top of page

SOC monitoring: what no CISO can do?

  • Jul 28
  • 6 min read

The policy is approved. Forty pages, signed, dated, the registration number filed in KSIS - Lithuania's national cybersecurity information system - within five working days, exactly as required. The risk assessment is done, the procedures are written, the staff have completed their cyber hygiene training.


Friday, 19:40. The accountant's account signs in to the document system. The login succeeds - the password is correct. Over the next hour, several hundred files are downloaded from that account. The accountant herself is at her country cottage, weeding strawberries, and knows nothing about it. The policy states precisely what to do in this situation.


But a document does not watch a screen. SOC monitoring - the continuous tracking of systems, accounts and network events, carried out by a security operations centre (SOC) - exists to spot unusual behaviour before it becomes an incident. It answers the one question no procedure can resolve: is anyone in your systems who has no business being there?


What a CISO does - and what the law does not allow them to do


Lithuania's Cybersecurity Law (KSĮ), which transposes the EU NIS2 directive, requires any company that becomes a cybersecurity entity to appoint a cybersecurity manager - in practice, a CISO - reporting directly to the company's chief executive (Article 15). Their work is risk assessment, procedures, supplier requirements, deadlines, training and compliance. We covered this separately: it is closer to the job of an architect than a bricklayer.



  • IT administrator
  • CISO
  • SOC


Under the Cybersecurity Requirements Description (KSRA), the regulation implementing the law, the CISO may not perform functions relating to administering networks or information systems or maintaining equipment. This is deliberate, not an oversight: nobody can review their own work objectively. One very concrete consequence follows: the person accountable for your company's security is, by law, not the person watching the systems run.


So even an excellent CISO - in-house or bought as a service - will not tell you on a Friday evening that someone is signing in to the accountant's account. Not because they are doing a poor job, but because it is neither their role nor their working hours.


One further conclusion follows for the chief executive: NKSC, Lithuania's National Cyber Security Centre, states that a fine for failing to meet cybersecurity requirements is imposed on the company's chief executive, not on the CISO. So „is anyone actually watching our systems?" is a question for the chief executive, not the IT department.


The 24-hour clock starts when someone finds out


Article 18 of the Cybersecurity Law sets clear deadlines. A significant cyber incident must be reported to NKSC without delay and no later than 24 hours from the moment of becoming aware of it. Within 72 hours - an initial impact assessment. Within one month - a final report stating the root cause that may have allowed the incident to happen. Anyone familiar with NIS2 incident reporting elsewhere in the EU will recognise the same three-stage structure.


Kibernetinio incidento eiga

Note the wording: the clock starts not at the breach, but at the moment someone becomes aware of it. The entire obligation rests on a single assumption - that there is somebody in your company to become aware.


Figures from the State Data Protection Inspectorate (VDAI), Lithuania's data protection authority, show what that means in practice. In its national cybersecurity status review, 29% of 2025 personal data breaches were caused by cyber incidents, and in 6% of all notifications the cause was never established. VDAI's conclusion is blunt: after an incident, organisations „are unable to properly investigate the cyber incident and establish its causes".


You cannot establish a cause without event logs - and they need to be not only switched on but still retained, with somebody who knows how to read them.


22 seconds instead of eight hours


How much time do you have? Less than you would think.


Attackers have long since divided the labour: some only force the door into a company's systems, then hand that access to others who encrypt the data and demand a ransom. According to Mandiant's M-Trends 2026 report, in 2022 more than eight hours passed between the initial breach and that hand-off. In 2025 it was 22 seconds. Everything the second team will need is staged in advance, during the initial infection.


Other figures from the same report, drawn from more than 500,000 investigation hours: median time from breach to detection is 14 days (Latvijas valsts meži noticed only once the attackers began encrypting the company's data), rising to 122 days in espionage cases. Only 52% of the time do organisations detect malicious activity themselves first. Almost half find out from the outside - from a partner, a customer, a regulator, or a ransom note.


Mandiant's recommendation to defenders after those numbers: treat even an apparently insignificant alert as a signal that a serious intrusion is about to follow.

Tomorrow morning is no longer a good response time.

„Isn't this only a problem for large companies?"


The headline Lithuanian statistics for 2025: 2,888 cyber incidents recorded - a quarter fewer than in 2024 - and only 19 significant incidents.


Just one line in the same review moves the other way. Incidents in the information systems of Lithuanian legal entities almost doubled in a year - from 155 to 280. More than half of all incidents involved social engineering, and user account takeover remains the leading intrusion method - precisely what happens in the Friday 19:40 scene. Worth noting too are the amendments to the Cybersecurity Law that took effect in July, under which still more companies may be added to the register of cybersecurity entities.


One legal detail is rarely discussed. Under Article 16, NKSC deploys and operates its own technical monitoring measures in the systems of essential entities. For important entities they may be deployed only at the entity's request, and only to contain an incident. In plain terms: if you are an important entity - the NIS2 category most foreign-owned subsidiaries in Lithuania fall into - day-to-day monitoring is your job, not the state's.


How SOC monitoring connects to what you already have?


If you already have a CISO - your own employee or a bought-in service - nothing needs dismantling. One loop needs closing, and three things are enough for that.


First, the people doing the watching need to know what matters to your company. The risk assessment your CISO prepared is not a document for the archive - it is the list of what to watch first. Without it, SOC monitoring becomes noise: hundreds of alerts with no order of importance.


Second, there must be an agreed path by which an observation reaches a human being on a Friday evening. Not a shared mailbox, but names and phone numbers, and a clear statement of who has the authority to disable an account without waiting for morning.


Third, the observation has to travel back onto paper. The same fact becomes the 24-hour notification to NKSC, the root cause in the one-month report, and a change to next quarter's risk assessment. That is CISO work again - and it needs raw material the CISO simply does not have without monitoring.


SOC veikla

Three questions worth asking this week


  1. If someone signed in to our systems from an unusual location tonight at 19:40, when would we find out? A bad answer: „probably Monday." A worse one: „when somebody called to tell us."

  2. Who is appointed as our cybersecurity manager, and does that same person administer our systems? If so, that does not meet the requirements, however well they do the job.

  3. Could we give NKSC a final report with a root cause within one month? That means event logs that still exist and are accessible. A bad answer: „logs are kept for 30 days."


If there is no answer to even one of them, that is not a reproach - just a map of where you currently stand.


Back to that Friday evening


Documents do their job: they set out what risks the company has, how to reduce them, and what to do when an incident happens. But between „it is written down" and „somebody noticed" there is a gap no document fills - and the faster attackers work, the more expensive that gap becomes.


That is exactly what our SOC service is for. If you do not know who in your company would answer the first of those three questions - let's talk.




 
 

Take the first step

Cybersecurity compliance doesn't happen in a day - contact us and start working towards it

bottom of page