Nobody Knows the Risks I Have Seen: Evaluating the Gap Between Risk Analysis and Security Operations
Nathan Daniel Schiele, Jari Egberts, Olga Gadyatskaya · 2024
Maintaining cyber security is becoming increasingly difficult, forcing organizations to turn to security service providers. These security service providers use teams with different skills to provide security outcomes for their clients. These teams often consist of risk analysts (RA) and security operations (SO) experts. It seems natural to expect that these complementary team members will inform each other about relevant security threats. Yet, this is not always the case. We have conducted a qualitative case study to examine the communication process between RA and SO within a large cyber security service organization. We conducted a series of semi-structured interviews with security experts ($n=11$) who are either in RA or SO to find what tasks they regularly perform, how they communicate with other teams, and what areas of improvement they would find useful. The transcripts of these interviews were analyzed with template analysis. We found that both RA and SO feel a communication gap, which they sometimes attribute to differences in teams' backgrounds. Use-case implementation has been identified as a potential major area of improvement as a means of communication between RA and SO. Finally, we also observed that some issues are related to communication with clients and low levels of maturity in client's processes.