A SOC Can’t Detect What It Never Learned to See
Before analysts can investigate an attack, somebody has to make sure the right evidence exists.

A security alert arrives. An analyst opens it, checks the surrounding activity and begins reconstructing what happened.
That sounds like the beginning of detection work.
In reality, a considerable amount of work happened earlier. Someone decided which events should be logged, configured the systems to produce them, collected those records centrally and made sure the data contained enough detail to support an investigation.
If that work is poor, even an excellent analyst is starting with missing pages.
An upcoming ITU cybersecurity exercise in Dushanbe makes this dependency unusually explicit. During the three day program from 21 to 23 September 2026, teams will configure centralized monitoring and telemetry collection before responding to simulated ransomware, data exfiltration, server compromise and command and control traffic. The methodology has a catch: performance against attacks on Day 3 depends on the monitoring participants configured on Day 2.
That’s a useful model for SOC training.
Visibility Is a Skill
SOC development often concentrates on the visible part of the job: analysing alerts, threat hunting and incident response.
Those capabilities depend on something less glamorous.
Logs need to exist.
CISA describes logging and monitoring as complementary activities. Logging records events such as authentication, file access and system changes. Monitoring examines those records for suspicious behaviour. Its guidance recommends collecting useful events from servers, firewalls, endpoints and cloud services, then centralising them so defenders can detect unusual activity.
That creates a different set of skills for SOC teams:
- Choosing which security events need to be collected
- Understanding what useful telemetry looks like across endpoints, networks, applications and cloud environments
- Configuring centralised event collection
- Recognising gaps in visibility
- Creating meaningful alerts without producing constant noise
- Preserving enough context for threat hunting and incident investigation
The last few points matter because collecting everything isn’t automatically the same as seeing everything.
A warehouse full of logs can still be remarkably unhelpful.
Build the Detection Before Testing the Defender
The ITU exercise flips a common training model in a useful way.
Rather than giving participants a fully instrumented environment and asking them to find an attacker, it makes them responsible for building part of their own visibility first.
Imagine doing the same in SOC training.
Give learners an enterprise environment with incomplete logging. Ask them to decide which events matter and configure collection. Only then launch a simulated intrusion.
If the attacker moves through an area they forgot to monitor, the resulting blind spot becomes part of the lesson.
If they collect enormous volumes of irrelevant information and bury the useful signal, that becomes visible too.
The exercise starts testing engineering judgment alongside analytical skill.
SOC Readiness Needs Both Sides
This has implications for workforce planning. Organizations need analysts who can investigate suspicious activity, but mature SOC capability also depends on people who understand the telemetry underneath detection.
Those skills can sit across SOC engineering, security operations, cloud security, network security and incident response. The exact job title matters less than whether the capability exists.
Practical environments such as cyber ranges can connect both sides. At ITSEC Cyber & AI Academy, learners can work with realistic infrastructure and security scenarios where configuration decisions affect what they’re later able to detect and investigate.
The best analyst in the room can’t investigate evidence that was never collected.
Sometimes SOC readiness begins one day before the attack.
Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.
References: ITU National Cybersecurity Exercises, 21–23 September 2026 · CISA: Use Logging on Business Systems · ITU CyberDrills
.png)


