What are the challenges when building an internal CSOC?
Building an effective CSOC comes with several challenges, which we have distilled into four main areas: costs, people, credibility and time to market.
The main overall challenge that MSPs need to consider is the sheer operational challenge of moving from a 9-5 MSP into a 24×7 MSSP. As cyber threats most likely occur out of working hours, you need 24×7 shift patterns in place – especially over holidays, which is a brand new challenge for many. The transition is no simple undertaking. For some, the challenges to build internally are worthwhile and a necessity, but for most the investment and commitment requires careful consideration.
Costs
There is no denying that building a CSOC requires large upfront investment. For many, the heavy upfront costs are enough to stop MSPs considering building as its simply uneconomic. An effective CSOC needs to be running 24x7x365, unlike Service Desks that can happily manage 9-5. This means shift pattern considerations and higher staff costs.
To run a 24x7x365 CSOC, the minimum staffing required is:
- 8 x Security Analysts (average salary £45,000)
- 1 x CSOC Manager (average salary £52,000)
- 2 x Security Engineer (£55,000 average salary)
- Head of Cyber Security (£72,000 average salary)
This has an annual wage bill of £594,000. And these really are the minimums, ignoring resource resilience and other CSOC functions, such as Incident Response. (Note: average salaries taken from https://uk.talent.com/en/)
People
People are the critical component of an effective CSOC and having the right people comes with its challenges:
- Recruitment – finding and hiring skilled cybersecurity staff is challenging as there is a substantial cyber skills gap.
- People Management – ensuring the right team management is in place for a 24×7 operations, such as out of hours management, and managing holidays and sickness to balance operational resilience.
- Retention – as the cyber market is very active there is a strong risk of poaching, so having a strong culture and benefits is vital to retain staff and ensure strong employee engagement.
- Training – you also need to consider continual training and development to ensure that knowledge remains current – especially critical within the fast-paced industry of cybersecurity.
Credibility
It can take a long time to build credibility and a market presence within the cybersecurity market. You also need to ensure that you have the relevant supporting sales and marketing collateral, internal teams are trained on how to sell and support customers and ensure that clients receive an excellent service.
Also ensuring that you have the right accreditations can be challenging, especially for smaller organisations. Attaining the relevant cybersecurity badges, such as ISO 27001 and Cyber Essentials Plus are a necessity, and if you specialise in particular security technologies then the right accreditations here can be challenging. For example, attaining Microsoft Security designations and Advanced Specialisations.
Time to Market
Finally, it takes a significant amount of time to build and effective CSOC. The average is three years, which many organisations cannot afford to wait that long, as their customers or opportunities will have gone elsewhere due to the urgency of the need.
It takes significant time to consider and organise:
- Processes – ensuring the right processes are in place and with time to finetune these for an effective and streamlined service.
- Technologies – having the right technologies and technical architecture and foundations in place.
- Legals & Commercials – you need time to build out the legals, service descriptions, ensure the right insurance levels and make sure you are commercially appropriate.