Organizations will spend more on security operations, but CISOs need metrics to demonstrate ROI. Credit: Thinkstock Overall, security operations are quite difficult, many organizations complain about too many manual processes, too many disconnected point tools, and a real shortage of the right skills. These issues can lead to lengthy incident detection and response cycles or worse yet, damaging data breaches. Just ask Equifax.A recent ESG survey of 412 cybersecurity and IT professionals about their organization’s security analytics and operations found organizations know they have problems and are willing to address them. For example, 33% say their spending on security operations will increase significantly, while another 49% indicate that their security operations spending will increase somewhat.While security operations spending will increase, it’s worth noting that 30% of cybersecurity professionals say that their biggest security operations challenge is the total cost of ownership. What does this mean? CISOs are willingly spending millions of dollars on security operations but getting marginal security efficacy and poor operational efficiency.How CISOs can improve security operationsAs the ESG data points out, business executives are more than willing to throw money at security operations problems, but they will demand that CISOs present them with all types of metrics demonstrating that increased investment is actually leading to improved results, such as improving the time needed for incident detection and response. Bolstering these metrics won’t be easy, but based upon ESG research, CISOs can make progress by doing the following:Creating a SOAPA integration plan. Leading CISOs are actively consolidating security technologies, eliminating vendors, and building a security operations and analytics platform architecture to unify detection and response tools across a common architecture.Pushing for process automation and orchestration. Even well-resourced security teams can’t keep up with the scale and complexity of today’s threat landscape. Progressive organizations are using automation and orchestration for use cases such as investigations, threat hunting, and automated remediation to accelerate processes.Unifying security and IT operations teams. Too often these teams have different goals and compensation, and they use diverse sets of tools in pursuit of their organizational mission. CIOs and CISOs are getting together to tear down walls between these groups, while SOAPA enables disparate groups to share data, prioritize tasks, and automate remediation actions.Adopting advanced analytics. Amidst all of the industry hype, true innovation is happening in areas such as artificial intelligence and machine learning. CISOs should carefully research these technologies, determine which analytics tools fit their organization’s skills and strength, and embrace pilot projects.As CISOs move forward with these initiatives, they should continually determine how to measure and report incremental and ongoing advancement they achieve with risk management, security efficacy, and operational efficiency. Successful CISOs will be the ones who can demonstrate and communicate real and honest progress anytime they are asked to do so. Related content analysis 5 things security pros want from XDR platforms New research shows that while extended detection and response (XDR) remains a nebulous topic, security pros know what they want from an XDR platform. By Jon Oltsik Jul 07, 2022 3 mins Intrusion Detection Software Incident Response opinion Bye-bye best-of-breed? ESG research finds that organizations are increasingly integrating security technologies and purchasing multi-product security platforms, changing the industry in the process. By Jon Oltsik Jun 14, 2022 4 mins Security Software opinion SOC modernization: 8 key considerations Organizations need SOC transformation for security efficacy and operational efficiency. Technology vendors should come to this year’s RSA Conference with clear messages and plans, not industry hyperbole. By Jon Oltsik Apr 27, 2022 6 mins RSA Conference Security Operations Center opinion 5 ways to improve security hygiene and posture management Security professionals suggest continuous controls validation, process automation, and integrating security and IT technologies. By Jon Oltsik Apr 05, 2022 4 mins Security Practices Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe