# A Modern SOC Should Include a Threat Intelligence Practice, Leverage Your New MSSP/MDR SOC Contract to Enhance Global SecOps Maturity
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-08-31
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: Enhance SecOps with Cyber Threat Intelligence | ThreatQuotient
Meta Description: Discover how ThreatQuotient can help your organisation integrate Cyber Threat Intelligence (CTI) practices to enhance your security operations. Don't let
URL: https://financedigest.com/a-modern-soc-should-include-a-threat-intelligence-practice-leverage-your-new-mssp-mdr-soc-contract-to-enhance-global-secops-maturityhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/digital-program-code-with-earth-globe-backgroundmje2pksd-sbi-300022975-1-1736837963346-compressed.jpg)

**_By Anthony Perridge_**

Cyber threat intelligence is now being used by organisations of all sizes across industries and geographies. In fact, 85% of respondents to the [_2021 SANS Cyber Threat Intelligence (CTI) Survey_](https://www.threatq.com/documentation/Survey_CTI-2021_ThreatQuotient.pdf) report they are producing or consuming [intelligence](https://www.financedigest.com/military-artificial-intelligence-ai-market-surges-to-usd-35-54-billion-by-2031-propelled-by-14-49-cagr-verified-market-research.html) with the remaining 15% planning to. More notably, for the first time the number of respondents without plans to consume or produce intelligence was 0%, down from 5.5% in 2020. But there is still much work to be done. A case in point, months after the SolarWinds Orion security breach, 63% of organisations [surveyed](https://www.domaintools.com/resources/survey-reports/survey-report-the-impact-of-the-solarwinds-breach-on-cybersecurity) remain highly concerned, 60% of those directly impacted are still trying to determine if they were breached, and 16% of organisations are still wondering if they were even impacted. Few organisations have matured their security operations (SecOps) to the point where they have integrated a complete CTI practice.

At ThreatQuotient, our mission is to advise and [support our customers as they plan](https://www.financedigest.com/how-to-support-clients-with-complex-succession-planning.html "How to support clients with complex succession planning") to enhance their SecOps by integrating a CTI practice at the core. Having worked on these projects for the past several years, we’ve seen that many of our customers rely on [Managed Security Service](https://www.financedigest.com/managing-the-hidden-security-gap-in-financial-services-the-office-printer.html "MANAGING THE HIDDEN SECURITY GAP IN FINANCIAL SERVICES: THE OFFICE PRINTER") Providers (MSSPs) or Managed Detection and Response (MDR) for the detection component of their SecOps, setting up processes and serving as tier-1 and tier-2 SOC analysts. These SOC [contracts are generally signed](https://www.financedigest.com/soccer-liverpool-boss-klopp-signs-new-contract-until-2026.html "Soccer-Liverpool boss Klopp signs new contract until 2026") for a minimum three-year period with the SOC service definitions and associated SLAs remaining fairly static during this period. While these contracts may specify the need for continuous enhancement, it can be extremely difficult to make significant [changes and update SLAs once the contract](https://www.financedigest.com/the-antibodies-contract-manufacturing-market-to-see-through-the-probable-sea-change-through-digitization.html "The Antibodies Contract Manufacturing Market to see through the probable sea change through digitization") is in place.

This limitation has [become even more problematic given the year](https://www.financedigest.com/scottys-little-soldiers-become-incentive-fm-groups-chosen-charity-in-three-year-partnership.html "Scotty’s Little Soldiers Become Incentive FM Group’s Chosen Charity In Three Year Partnership") of dramatic disruption every customer has experienced. Almost 20% of respondents told SANS that the pandemic has changed how they use threat [intelligence](https://www.financedigest.com/using-threat-intelligence-to-minimise-cyber-insurance-risks.html "Using Threat Intelligence to Minimise Cyber Insurance Risks") due to a rise in phishing and ransomware attacks and work-from-home threats. Moreover, the recent [rise of worldwide supply](https://www.financedigest.com/oil-rises-on-prospect-of-opec-supply-cut.html "Oil rises on prospect of OPEC+ supply cut") chain attacks has been a real game changer for defenders. However, strategic shifts to mature your SecOps and evolve your use of [threat intelligence](https://www.financedigest.com/russian-threat-to-baltic-security-rising-estonian-intelligence-report.html "Russian threat to Baltic security rising – Estonian intelligence report") by implementing a CTI practice are difficult to achieve if you’re outside a contract renewal window. That’s why it’s critical for [customers to think ahead about their SecOps maturity needs](https://www.financedigest.com/why-empathy-needs-to-sit-at-the-heart-of-bbls-and-cbils-customer-service.html "Why empathy needs to sit at the heart of BBLS and CBILS customer service") and work with their MSSP/MDR at contract renewal or during the RFP process to synchronise SecOps process evolutions. It’s the only way to ensure you’ll be able to onboard a CTI [platform when you’re ready and gain the benefit](https://www.financedigest.com/unlocking-the-code-how-to-benefit-from-low-code-platforms.html "Unlocking the code – How to benefit from low code platforms") of threat intelligence sharing, orchestration and collaboration.

