Fighting Alert Fatigue: Solving the SOC - Cybersec Café #3
Anyone who has worked in a Security Operations Center (SOC) or in a Detection and Incident Response Team has experienced Alert Fatigue: desensitization to security alerts due to a high volume hitting your ticketing system. It’s an ever evolving battle to fight, and it can get increasingly difficult the longer it gets pushed off. But why is Alert Fatigue such a dangerous “disease” to your SOC Team? Picture this: You’re working in the SOC at a growing FinTech company as an Analyst. In your environment, you have detections configured to pick up Multi-Factor Authentication (MFA) getting enabled or disabled on employee phones in your company. A large class of new hires is onboarding today, and there are a lot of alerts firing off to start the work day of new colleagues enabling MFA on their phones. You notice some users disabling MFA due to IT helping with troubleshooting, and adding to the amount of alerts filling the queue. Now you have to spend the time going through the tedious process
Anyone who has worked in a Security Operations Center (SOC) or in a Detection and Incident Response Team has experienced Alert Fatigue: desensitization to security alerts due to a high volume hitting your ticketing system. It’s an ever evolving battle to fight, and it can get increasingly difficult the longer it gets pushed off. But why is Alert Fatigue such a dangerous “disease” to your SOC Team? Picture this: You’re working in the SOC at a growing FinTech company as an Analyst. In your environment, you have detections configured to pick up Multi-Factor Authentication (MFA) getting enabled or
Explore this link on the map →