to intercept intrusions before they evolve into full-scale breaches.”
For Eliad Kimhy, Senior Security Researcher at Acronis, the transformation is also being driven by fundamental changes in both the sources and sheer volume of security data.
“ The traditional SOC was built around analysing IT data: many sources of information, some from endpoints and others from network traffic, coalescing, ideally, into a single pane, correlated and processed through a series of rules or products, and then passed on to a human analyst. The analyst’ s job was therefore to work through those events, judge whether each was benign or serious, and decide on the next steps. An abundance of data, and the need for analysts to do the brunt of the analysis, have in turn led to alert fatigue and personnel shortages, as more and more data needed analysing and the analysis became increasingly complex. enrichment, initial investigation and other highvolume tasks can increasingly be handled by automation, allowing analysts to concentrate on complex investigations and decisions that require context. The important distinction is between automating a task and automating judgement. High-confidence actions can be automated where the risk is understood, while more consequential decisions should remain under human oversight. That becomes particularly important as AI moves from simply assisting analysts to taking actions across security environments. The goal is to give a small team the reach of a much larger operation, without turning security into an entirely autonomous process that people no longer understand or control.”
Ram Narayanan, Country Manager, Check Point Software Technologies
“ A modern SOC still operates in a similar way, but two things have changed. The first is the data: endpoint and network telemetry are no longer sufficient because identity, the cloud control plane and SaaS audit logs are where much of today’ s attacker activity is actually visible. The second is volume and tempo – alert counts have grown, and intrusions now run from initial access to impact, in hours, rather than days.
“ That is why triage becomes automation-first, so the analyst’ s first look is at an enriched, correlated incident rather than a single event, preferably with a recommended next step attached. The analyst’ s role does not disappear in that model; it moves up, from judging individual events to validating incidents, hunting and engineering better detections.”
Automation without removing the human
With alert fatigue and analyst burnout continuing to challenge security teams, automation and AI are becoming central to the SOC. The objective, however, is not necessarily to remove people from security operations, but to shift their attention towards work where human judgement provides the greatest value.
Ram Narayanan, Country Manager, Check Point Software Technologies, Middle East, said:“ AI should take the repetitive work away from analysts, not take analysts out of the equation. Correlation,
Ahmad Alshaer – Security Leader, Middle East & Africa, DXC Technology
Ahmad Alshaer – Security Leader, Middle East & Africa, DXC Technology, similarly argues that automation should reposition security professionals rather than replace them.
“ Whether you are running 70 % or 95 % SOC automation, the principle is the same. Move repetitive work to machines, keep humans for decisions that require judgement, and document everything.
“ So the goal with automation is not about removing people, it is about repositioning them. L1 work like classifying, enriching and closing alerts, increasingly shifts to automation under human supervision, and analysts spend their time on complex investigations, threat hunting and tuning detections instead.
“ Engineers change too. Detection engineers and platform teams start operating like product owners, managing detections and response actions the way application teams manage releases.
“ Of course, none of this works without tighter governance. Automated actions need guardrails,
26 WWW. INTELLIGENTCISO. COM / MIDDLE-EAST