How to overcome the 5 most common SecOps challenges

3014
Of your peers have already read this article.
3:00 Minutes
The most insightful time you'll spend today!
The success of the modern security operations center, despite the infusion of automation, machine learning, and artificial intelligence, remains heavily dependent on people. This is largely due to the vast amounts of data a security operations center must ingest—a product of an ever-expanding attack surface and the borderless enterprise brought on by the rapid rise of cloud adoption.
All those alerts coming in mean proactive and reactive human decision making remains critical.
Perhaps it should come as no surprise that the information security analyst now ranks as No. 1 News’ 100 Best Jobs Rankings, “determined by identifying careers with the largest projected number and percentage of openings through 2030, according to the U.S. Bureau of Labor Statistics.” Security, and specifically detection and response, is not only a business imperative—it is arguably the top worry on the minds of CEOs.
However, the security analyst is also one of the most likely professionals to want to leave their jobs, according to a newly released “Voice of the SOC Analyst” study conducted by Tines.
What gives? Turnover woes are attributable to several key SecOps challenges that never seem to budge.
1) Alert fatigue and false positives: Have you ever received so much spam or junk mail that you end up ignoring your new messages entirely, leading you to miss an important one? The same can happen for alerts. Too much noise is unsustainable and can lead to the real threats being missed, especially as perimeters expand and cloud adoption increases.
2) Disparate tools: Already in the company of too many point-detection tools, security operations professionals are saying hello to a few more in the era of remote work and increased cloud demands. The latest count is north of 75 security tools that need to be managed by the average enterprise.
3) Manual processes: Use case procedures that result in inconsistent, unrepeatable processes can bottleneck response times and frustrate SecOps teams. Not everything in the SOC needs to—or should be—automated, but much can be, which then frees up analysts and engineers to concentrate on higher-order tasks and be able to more easily train new employees.
4) Talent shortage: Death, taxes, and the cybersecurity skills shortage. As sure as the sun will rise tomorrow, so will the need for skilled individuals to wage the cybersecurity fight. But what happens when not enough talent is filling the seats? Teams must compensate to fill the gap.
5) Lack of visibility: Security operations metrics are critical for improving productivity and attracting executive buy-in and support, but SecOps success can be difficult to track, as reports can require a significant amount of work to pull together.
The caveat of course is that it would be rare to find a SecOps team working without the above challenges. As such, some of the immediate steps you can take to push back against these constraints focus on people-powered processes and technologies to remedy the issues.
According to a recent paper co-authored by Google Cloud and Deloitte:
Humans are—and will be—needed to both perform final triage on the most obtuse security signals (similar to conventional SOC Level 3+) and to conduct a form of threat hunting (i.e. looking for what didn’t trigger that alert).
Machines will be needed to deliver better data to humans, both in a more organized form (stories made of alerts) and in improved quality detections using rules and algorithms— all while covering more emerging IT environments.
Both humans and machines will need to work together on mixed manual and automated workflows.
So, what does this ultimately mean you must do to improve your security operations? Here are five practical suggestions:
Detect Threats More Efficiently
Efficiencies within the SOC can be realized from a SIEM solution that automatically detects threats in real-time and at scale. The right platform will support massive data ingestion and storage, relieve traditional cost and scaling limitations, and broaden the lens for anomaly and machine learning/AI-based detection. With data stored and analyzed in one place, security teams can investigate and detect threats more effectively.
Respond to Threats Automatically
SOAR can be a game-changer in terms of caseload reduction and faster (and smarter, especially when integrated with threat intelligence) response times. But before rushing headfirst into automation, you should consider your processes, review outcomes you are trying to achieve (such as reduced MTTD)–and then decide exactly what you want to automate (which can be a lot with SOAR). Once clear processes are determined where automation can contribute, SOC personnel are freed up to be more creative in their work.
Prioritize Logs
Many teams lack a strategy for collecting, analyzing and prioritizing logs, despite the fact that these sources of insight often hold the clues of an ongoing attack. To help, here are two cheat sheets featuring essential logs to monitor.
Outsource What You Can’t Do Yourself
Process improvements may help you compensate for perceived personnel shortages (for example, perhaps fixing a misconfigured monitoring tool will reduce alert noise). Of course, many organizations need additional human hands to help them perform tasks like round-the-clock monitoring and more specialized functions like threat hunting. Here is where a managed security services provider or managed detection provider can be helpful. Be realistic about your budget, however, as you may be able to introduce some solutions in-house.
Institute Career Models
Lack of management support is cited as the fourth-biggest obstacle to a fully functioning SOC model, according to the 2022 SANS Security Operations Center Survey. To overcome this, SecOps leaders must help improve workflow processes, protect innovation, keep teams absorbed in inspiring and impactful work versus mundane tasks, remain flexible with staff, and endorse training and career development. Because at the end of the day, the SOC is still distinctly human–and that is who will be the difference maker between success and failure.
Google Launches Smart Canvas to Stir-up Collaboration in Google Workspace

