As organizations increasingly decentralise and adopt diverse technologies, the traditional security operations centre / center (SOC) model is struggling to keep pace with the expanding attack surface and volume of data to be monitored and protected. This shift necessitates a reimagining of SOCs to remain effective and agile amidst ever-evolving threats and business landscapes. In this article, James Todd explores how to design a future-ready SOC, proposing a new reference architecture to tackle these challenges.
Resilience Resources
The Institute of Directors New Zealand has released a new resource to help boards understand AI. The guide aims to help directors develop and improve governance and risk management of this area.
The Cloud Security Alliance’s (CSA) AI Technology and Risk Working Group has developed a new document that explores the role of AI-powered tools in reshaping offensive security strategies.
The US Small Business Administration (SBA) has published ‘Business Resilience Guide: Reducing Risks and Building on Strengths’, providing a resource to help small businesses plan and recover from disasters.
The UK Government Cabinet Office has published ‘Organisational Resilience Guidance for UK Government Departments, Agencies and Arm’s Length Bodies’.
Robert Hall looks at the foundational elements of resilience and explains how they enable an entity to bounce forward in times of disruption, crisis, and change.
The Royal Academy of Engineering’s Engineering X community has published a new report which looks at lessons that can be learned from failures in complex systems.
A recent report highlighted that many people found that existing business continuity plans didn’t really help during ransomware incident response. Charlie Maclean-Bristol gives ten reasons why this might be the case.
In 2009, the Cloud Security Alliance (CSA) released its first Security Guidance for Cloud Computing document. 15 years later, it has published the fifth version, Security Guidance for Critical Areas of Focus in Cloud Computing.
Darren Guccione outlines the changes in the European Union’s NIS2 regulation compared to the current NIS regulation and how organizations can effectively prepare for October 17th 2024: the deadline when EU member states need to ‘transpose its measures into national law’.









