Logo
Cybersecurity

A SOC Can’t Detect What It Never Learned to See

Before analysts can investigate an attack, somebody has to make sure the right evidence exists.

ITSEC AsiaITSEC Asia
|
Sep 17, 2026
A SOC Can’t Detect What It Never Learned to See

A security alert arrives. An analyst opens it, checks the surrounding activity and begins reconstructing what happened.

That sounds like the beginning of detection work.

In reality, a considerable amount of work happened earlier. Someone decided which events should be logged, configured the systems to produce them, collected those records centrally and made sure the data contained enough detail to support an investigation.

If that work is poor, even an excellent analyst is starting with missing pages.

An upcoming ITU cybersecurity exercise in Dushanbe makes this dependency unusually explicit. During the three day program from 21 to 23 September 2026, teams will configure centralized monitoring and telemetry collection before responding to simulated ransomware, data exfiltration, server compromise and command and control traffic. The methodology has a catch: performance against attacks on Day 3 depends on the monitoring participants configured on Day 2.

That’s a useful model for SOC training.

Visibility Is a Skill

SOC development often concentrates on the visible part of the job: analysing alerts, threat hunting and incident response.

Those capabilities depend on something less glamorous.

Logs need to exist.

CISA describes logging and monitoring as complementary activities. Logging records events such as authentication, file access and system changes. Monitoring examines those records for suspicious behaviour. Its guidance recommends collecting useful events from servers, firewalls, endpoints and cloud services, then centralising them so defenders can detect unusual activity.

That creates a different set of skills for SOC teams:

  • Choosing which security events need to be collected
  • Understanding what useful telemetry looks like across endpoints, networks, applications and cloud environments
  • Configuring centralised event collection
  • Recognising gaps in visibility
  • Creating meaningful alerts without producing constant noise
  • Preserving enough context for threat hunting and incident investigation

The last few points matter because collecting everything isn’t automatically the same as seeing everything.

A warehouse full of logs can still be remarkably unhelpful.

Build the Detection Before Testing the Defender

The ITU exercise flips a common training model in a useful way.

Rather than giving participants a fully instrumented environment and asking them to find an attacker, it makes them responsible for building part of their own visibility first.

Imagine doing the same in SOC training.

Give learners an enterprise environment with incomplete logging. Ask them to decide which events matter and configure collection. Only then launch a simulated intrusion.

If the attacker moves through an area they forgot to monitor, the resulting blind spot becomes part of the lesson.

If they collect enormous volumes of irrelevant information and bury the useful signal, that becomes visible too.

The exercise starts testing engineering judgment alongside analytical skill.

SOC Readiness Needs Both Sides

This has implications for workforce planning. Organizations need analysts who can investigate suspicious activity, but mature SOC capability also depends on people who understand the telemetry underneath detection.

Those skills can sit across SOC engineering, security operations, cloud security, network security and incident response. The exact job title matters less than whether the capability exists.

Practical environments such as cyber ranges can connect both sides. At ITSEC Cyber & AI Academy, learners can work with realistic infrastructure and security scenarios where configuration decisions affect what they’re later able to detect and investigate.

The best analyst in the room can’t investigate evidence that was never collected.

Sometimes SOC readiness begins one day before the attack.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ITU National Cybersecurity Exercises, 21–23 September 2026 · CISA: Use Logging on Business Systems · ITU CyberDrills

Share this post

You may also like

A Guide to CSOC
Cybersecurity

A Guide to CSOC

Hacks

CSOC stands for Cyber Security Operation Center, but it can be a bit confusing because CSOC teams can also be referred to as Computer Security Incident Response Teams (CSIRT), Computer Incident Response Centers (CIRC), Security Operations Centers (SOC), or Computer Emergency Response Teams (CERT). For the purpose of this article, we will stick to the term CSOC. CSOC works in defense to combat unauthorized activities occurring in strategic networks. Its activities include monitoring, detection, analysis, response, and restoration. CSOC is a team of network security analysts organized to detect, analyze, respond to, report, and prevent network security incidents 24/7, 365 days a year. There are various types of CSOCs categorized based on their organizational and operational models, so let's delve deeper and take a closer look at the different types of CSOCs. Virtual CSOC: As the name suggests, this type of operation often lacks dedicated facilities, and team members work periodically using a reactive approach to cyber threats. I believe that the reactive capabilities of virtual CSOCs cannot be sustained

ITSEC AsiaITSEC Asia
|
Jul 10, 2023 7 minutes read
Fraud Management in Digital Era: How to Detect, Prevent, and Respond Before Losses Escalate
Cybersecurity

Fraud Management in Digital Era: How to Detect, Prevent, and Respond Before Losses Escalate

INTRODUCTION In 2025, a large-scale fraud operation uncovered by INTERPOL revealed how sophisticated Business Email Compromise (BEC) scams have become. A transnational criminal group targeted a Japanese company by impersonating a legitimate business partner through hacked or spoofed email accounts. The communication looked completely normal with the same tone, same format, and same context. The attackers sent updated banking details for a supposed transaction, convincing the company to transfer funds to a fraudulent account based in Thailand. Because the email matched ongoing business conversations, there was no immediate suspicion. By the time the fraud was detected, millions had already been moved across multiple accounts. Fraud is no longer just about stolen wallets or obvious scams. In today’s digital world, it has evolved into something far more sophisticated, quiet, convincing, and often invisible. Powered by advanced technologies like Deepfake Technology and automated systems, modern fraud can replicate voices, mimic identities, and blend seamlessly into everyday digital interactions. What makes it dangerous is not just the technology, but how naturally it fits into

ITSEC AsiaITSEC Asia
|
Apr 10, 2026 6 minutes read
Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape
Cybersecurity

Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape

If you only went to the doctor once a year, you probably would not assume you were perfectly healthy for the other 364 days. Health changes over time. New conditions can develop, existing issues can worsen, and unexpected problems may arise between checkups. That is why people increasingly rely on regular monitoring and preventive care rather than waiting for an annual appointment to discover something has gone wrong. Cybersecurity works in much the same way. For many years, annual penetration testing has been considered a cybersecurity best practice. Organizations schedule an assessment, receive a report, address the findings, and repeat the process the following year. In relatively static environments, this approach provided a reasonable level of assurance. Modern organizations, however, no longer operate in static environments. Cloud adoption has accelerated. APIs have become essential to digital services. Development teams deploy updates continuously, and third-party integrations have become increasingly common. As organizations move faster, their attack surfaces evolve just as quickly. A system that was secure six months ago may look very

ITSEC AsiaITSEC Asia
|
Jan 09, 2026 7 minutes read

Receive weekly
updates on new posts

Subscribe