5449
Of your peers have already read this article.
2:00 Minutes
The most insightful time you'll spend today!
After more than a year of remote collaboration, many people are showing signs of digital fatigue. Throughout the pandemic, millions of employees bridged the physical distances with their colleagues by making themselves more available, joining a deluge of virtual meetings, and leaning into a dizzying array of tools and applications. As part of our mission to build the future of work, we’re addressing these challenges in Google Workspace.
As we announced today at I/O, we’re launching smart canvas—a new product experience that delivers the next evolution of collaboration for Google Workspace. Between now and the end of the year, we’re rolling out innovations that make it easier for people to stay connected, focus their time and attention, and transform their ideas into impact.
Specifically, we’re enhancing the apps that hundreds of millions of people use every day—like Docs, Sheets, and Slides—to make them even more flexible, interactive, and intelligent. With smart canvas, we’re bringing the content and connections that transform collaboration into a richer, better experience in Google Workspace.
When we launched Google Docs and Sheets 15 years ago, these apps introduced the world to a new way of working. They enabled anytime, anywhere teamwork—a stark contrast to the legacy tools that were designed for an era of individual work on office desktops. For over a decade now, we’ve been pushing documents away from being just digital pieces of paper and toward collaborative, linked content inspired by the web. Smart canvas is our next big step.https://www.youtube.com/embed/SDBbFETGiA4?enablejsapi=1&
Making collaboration more flexible and helpful
The evolving hybrid work model gives new urgency to existing collaboration challenges. How do teams stay focused and connected as they work together, regardless of where people are located? With smart canvas, we’re building deeper connections across Google Workspace to transform collaboration anywhere it happens.
For example, we’re taking something that people already use every day—@-mentions—to open up new, powerful collaboration capabilities. New interactive building blocks—smart chips, templates, and checklists—will connect people, content, and events into one seamless experience.
Already available, when you @ mention a person in a document, a smart chip shows you additional information like the person’s location, job title, and contact information. And starting today, we’re introducing new smart chips in Docs for recommended files and meetings. To insert smart chips into your work, simply type “@” to see a list of recommended people, files, and meetings. From web or mobile, your collaborators can then quickly skim associated meetings and people or preview linked documents, all without changing tabs or contexts. Smart chips will come to Sheets in the coming months.

Additionally, we’re making it easier to drive projects forward by streamlining common team workflows. Starting today in Docs, checklists are available on web and mobile, and you’ll soon be able to assign checklist action items to other people. These action items will show up in Google Tasks, making it easier for everyone to manage a project’s To Do list.
We’re also introducing table templates in Docs. Topic-voting tables will allow you to easily gather team feedback while project-tracker tables will help you capture milestones and statuses on the fly. And a new document template for capturing meeting notes will automatically import any relevant information from a Calendar meeting invite, including smart chips for attendees and attached files.

With our new pageless format in Docs, you’ll be able to remove the boundaries of a page to create a surface that expands to whatever device or screen you’re using, making it easier to work with wide tables, large images, or detailed feedback in comments. And if you want to print or convert to PDF, you’ll be able to easily switch back to a paginated view.
Meanwhile, you’ll be able to toggle between new views in Sheets to better manage and interact with your data. Our first launch will be a timeline view that makes tracking tasks easier and faster. This flexible view allows you to organize your data by owner, category, campaign, or whichever attribute fits best. Using a dynamic, interactive timeline strengthens your ability to manage things like marketing campaigns, project milestones, schedules, and cross-team collaborations.

Fostering human connection—wherever people work
With smart canvas and innovations in Google Meet, we’re making it easy to bring the voices and faces of your team directly into the collaboration experience, to help people share ideas and solve problems together from anywhere. As part of that, we’re building tighter integrations between our communication and collaboration tools so you can pull content into conversations and conversations into content.
Starting today, we’re rolling out the ability to present your content to a Google Meet call on the web directly from the Doc, Sheet, or Slide where you’re already working with your team. Jumping between collaborating in a document and a live conversation without skipping a beat helps the project—and the team—stay focused. And in the fall, we’re bringing Meet directly to Docs, Sheets, and Slides on the web, so people can actually see and hear each other while they’re collaborating.