Based on our experience helping customers navigate this situation, here are some of the [keys to global project success](https://www.financedigest.com/hiring-smart-is-the-key-to-success-for-entrepreneurs-heres-how-you-do-it.html "“Hiring Smart” is the key to success for entrepreneurs. Here’s how you do it.") when leveraging a SOC MSSP/MDR contract process.

**Don’t let the window close: The [time is now to move](https://www.financedigest.com/move-over-tina-its-time-for-tara.html "Move over TINA, it’s time for TARA") from being reactive to anticipatory**

Disruptions are a fact of life, and threat actors will continue to take advantage of them. A CTI platform allows you to take a proactive, and even anticipatory, approach to [security](https://www.financedigest.com/ferrostaal-group-formally-establishes-cyber-security-practice-in-middle-east.html) operations by profiling not only the attack, but attackers who rapidly change their tools, techniques and procedures (TTPs) to evade defensive technologies. With intelligence-based workflows, security operators can then use these insights into adversaries and how they are evolving to enrich internal surveillance, focusing on high priority and relevant threats and minimising alerts that are just noise or are false positives. Security teams can strengthen defenses by automatically sending relevant threat [intelligence](https://www.financedigest.com/military-artificial-intelligence-ai-market-surges-to-usd-35-54-billion-by-2031-propelled-by-14-49-cagr-verified-market-research.html) directly to the sensor grid, SIEM, logs, and ticketing systems, to proactively [protect the organisation](https://www.financedigest.com/protect-your-organisation-from-fraud.html "Protect your organisation from fraud") from future threats. In such a set-up, the customer SecOps teams can create detection policies in real-time and actively collaborate with the MSSP/MDR to [perform crisis management](https://www.financedigest.com/goodbye-excel-spreadsheets-hello-performance-management-tools.html "Goodbye excel spreadsheets, hello performance management tools") when a new, massive threat appears.

**CTI serves and is fed by all four functions of your SecOps**

[Security](https://www.financedigest.com/ferrostaal-group-formally-establishes-cyber-security-practice-in-middle-east.html) operations typically consist of four main functions: the defense team, [risk management](https://www.financedigest.com/aon-launches-new-catastrophe-model-to-manage-the-risk-of-icelands-most-disastrous-peril-earthquake.html "Aon launches new catastrophe model to manage the risk of Iceland’s most disastrous peril: Earthquake"), the SOC for detection, and the incident response team (Figure 1). With a CTI platform, you can leverage threat intelligence across these functions to better understand your adversaries and their tactics, techniques and procedures (TTPs) so you can strengthen defenses, mitigate risk, and accelerate [detection and response](https://www.financedigest.com/endpoint-detection-and-response-market-is-projected-to-expand-at-a-cagr-of-21-from-2020-to-2030-tmr.html "Endpoint Detection and Response Market Is Projected To Expand At A CAGR of 21% from 2020 To 2030 | TMR") in a homogeneous and efficient way. As tools and [teams in each of these four areas gather additional](https://www.financedigest.com/tailify-bolsters-leadership-team-with-addition-of-julia-burton-brown-as-commercial-director.html "Tailify bolsters leadership team with addition of Julia Burton Brown as Commercial Director") threat data, learnings and observations, they can feed that information into your CTI platform to create an organizational memory. Intelligence is automatically reevaluated and reprioritised based on this new information, so the CTI [practice continues to improve by leveraging trusted](https://www.financedigest.com/exact-launches-practice-management-solution-to-help-transform-accountants-into-trusted-business-advisors.html "Exact launches Practice Management solution to help transform accountants into trusted business advisors") and timely information that helps accelerate the right actions and allows real threat data-driven orchestration across all SecOps tools.

