The Quarterly – Q3 FY25

Time to pull your SOCs up

Cyber security in financial services is a hot topic – especially after the major cyber attack that shook the superannuation industry in early April. Thankfully, the targeted super funds had implemented cyber security measures sufficient to prevent truly catastrophic outcomes for members. As APRA regulated entities, these funds are obliged to comply with CSP 234 – the outcome of which is solid detection and response capabilities. It’s thanks to compliance with CPS 234 that the malicious activities in April were detected early, therefore minimising damage. However, the range of ways in which threat actors can get at sensitive data, and the speed at which attacks can unfold is only increasing.

This reality has been front of mind for Novigi, as we recognise the role we can play in further bolstering the super sector’s cyber resilience through services such as MSOC (Managed Security Operations Centre). Most of our audience will have heard of SOC, but fewer will have heard of its outsourced twin, MSOC. MSOC is a highly specialised service that is provided to entities that do not have specialist, inhouse security teams. It’s a more cost-effective solution, that ensures your organisation is meeting APRA requirements, keeping abreast of the latest threats, and continuously updating the proactive approaches required to stay ahead of threat actors.

Before launching into solution mode, we needed to do a pulse check with industry leaders. Through five interviews with leaders in super funds and service providers, we set out to understand what keeps cyber leaders up at night, and what they want to see more of in the future. While the sample size for this research was small, the output was mighty! Here are the big-ticket items that came up in the interviews.

Prevalence of SOC

The interviews revealed that four out of five respondents already have a formal SOC in place. The remaining one respondent noted that their organisation has some level of informal, in-house SOC coverage. Diving deeper into the structure of these SOCs revealed that:

    • 2 of 4 respondents outsource their SOC
    • 1 of 4 respondents has an insourced SOC
    • 1 of 4 of respondents have a hybrid SOC, where some elements are outsourced, and others, insourced

Decision making around insourcing and outsourcing largely related to the organisation’s technological capacity. Some players in the super space are just as much tech providers as they are administrators or funds. Others know that technology is not within their core capability and choose to outsource their SOC to professionals.

While the presence of a SOC is now widespread, 60% of respondents noted that their SOC still needed to mature. Respondents were able to clearly articulate their vision of a mature SOC – defined by the service’s understanding of the organisation they’re servicing, eliminate key-person dependencies, and clear SLAs that are adhered to, for example. The consequences of an immature SOC should be taken seriously. While having a SOC is not the silver bullet that will resolve all the world’s cyber security issues, they certainly help minimise the potential damage of dubious threat actors.

Proactive protection

Across the board, interviewees expressed the need to evolve beyond traditional monitoring and response to embrace proactive protection. This includes activities like threat hunting, proactive penetration testing, prompt response times to incidents, and incident simulations. These activities are now considered to be standard activities in a modern SOC. One respondent shared that it “always feels like we’re reactive, rather than proactive. We feel like we’ve got to spend a lot of time and effort understanding what’s going on…so we can judge whether that [cyber threat] could happen to us”. Another respondent notes that SOCs often operate “…as an external handoff rather than being proactive or embedded in the team.” This sentiment was shared among many respondents, who similarly felt that a united front, upheld by both the SOC and the fund/service provider, was something that hasn’t been successfully achieved across the board.

Expectations around proactivity also extend to information sharing. There’s a push toward integrating threat intelligence and behavioural analytics, with some organisations pursuing industry-specific intelligence feeds to reduce irrelevant noise. One respondent commented, “I feel like there’s a gap in the industry to share information about the dominant ways in which super sector is being targeted at that time”. This same respondent noted that the most common means of intelligence sharing is via ACSC (Australian Cyber Security Centre), however, their alerts can be “really slow” – sometimes running four to five days behind the incident. Information sharing is key to our collective success in the superannuation industry. Failing to do so will leave us all vulnerable.

Reporting

One of the strongest recurring pain points from the interviews was around the quality and relevance of SOC reporting. Specifically, participants want reporting that is:

1. Real-time or close to it

2. Understandable by a wide range of stakeholders (including regulators and auditors) 

3. Tailored to the business’s actual operating model and objectives

All respondents noted that dashboard reporting was the desired means by which this information is communicated. The benefit of this mode of communication is the concise, clear and comprehensible nature of data visualisation, enabling various parties to quickly grasp the current state of play. Some respondents commented that thorough, current and tailored reporting enables them to better demonstrate to regulators and auditors the efficacy of their controls and response times. Overall, the sentiment among respondents was that SOC reporting was not meeting expectations, nor making their lives any easier when it comes to communicating with regulators. Reporting for regulators was noted as a pain point by the majority of respondents, especially in light of increased reporting requirements under CPS 234 and CPS 230. Under these regulations, funds must demonstrate not just the existence of controls, but their effectiveness in design and operation—a standard many SOCs are still racing to meet.

MSOC moving forward

The interviews concluded with two key questions –

1. Do you think your current SOC is delivering the highest priority characteristics and outputs your organisation requires?

2. Do you think your current SOC is futureproof?

The answers were very telling…

    • Only 25% of respondents could confidently say that they get the highest priority characteristics and outputs from their current SOC. The remaining 75% indicated that their SOC was only partly delivering these characteristics and outputs. Including things such as prompt response times to incidents, effective and prompt reporting, and a more collaborative relationship between their organisation and the SOC provider.
    • 75% of respondents commented that their current SOC is not futureproof

These statistics reflect the rift between what we expect from a modern SOC, and what organisations are currently receiving. SOC maturation in the form of consistent, high speed, high accuracy service were the big take-aways for us. While there are inevitably some SOC providers who are doing a stellar job, these interviews suggest that there are others who need to pull up their SOCs and improve their service, if you’ll pardon the pun.

 


Time to Pull Your SOCs Up is part of The Quarterly – Q3 FY25

The production of our quarterly report is led by Novigi’s Market Strategy and Propositions team: 

 

Kevin Fernandez

General Manager, Market Strategy & Propositions

Sophie Coianiz

Analyst, Market Strategy & Propositions

This article was also strengthened by a wider group of Novigi specialists, whose withering years of toil and rich experience added depth and clarity to the perspectives shared. 

Key Contributors:

 

Simon Tweedie

Executive General Manager, Workplace Technology

For more information about anything you’ve read here, or if you have a more general inquiry, please contact us.

Key Contributors

The people behind this edition

PRIVACY COLLECTION NOTICE

Pin It on Pinterest

Share This