Logo
Cybersecurity

A SOC Can’t Detect What It Never Learned to See

Before analysts can investigate an attack, somebody has to make sure the right evidence exists.

ITSEC AsiaITSEC Asia
|
Sep 17, 2026
A SOC Can’t Detect What It Never Learned to See

A security alert arrives. An analyst opens it, checks the surrounding activity and begins reconstructing what happened.

That sounds like the beginning of detection work.

In reality, a considerable amount of work happened earlier. Someone decided which events should be logged, configured the systems to produce them, collected those records centrally and made sure the data contained enough detail to support an investigation.

If that work is poor, even an excellent analyst is starting with missing pages.

An upcoming ITU cybersecurity exercise in Dushanbe makes this dependency unusually explicit. During the three day program from 21 to 23 September 2026, teams will configure centralized monitoring and telemetry collection before responding to simulated ransomware, data exfiltration, server compromise and command and control traffic. The methodology has a catch: performance against attacks on Day 3 depends on the monitoring participants configured on Day 2.

That’s a useful model for SOC training.

Visibility Is a Skill

SOC development often concentrates on the visible part of the job: analysing alerts, threat hunting and incident response.

Those capabilities depend on something less glamorous.

Logs need to exist.

CISA describes logging and monitoring as complementary activities. Logging records events such as authentication, file access and system changes. Monitoring examines those records for suspicious behaviour. Its guidance recommends collecting useful events from servers, firewalls, endpoints and cloud services, then centralising them so defenders can detect unusual activity.

That creates a different set of skills for SOC teams:

  • Choosing which security events need to be collected
  • Understanding what useful telemetry looks like across endpoints, networks, applications and cloud environments
  • Configuring centralised event collection
  • Recognising gaps in visibility
  • Creating meaningful alerts without producing constant noise
  • Preserving enough context for threat hunting and incident investigation

The last few points matter because collecting everything isn’t automatically the same as seeing everything.

A warehouse full of logs can still be remarkably unhelpful.

Build the Detection Before Testing the Defender

The ITU exercise flips a common training model in a useful way.

Rather than giving participants a fully instrumented environment and asking them to find an attacker, it makes them responsible for building part of their own visibility first.

Imagine doing the same in SOC training.

Give learners an enterprise environment with incomplete logging. Ask them to decide which events matter and configure collection. Only then launch a simulated intrusion.

If the attacker moves through an area they forgot to monitor, the resulting blind spot becomes part of the lesson.

If they collect enormous volumes of irrelevant information and bury the useful signal, that becomes visible too.

The exercise starts testing engineering judgment alongside analytical skill.

SOC Readiness Needs Both Sides

This has implications for workforce planning. Organizations need analysts who can investigate suspicious activity, but mature SOC capability also depends on people who understand the telemetry underneath detection.

Those skills can sit across SOC engineering, security operations, cloud security, network security and incident response. The exact job title matters less than whether the capability exists.

Practical environments such as cyber ranges can connect both sides. At ITSEC Cyber & AI Academy, learners can work with realistic infrastructure and security scenarios where configuration decisions affect what they’re later able to detect and investigate.

The best analyst in the room can’t investigate evidence that was never collected.

Sometimes SOC readiness begins one day before the attack.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ITU National Cybersecurity Exercises, 21–23 September 2026 · CISA: Use Logging on Business Systems · ITU CyberDrills

Share this post

You may also like

This is Why You Should Automate Your Cybersecurity
Cybersecurity

This is Why You Should Automate Your Cybersecurity

DO YOU NEED TO AUTOMATE YOUR CYBERSECURITY OPERATIONS? The answer is likely "yes," and whenever I ask anyone about automation, they unequivocally state that automation will undoubtedly enhance the overall cybersecurity foundation if implemented correctly in their organizations. They say "if" because the organizations I speak with, not many of them have actually implemented automation into their operations, even if they intend to do so. They usually reason that they are too busy to stop and learn how. Here are some of the strongest reasons to automate... We live in a world where launching cyber attacks on an organization is far cheaper than defending it. To make matters worse, the threat landscape is becoming increasingly difficult to cover. You face exponentially growing threats where adversaries are getting the upper hand every day while your security tools incessantly warn you. Business resilience is the ultimate goal of any cybersecurity operation, and the only way to improve the overall resilience of your organization is to improve your overall efficiency in protecting it.

ITSEC AsiaITSEC Asia
|
Jul 20, 2023 — 4 minutes read
How to Protect Your Personal Data: A Practical Guide for Individuals and Organizations
Cybersecurity

How to Protect Your Personal Data: A Practical Guide for Individuals and Organizations

Your personal data is more valuable than you might think, and cybercriminals know it. From your email address and phone number to your banking credentials and health records, every piece of information you share online can be stolen, sold, or weaponized against you. But here is the uncomfortable truth: most people underestimate how vulnerable they are, and most organizations still treat data protection as an afterthought rather than a priority. This guide breaks down exactly how personal data gets compromised, what the real-world consequences look like, and, most importantly, what you can do about it right now. According to the IBM Cost of a Data Breach Report 2025, the global average cost reached USD 4.4 million. Behind every statistic is a real person whose identity was stolen, whose bank account was drained, or whose private records were exposed to strangers. WHY PERSONAL DATA PROTECTION IS A GLOBAL EMERGENCY We are living through a data breach epidemic. Every week, news breaks about a new company, government agency, or institution that has

ITSEC AsiaITSEC Asia
|
Apr 27, 2026 — 8 minutes read
Your SOC Can’t Handle a Cyber Crisis Alone
Cybersecurity

Your SOC Can’t Handle a Cyber Crisis Alone

Imagine a ransomware incident at 10:30 on a Tuesday morning. The SOC detects suspicious activity and starts investigating. Soon IT needs to isolate systems. Management wants to know whether operations should continue. Legal needs facts. Communications may need to prepare a response. Someone has to decide whether customers or authorities need to be informed. By lunch, cybersecurity has become an organizational exercise. That reality is reflected in current training from the International Telecommunication Union. An ITU Academy incident response course currently open for applications uses three scenarios: a ransomware attack, a data breach and an attack affecting a national education system. Participants work through the incident response lifecycle using collaborative tabletop exercises. The lesson is useful far beyond education. Incident response capability depends on how well different people can make decisions together. TECHNICAL SKILL IS ONLY ONE LAYER A strong SOC can identify malicious activity, analyse evidence and recommend containment. It still needs an organization around it that knows what happens next. Useful incident response capability therefore spreads across several functions: *

ITSEC AsiaITSEC Asia
|
Sep 15, 2026 — 3 minutes read

Receive weekly
updates on new posts

Subscribe