What does a modern SOC really look like? Craig Gilliver (Head of Cyber, Sector Alarm Group) joins me to unpack how to build a security operations function that fits the business you actually run. Coverage that matters, visibility you can act on, and costs you can defend!
We get into: why every SOC should start with business risk (not “collect everything”); the coverage vs. storage trade-off and how to show ROI beyond license spend; why SOC teams often become “productive disruptors” who expose missing owners, undocumented systems and CMDB gaps; and how to keep analysts sharp when the alert firehose never stops.
Craig also tackles the AI hype head-on & why attacker tooling is evolving faster than many defenses. Listen to his pragmatic take on The Board conversation: security is one voice at the table, so bring signal, not noise.
If you’re building, rebooting or right-sizing a SOC, this one’s a blueprint.