Sony’s Charles Anderson on How to Manage Detections and Risk Across a Global Company
Jan 24, 2024
Managing the global SOC for a company as big as Sony has its challenges — specifically in that there's no one-size-fits-all solution to detection at scale. But as Charles Anderson, Director, Global SOC at Sony, explains in our newest podcast episode, they've figured out some best approaches and practices to mitigate risk across the organization.
Here are the top takeaways:
Use metadata to improve risk-based alerting. Sony's SOC takes a layered approach to alerting. But they also track the metadata of their detection content. That way they can look at low fidelity alerts and make connections — like seeing sequential kill chain phases.
In a global company, you may need a more complex approach to tuning. A company as large as Sony needs specialization, so their approach today uses a baseline condition layered with content that has different scopes. This allows for the flexibility they need at scale while also ensuring high-quality detections.
Think about your detection content as classification algorithms. Charles says that when you take this approach, you can borrow knowledge from the software engineering industry on how to grade the quality of algorithms. However, your approach should always align with what leadership will care about the most.
Track metrics like Time to Detect to help with strategy. Sony tracks Time to Detect for every piece of detection content individually. They do so in order to see the full story of their program and identify where they can make improvements in their approach. Tracking metrics allows for a "fail fast and fix it" approach.
By continuing to use this website you consent to our use of cookies.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.