Security Operations Center-as-a-Service (SOCaaS) is gaining adoption as organizations try to secure an expanded attack surface created by digital transformation, cloud adoption, and a more mobile and remote workforce. With employees accessing systems and data from both on-premises and cloud environments outside the corporate network, risk has increased further in the post-Covid era. To meet regulatory obligations and protect sensitive and proprietary information, many organizations have invested heavily in security tools, but this has produced daily alert volumes that are difficult—especially for small and medium-sized businesses—to investigate and analyze.
SOCaaS has emerged to address alert overload, extract more value from existing security investments, extend monitoring to cloud, operational technology (OT), and IoT, and drive continual improvement by measuring control effectiveness. It also helps demonstrate to auditors a standardized detection and response capability, and mitigates the cybersecurity skills shortage by providing scalable SOC resources at lower cost than building capacity in-house. As a cloud-based, multi-tenant SaaS offering, SOCaaS avoids hardware and software management while improving resiliency, update cadence, scalability, and remote co-management.
Cysiv, founded in 2018 and now independent after incubation within Trend Micro, provides a cloud-native, co-managed SOCaaS platform that ingests telemetry from any log-generating source, integrates with existing SIEMs (or provides SIEM capabilities), and emphasizes detection, investigation, triage, threat hunting, remediation, and built-in SOAR. It uses machine learning, signature recognition, behavior analytics, statistics, and broad threat intelligence sources to reduce false positives and alert fatigue while enabling higher-fidelity detection and forensics. Pricing is consumption-based (events per second and users/workloads). Strengths include scalability, service tiers, co-management access, threat intelligence breadth, and SOAR; challenges include reliance on third parties for intrusion detection/prevention and missing automatic containment, vulnerability scanning, and asset discovery (on the roadmap).
See All Locations
See All Locations