**A CTI practice requires some modifications to all four functions, including the SOC MSSP/MDR contract**

When you introduce a CTI practice into the core of your security operations (Figure 2), every function must adapt to work with a CTI platform in order to [benefit from collaboration and communication](https://www.financedigest.com/teach-first-reaps-the-benefits-of-joined-up-communications-with-via-voice.html "Teach first reaps the benefits of joined-up communications with via voice ") (SIEM, SOAR, EDR, etc.). Some [service providers are able to accelerate the process because they offer](https://www.financedigest.com/why-the-banking-industry-needs-to-offer-more-than-just-enticing-perks-and-subscription-services.html "Why the banking industry needs to offer more than just enticing perks and subscription services") a CTI capability as part of their practice. For others, a bit more work needs to be done to their processes and SLAs to [ensure successful](https://www.financedigest.com/strategic-budgeting-ensures-success-of-community-support-programs.html "Strategic Budgeting Ensures Success of Community Support Programs") onboarding of a CTI platform. In either case, modifications are simpler and faster when initiated at contract time. Otherwise, you risk missing out on the full value a CTI practice can [bring to your business](https://www.financedigest.com/how-to-bring-business-and-charities-together-through-events.html "How To Bring Business And Charities Together Through Events").

**The CTI practice can be activated when you are ready**

If you are working with an MSSP/MDR that already has a CTI practice offering, they can provide a CTI [platform for your environment and over time transfer the skills to run](https://www.financedigest.com/aon-empowers-cat-modellers-to-run-any-model-on-its-enhanced-elements-10-platform.html "AON EMPOWERS CAT MODELLERS TO RUN ANY MODEL ON ITS ENHANCED ELEMENTS 10 PLATFORM") the CTI practice to your team. Should you decide to have the service provider continue to run the CTI practice for you, the threat memory is yours and remains on your site for reuse to continue to improve prevention, blocking and global analytics. This is the implementation model we have seen the most in the past 12 months, but it’s early days and service providers are [working together with their customer SecOps teams](https://www.financedigest.com/finance-teams-have-been-left-in-the-dark-on-the-real-cost-of-working-from-home.html "Finance teams have been left in the dark on the real cost of working from home") to optimise the path forward. If the MSSP/MDR doesn’t have a CTI practice offering (unlikely nowadays), look for a CTI platform that leverages a flexible [data model and supports open intelligence sharing](https://www.financedigest.com/chipmakers-weigh-on-european-shares-focus-on-u-s-jobs-data.html "Chipmakers weigh on European shares; focus on U.S. jobs data") standards to ensure efficient and effective connectivity and communication. The goal is to be “CTI practice ready”, even if you aren’t ready to activate the program right away.

The escalation of cyberattacks over the [last few months](https://www.financedigest.com/fintech-trends-to-look-out-for-during-the-last-six-months-of-2019.html "Fintech trends to look out for during the last six months of 2019") has shown us there’s no time to waste in maturing your SecOps program. A reactive [security](https://www.financedigest.com/ferrostaal-group-formally-establishes-cyber-security-practice-in-middle-east.html) posture, where you are in a cycle of detect and respond only, is not a viable option anymore. You [need to make sure](https://www.financedigest.com/need-additional-funding-but-not-sure-how-to-go-about-it.html "Need additional funding but not sure how to go about it?") you’re leveraging threat intelligence throughout your security operations to understand your adversaries, strengthen defenses, and accelerate detection and response by turning your SecOps into an anticipatory program. When you work with your SOC MSSP/MDR at contract time, you remain in control of the timeline and aren’t forced to wait another three years for the next contract negotiation cycle to gain the [full value](https://www.financedigest.com/are-you-getting-full-value-from-your-outsourcing-partnerships.html "Are you getting full value from your outsourcing partnerships?") of a CTI practice and platform.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

