How to Build a Modern Security Operations Center

TL;DR
Build a modern security operations center around three connected capabilities: flexible data access, advanced analytics, and operational workflows. Use machine learning to augment human judgment, automate repetitive tier-one work, and unify analysts’ tools so teams can observe threats, add context, decide quickly, and coordinate effective responses at machine speed.
Transcript
Good afternoon, everyone. My name is Haiyan. I, uh, flew all the way from San Francisco, and, uh, I lead the cybersecurity business for Splunk. Some of you, uh, have asked me why the name Splunk? What does it mean? S-it actually came from the word spelunking, which means under cave s-exploration. The underground caves are dark, just like the data t... Read More
Key Insights
- A cybersecurity strategy depends on its underlying data strategy because machine data, business context, and threat intelligence provide the evidence needed to understand risks. Without technology that makes diverse data usable and accessible, valuable security information can remain hidden and difficult for analysts to apply.
- Automation is essential to security operations because it addresses both shortages of skilled cybersecurity professionals and the speed of modern attacks. Machine-speed monitoring and response can handle codifiable work quickly, allowing people to focus on decisions that require intuition, advanced reasoning, and direct intervention.
- Global cyber defense requires collaboration because adversaries already share information and coordinate activities across borders. Security organizations therefore need ways to exchange intelligence, cooperate on investigations, and coordinate responses rather than treating every threat as an isolated problem handled by one team or technology.
- Compliance and risk monitoring are continuous activities because privacy concerns, government regulation, and changing digital environments do not remain static. Treating compliance as a one-time checkbox cannot provide the ongoing awareness required to understand evolving exposure and maintain assurance across an organization.
- Cloud, APIs, mobile systems, edge computing, and industrial IoT are changing security boundaries. Cloud blends security with DevOps, APIs reshape application development, mobile and edge systems redefine endpoints, and industrial IoT blurs the distinction between information technology and operational technology networks.
- The OODA loop organizes security operations into four capabilities: observe, orient with context, decide, and act. Executing this cycle quickly helps defenders transform collected information into informed decisions and coordinated action, reducing the operational gap between security teams and fast-moving adversaries.
- A modern security operations center rests on three technology foundations: data, analytics, and operations. The data platform collects and contextualizes information, the analytics engine supports faster decisions, and the operations platform turns decisions into workflows while orchestrating technologies and automating responses.
- A future security operations center should aim to automate at least 90 percent of repetitive tier-one work. This goal is intended to redeploy scarce human expertise toward investigations, intuition-driven judgments, higher-order reasoning, and exceptional situations that have not yet been translated into automated playbooks.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How do you build a modern security operations center?
Build the security operations center around three connected foundations: data, analytics, and operations. Use a flexible data platform to access information from different locations and add context. Apply analytics and machine learning to augment analysts and accelerate decisions. Finally, use an operations platform to turn those decisions into workflows, orchestrate the technology stack, and automate appropriate monitoring and response activities.
Q: What is a security nerve center?
A security nerve center is a model for a modern security operations center inspired by the human brain and nervous system. It helps an organization adapt by bringing information, context, decisions, and actions together. Its core process follows four capabilities: observe available signals, orient those observations with context, decide what should happen, and act through coordinated operational workflows.
Q: How does the OODA loop apply to cybersecurity?
The OODA loop applies to cybersecurity by structuring defense into four recurring steps: observe, orient, decide, and act. Security teams first collect relevant signals, then interpret them with business and threat context. They make a decision based on that combined understanding and execute a response. Faster execution of this loop helps defenders compete with rapidly moving adversaries.
Q: Why does cybersecurity need a data strategy?
Cybersecurity needs a data strategy because digital systems generate large volumes of machine data that may contain evidence about identities, business activity, risks, and threats. A flexible platform must make that data accessible and usable, combine it with business context and threat intelligence, and support analysis. Without this foundation, security decisions lack the broad observations and context required for effective action.
Q: Why is automation important in security operations?
Automation is important because security operations face both a shortage of skilled personnel and a need to respond at machine speed. Repetitive, manual, and codifiable tier-one tasks can be handled through automated playbooks. This reduces delays and allows valuable analysts to concentrate on investigations, intuition, higher-order reasoning, and situations where human intervention is still necessary.
Q: What should security teams automate first?
Security teams should prioritize repetitive tier-one work that is manual but can be codified into playbooks. The stated goal is to automate at least 90 percent of this category of work. Automation should support monitoring and response while preserving human involvement for complex investigations, root-cause analysis, forensic work, unusual incidents, and decisions that cannot yet be reliably encoded.
Q: What capabilities should security operations technology provide?
Security operations technology should ingest data, business context, and threat intelligence, then support both detection and prediction. It should orchestrate and automate responses, recommend suitable playbooks or analysts, accelerate investigation and root-cause analysis, enable collaboration and containment, manage cases, produce reports, and provide metrics that teams can use to measure improvements and refine their operations continuously.
Q: How are cloud and connected technologies changing cybersecurity?
Cloud changes how organizations develop and consume computing infrastructure, making security integration necessary rather than an afterthought. It also blends security with DevOps. APIs reshape application development and application security, while mobile and edge computing redefine endpoint protection. Industrial IoT further blurs information technology and operational technology, requiring new approaches to protecting operational networks and their IT connections.
Summary & Key Takeaways
-
Cybersecurity strategy must be supported by a coherent data strategy because expanding digital systems create large volumes of machine data that otherwise remain difficult to use. Organizations need flexible access to data, business context, and threat intelligence so analysts can identify risks, understand incidents, and make informed decisions across complex environments.
-
A modern security operations center functions like a security nerve center by following the OODA loop: observe, orient, decide, and act. Its foundation consists of data, analytics, and operations. Together, these capabilities help teams collect diverse information, augment human reasoning with machine learning, and convert decisions into coordinated workflows and responses.
-
Security operations should automate repetitive tier-one activities while reserving human talent for intuition, higher-order reasoning, and situations that cannot yet be encoded into playbooks. An integrated analyst experience should also support prediction, recommendations, investigation, collaboration, containment, case management, reporting, measurement, orchestration, and continuous delivery of actionable intelligence.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator