Logo
Cybersecurity

A SOC Can’t Detect What It Never Learned to See

Before analysts can investigate an attack, somebody has to make sure the right evidence exists.

ITSEC AsiaITSEC Asia
|
Sep 17, 2026
A SOC Can’t Detect What It Never Learned to See

A security alert arrives. An analyst opens it, checks the surrounding activity and begins reconstructing what happened.

That sounds like the beginning of detection work.

In reality, a considerable amount of work happened earlier. Someone decided which events should be logged, configured the systems to produce them, collected those records centrally and made sure the data contained enough detail to support an investigation.

If that work is poor, even an excellent analyst is starting with missing pages.

An upcoming ITU cybersecurity exercise in Dushanbe makes this dependency unusually explicit. During the three day program from 21 to 23 September 2026, teams will configure centralized monitoring and telemetry collection before responding to simulated ransomware, data exfiltration, server compromise and command and control traffic. The methodology has a catch: performance against attacks on Day 3 depends on the monitoring participants configured on Day 2.

That’s a useful model for SOC training.

Visibility Is a Skill

SOC development often concentrates on the visible part of the job: analysing alerts, threat hunting and incident response.

Those capabilities depend on something less glamorous.

Logs need to exist.

CISA describes logging and monitoring as complementary activities. Logging records events such as authentication, file access and system changes. Monitoring examines those records for suspicious behaviour. Its guidance recommends collecting useful events from servers, firewalls, endpoints and cloud services, then centralising them so defenders can detect unusual activity.

That creates a different set of skills for SOC teams:

  • Choosing which security events need to be collected
  • Understanding what useful telemetry looks like across endpoints, networks, applications and cloud environments
  • Configuring centralised event collection
  • Recognising gaps in visibility
  • Creating meaningful alerts without producing constant noise
  • Preserving enough context for threat hunting and incident investigation

The last few points matter because collecting everything isn’t automatically the same as seeing everything.

A warehouse full of logs can still be remarkably unhelpful.

Build the Detection Before Testing the Defender

The ITU exercise flips a common training model in a useful way.

Rather than giving participants a fully instrumented environment and asking them to find an attacker, it makes them responsible for building part of their own visibility first.

Imagine doing the same in SOC training.

Give learners an enterprise environment with incomplete logging. Ask them to decide which events matter and configure collection. Only then launch a simulated intrusion.

If the attacker moves through an area they forgot to monitor, the resulting blind spot becomes part of the lesson.

If they collect enormous volumes of irrelevant information and bury the useful signal, that becomes visible too.

The exercise starts testing engineering judgment alongside analytical skill.

SOC Readiness Needs Both Sides

This has implications for workforce planning. Organizations need analysts who can investigate suspicious activity, but mature SOC capability also depends on people who understand the telemetry underneath detection.

Those skills can sit across SOC engineering, security operations, cloud security, network security and incident response. The exact job title matters less than whether the capability exists.

Practical environments such as cyber ranges can connect both sides. At ITSEC Cyber & AI Academy, learners can work with realistic infrastructure and security scenarios where configuration decisions affect what they’re later able to detect and investigate.

The best analyst in the room can’t investigate evidence that was never collected.

Sometimes SOC readiness begins one day before the attack.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ITU National Cybersecurity Exercises, 21–23 September 2026 · CISA: Use Logging on Business Systems · ITU CyberDrills

Share this post

You may also like

This is How Information Security Analysis Protects What Prevention Can't
Cybersecurity

This is How Information Security Analysis Protects What Prevention Can't

INTRODUCTION Organizations worldwide are investing more in cybersecurity than at any point in history, yet breaches are growing more frequent, more expensive, and more damaging. The global average cost of a data breach reached USD 4.88 million in 2024, the highest figure ever recorded. Even more alarming, the average time to identify a breach stood at 194 days, nearly half a year of undetected attacker activity inside a network before anyone realized something was wrong. These numbers raise an urgent question every business leader must answer honestly: if an attacker entered your network today, how long would it take your organization to find out? And once discovered, could you identify exactly what was accessed, how the attacker moved, and what vulnerabilities made it possible in the first place? For most organizations, the honest answer is: not fast enough, and not with enough certainty. That gap is precisely what Information Security Analysis (ISA) is designed to close. Prevention, including firewalls, antivirus, and multi-factor authentication, is necessary but not sufficient. When attackers

|
Mei 11, 2026 7 minutes read
AI Is Raising the Bar for Cybersecurity Talent
Cybersecurity

AI Is Raising the Bar for Cybersecurity Talent

For cybersecurity teams, AI is quickly moving from something experimental to something people actually use. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 77% of surveyed organizations had adopted AI for cybersecurity. It is already being used for tasks such as phishing detection, intrusion response and user-behaviour analysis. That sounds like good news for teams struggling with workload. And mostly, it is. But AI doesn’t remove the need for skilled cybersecurity professionals. It changes what those professionals need to be good at. AUTOMATION CAN DO MORE. SO HUMANS HAVE TO DO MORE TOO. The same WEF research found that 54% of organizations considered insufficient knowledge or skills a barrier to using AI effectively in cybersecurity. Another 41% pointed to the need for human oversight. That second number matters. AI can analyse enormous amounts of information quickly. What it still struggles with is context: whether an unusual event is genuinely dangerous, how a technical issue affects the business and what action makes sense when the available information is incomplete. Cybersecurity professionals increasingly need

ITSEC AsiaITSEC Asia
|
Sep 02, 2026 3 minutes read
Cybersecurity Careers Should Start Before University
Cybersecurity

Cybersecurity Careers Should Start Before University

Ask a teenager what jobs exist in technology and you’ll probably hear programmer, software engineer or perhaps data scientist. Ask about cybersecurity and the picture can become considerably fuzzier. Maybe “hacker” makes an appearance, usually wearing an imaginary hoodie. That perception matters because Indonesia needs a much larger pool of people who see cybersecurity as a realistic career before they have to choose one. Komdigi has started pushing cybersecurity education further down the talent pipeline. In May, its Digital Human Resources Development Agency provided Basic Cyber Security training to 124 students at SMKN 2 Depok, covering digital security awareness and preparation for a technology-driven workplace. The direction is also appearing internationally. NIST’s NICE program updated its September webinar on 2 September with a specific focus on preparing students for future cyber careers. One part examines how K–12 education can introduce skills connected to immediate workforce realities such as cloud security and generative AI. Cybersecurity education is moving earlier because the work itself isn’t waiting. EXPOSURE BEFORE SPECIALISATION Starting earlier doesn’t mean asking

ITSEC AsiaITSEC Asia
|
Sep 07, 2026 3 minutes read

Receive weekly
updates on new posts

Subscribe