3 Things CISOs Need to Know About Microsoft's ISOC Announcement
Cost pressure can decide what your security team gets to see. A useful log source gets left out. Investigation history gets shortened. Analysts work with the evidence the organization could afford to keep. That is the part of Microsoft's Integrated Security Operations Center, or ISOC, announcement I keep coming back to. Bringing SIEM capabilities into the Defender experience, using native security data, and changing the economics gives customers a reason to revisit those decisions.