IR and SOC against the haunted house

IR and SOC against the haunted house

IR and SOC against the haunted house

Our story begins...

...when the young Duke of Securington acquires a small mansion on the outskirts of the tranquil town of Little Incident. For generations, local residents have been telling stories about the nearby cemetery - which is rumoured to be haunted. The Duke of Securington, however, does not believe in such tales - and moves in with his young family. But one night he is startled out of his sleep - he hears a rumbling and howling. He quickly jumps up and dresses as well as a gentleman can in the blink of an eye: In pyjamas and top hat. He quietly stomps across the creaking wooden floor, the rumbling getting louder and louder. What could it be? "From the cellar - that must be where it's coming from". He slowly turns the knob of the old cellar door and hesitantly opens it. As he takes a look into the cellar, his face freezes into a still life: There is indeed a small ghost sitting in his vault, throwing boxes and pieces of furniture around. Duke's gaze quickly falls on the weak spot swaying back and forth: it must have slipped in through the cellar window. The Duke quickly lets the door fall into the lock and pushes the old bookshelf in front of it - his gaze falls on an old book: The Haunting of Little Incident - A Guide for the Haunted. As he blows a thick layer of dust off the book, he opens the cover: "Chapter 1: Immediate measures" it says. "Important: Never open the basement window." And at the bottom is a small note: "Be sure to call: 555-44678 - Van Helsing - Ghost Hunters and Co."

Modern ghost hunters

In the series X-Factor: The Incredible, Jonathan Frakes would now look into the camera and ask: "Do you think this story is made up?". And indeed, this kind of thing happens all the time - especially in IT. What happened to the Duke of Securington above happens to companies around the world almost every day. Not in the basement - but the entire IT of companies is the target of cyberattacks. We at suresecure are the ones who prevent precisely these scenarios. What makes us so successful? Our experience.

There are usually different teams for Incident Response (IR) and for the Security Operations Centre (SOC). We combine these resources and this has several advantages:

  • Our specialists learn from all incidents and contribute their expertise to the SOC. This means we are always up to date. Current attack scenarios can be taken into account immediately. This allows us to create use cases from which all our partners benefit immediately.  

  • Short information chains. Teams do not have to be engaged or informed externally.  

  • Contact persons are known.

  • Standardised procedures simplify processes.  

This early detection and procedure can often make the difference between full and partial encryption - and thus between very high amounts of damage. These usually consist not only of monetary damage, but also the damage to the company's image when an attack becomes known is often immense. And the detection of an incident by the SOC and the subsequent processing by this team of experts is therefore worth more than gold.  

High damage without SOC

With a connected SOC, high-level coordination meetings with an IR manager do not have to take place at this point in the event of an incident. The IT infrastructure is already known, contacts and reporting chains have already been clarified. This significantly shortens the time it takes to deal with the security incident. A SOC significantly reduces the probability of a dramatic attack. If a successful attack does occur, the probability of major damage is significantly reduced.

Image

Another advantage of our experience is the psychological aspect. For our partners, incidents are often a very stressful and sweaty affair. Thanks to our ever-growing experience and daily dealings with incidents of this kind, our IR managers are often able to provide mental support. This is also part of our expertise.  

"Incident response management is not a sprint, it's a marathon. Take breaks! Have a drink! Be aware that you haven't done anything wrong! The partners are usually also very grateful for mental help!"

Manager Security Operations

This is how it went from our Duke of Securington, by the way. A year later, the alarm light went on in the ghost hunters' headquarters. The ghost security system had sounded the alarm! It was the cellar window again. Van Helsing immediately sets off. In the pouring rain, he knocks on the door of the villa. He hears quiet footsteps from the other side. The loud clanging of several locks can be heard. As the oak door starts to move with a deep squeak, light penetrates outside. And in the rays, the Duke of Securington appears in the doorway - a grey cat in his arms - with wet, slick fur. "It was raining - so I let this stray cat in. Everything is all right. Thank you for being so vigilant and coming straight here. We're safe thanks to you. And there's one good thing for you: I have tea on the stove. I'd be happy to invite you in."

Screen Shot 2025-05-15 at 13-1374.png

Philipp Lessig

Content Creator

Published on 17.05.2025