Live captions and translations in Google Meet will also play a crucial role in keeping people connected as they work together in distributed teams. We currently offer live captions in five languages, with more on the way. And we’re introducing live translations of captions later this year, starting with English-language live captions translated into Spanish, Portuguese, French, or German, with many more languages to follow.
With recent enhancements to Google Meet, we’re also giving people more control and flexibility over the meeting experience, including more space to see people and content, plus the ability to pin and unpin content and video feeds. And to help with meeting fatigue, you can now turn off your self-feed entirely.
Because we know that collaboration is fluid and fast-moving, we’re making it easier for teams to give feedback on the fly and to move seamlessly between conversations and building content together. Teams can now jump from a discussion in Google Chat directly to building content together. Creating and editing Sheets and Docs from Google Chat rooms is already live in our web experience, and we’ll enable it for Slides in the coming weeks. And to gauge the team’s reactions along the way, we’re introducing emoji reactions in Docs in the next few months.

Working smarter and safer
Google Workspace is already infused with powerful intelligence that enables people to make the best use of their time and attention. Whether it’s with the two billion grammar suggestions we surface in Docs every month, or the intelligent file suggestions in Drive’s Priority and Quick Access features that cut file finding time by 50%.
To help everyone work smarter, in the next few months we’re introducing additional assisted writing features in Docs on the web. This includes warnings about offensive words and language, as well as other stylistic suggestions that can speed up editing and help make your writing more impactful. We’re also adding more assisted analysis functionality in our Sheets web experience, with formula suggestions that make it easier for everyone, not just analysts, to derive insights from data. Sheets intelligence helps you build and troubleshoot formulas, making data analysis faster and reducing errors.

As smart canvas evolves, we’re making it easy for businesses to connect the apps and tools they rely on to Google Workspace. This builds on our history of supporting a variety of add-on features that take the friction out of collaboration—from adding e-signatures directly in Google Workspace with DocuSign to the Salesforce connector that integrates with Sheets. To help people work even smarter, we recently announced that AppSheet Automation is generally available, so that you can automate time-consuming tasks—like approving invoices and onboarding new hires—without having to write a single line of code.
Looking ahead, we’re planning to build additional APIs so you can bring the information and actions you need from third-party tools directly into smart canvas elements like smart chips, checklists, and table templates.
And because trust is at the center of all collaboration within Google Workspace, today we’re also launching advanced capabilities that help protect users against security threats and abuse as they work together.
Transforming how people work to deliver real-world innovation
While there’s no one way to collaborate, we know from our customers that transforming how people work results in real-world innovation.
Google Workspace fuels a new way of working together. It lets our teams around the world—whether they’re in the office, at home, or in the grocery store aisle—work more flexibly and translate their ideas into new ways of delighting customers.
—Thibaud Cainne, Global Head of Tech Infra and Digital Workplace, Carrefour
Transformation happens at all levels, and often in every tool. We were able to get 17,000 of our people to make the shift from Excel to Google Sheets in just six months by demonstrating how we could optimize, automate, and connect spreadsheets and their data. That kind of collaboration leads to real-world innovation for our clients.
—Monica Andrea Diaz Pinzon, Chief of Digital Transformation (Special Projects), Banco Davivienda
We built a digital hub on Google Workspace to transform the way we connect with employees and partners across multiple locations and organizations. It allowed us to spin up major research projects in days instead of months, including delivery of major COVID-19 vaccine studies.
—Justin Riordan-Jones, Head of System and Information (Research), Department of Health & Social Care, National Institute for Health Research (UK)
As smart canvas drives the next era of collaboration in Google Workspace, we remain committed to providing a solution that’s flexible, helpful, and that fuels innovation for organizations in every industry. On the frontlines, in corporate offices, and across the countless workspaces in between, Google Workspace will continue to transform how work gets done.
You Need Enhanced Security for a Successful Cloud Transformation

