Back to glossaryCyber

SOC / CIRT (Security Operations Center / Cyber Incident Response Team)

Security monitoring and cyber incident response team, whose existence and maturity are a cyber underwriting criterion.

Definition

A SOC (Security Operations Center) is a team dedicated to the continuous monitoring, usually around the clock, of an organization's information systems security. It analyzes security alerts, correlates suspicious events and qualifies potential incidents before deciding on escalation or response. A CIRT (Cyber Incident Response Team), sometimes called a CSIRT (Computer Security Incident Response Team), is the team responsible for operational response once an incident is confirmed: containment of the compromise, digital evidence collection (forensics), remediation and return to normal. The two entities are often linked or merged in large organizations. For cyber underwriting, the existence of an internal or outsourced SOC is a major maturity indicator, correlated with shorter detection and containment times, and therefore less extensive losses. The cyber assistance clause in modern policies generally provides access to an external CIRT hotline, activable immediately upon a loss, for insureds who lack this capability in-house.

Example

An insurer observes that its insureds with a 24/7 SOC report ransomware losses with a median dwell time of 4 days, versus 22 days for insureds without a SOC. This gap translates directly into remediation costs, reducing the average loss by 60 percent.

Related terms
Also known as

SOC, CIRT, CSIRT, Security Operations Center, Cyber Incident Response Team