2628
Of your peers have already read this article.
1:30 Minutes
The most insightful time you'll spend today!
Twenty years ago, organizations discovered the magic of server virtualization. Among the many benefits of virtualization, it heralded the end of the need for one physical server per application and the beginning of managing software-defined infrastructure. It helped automate building and installing systems, and it helped lay foundations for today’s Continuous Integration/Continuous Delivery mechanisms and DevOps practices. However, the adoption of virtualization was not always smooth and several hurdles stood in its path. Today’s organizations are facing similar obstacles in their journey to the cloud.
Organizations that wanted to virtualize their server environment two decades ago faced a significant challenge that was neither technical nor budgetary, but organizational, stretching across IT teams and beyond. The first team to be concerned about virtualization was the one in charge of installing the physical servers in the racks of the datacenter, managing the physical network connections and operating environmental controls, such as HVAC and power systems. These tasks were drastically reduced, if not outright eliminated.
The second team affected by this shift in technology was the one responsible for installing the operating system and running the post-install procedures. Their job almost completely disappeared as most virtual machines were automatically instantiated from templates.
As a result, successful adoption relied on the ability to smooth these organizational changes. Along the way, training the staff and making sure they acquire the new skills necessary to operate the virtualization infrastructure was critical. And usually, the affected teams eventually found that their new responsibilities were different but still essential to the organization, and perhaps even more appealing.
Virtualizations lessons for cloud transformation regulators
Discussions on virtualization didn’t end with these internal changes when organizations were operating in a regulated environment. They needed to engage closely with their regulators. Regulated organizations often considered the hypervisor solely as an additional layer of software with potential vulnerabilities.
This viewpoint raised risks (such as virtual machine escape) that didn’t exist with physical servers. Even if this is taken into account and the risks mitigated, it should have been considered in balance with all the benefits of machine virtualization, including security benefits such as asset identification, harmonization, and smoother patch management.
While the relevance and benefits of virtualization are now widely accepted, history has repeated itself as similar issues have arisen for organizations facing cloud migrations. When large cloud service providers (CSP) began supporting critical workloads for their customers, regulators increased their oversight over CSPs and issued guidance concerning cloud adoption. This happened in the European financial sector, with guidelines from the European Supervisory Authorities (European Banking Authority, European Securities and Market Authority and European Insurance and Occupational Pensions Authority,) and the coming Digital Operational Resilience Act regulation.
These regulations can help establish trust between providers and customers. As regulator decisions are vital for organizations, there is an opportunity now with cloud technology to balance the risks with the benefits and take into consideration all the ways CSPs can help organizations improve their overall security and compliance levels.
Cultural transformation can drive cloud transformation
Another similarity between cloud transformation and the journey to virtualization is the required internal transformation. When an organization decides to start its journey to the cloud, training its staff with the new technology and tools is a necessary step, but probably not the first nor the most arduous to make. A change of mindset is paramount to fully incorporate all the cloud benefits, in particular regarding security.
This new approach begins with a deep transformation at the organizational level. Organizations should avoid viewing the cloud as a datacenter because there’s so much more potential to cloud technology. This new approach and its accompanying organizational transformation is driven by two factors: The burdens that the CSP removes from the customer, and the new flexibility that software-defined infrastructure brings to the table.
The CSP directly manages several tasks and services, and their security, which means that they’re no longer a direct concern for the customer. These responsibilities include data center management, security-hardened hardware, default encryption for data at rest and data in transit, and resilient network management.
Since all the infrastructure used by the organization to manage its workloads is software defined, it brings much more flexibility to what can be done with it. Software-defined infrastructure can more easily enable security guardrails and continuous compliance that weren’t possible before.
While there’s a temptation to approach an organization’s cloud transformation as merely a “lift and shift” operation from on-premises infrastructure, the reality is that approach reduces the potential gains a cloud transformation can bring to an organization. Moving systems to the cloud accounts for a small portion of the potential impact, while updating the mindset can be truly transformational. Development, architecture and security processes need to be rebuilt; this inevitably requires a deeper transformation of the organization.
The next step is to transform the operations, to align them with the overall organization and the new defined processes, operationalize CI/CD and build DevOps practices. After that, the technological gap will be adjusted, moving the new tools and teaching teams how to best use them.
The important point here is the order of the transformation to manage: organization, operations and technologies (O-O-T) and not the other way round (T-O-O). Of course, these three steps should not be considered completely sequential, as technology plays an important role in the organization and the operations. However, it is essential to support the development of personnel and frameworks to take full advantage of the transformation opportunity, rather than primarily focusing on the tooling.
In addition, at Google Cloud, we believe in a shared fate that goes far beyond the usual shared responsibility model. We think it is part of our duty to help our customers to achieve their goals in their scope of responsibility. We prepare secure landing zones and guide the customers, we bring transparency to security controls and help them with cyber-insurance.
Our shared objective with our customers is to continuously improve security. Our Google Cybersecurity Action Team initiative helps us to be engaged alongside our customers, provide them with necessary guidance, support them in their security and compliance strategies, and assist their organizational and operational transformation in their cloud journey.
- Listen to a related podcast “How to Apply Lessons from Virtualization Transition to Make Cloud Transformation Better”
- Listen to “Preparing for Cloud Migrations from a CISO Perspective, Part 1”
- Read “The journey to the cloud mitigates enterprise risk”
- Also, review “Megatrends drive cloud adoption—and improve security for all”
- Visit Google Cybersecurity Action Team website
The Ultimate Guide to VPC Service Controls: Strengthening Your Security Posture

2503
Of your peers have already read this article.
2:30 Minutes
The most insightful time you'll spend today!
While cloud security skeptics might believe that data in the cloud is just one access configuration mistake away from a breach, the reality is that a well-designed set of defense in depth controls can help minimize the risk of configuration mistakes and other security issues. Our Virtual Private Cloud (VPC) Service Controls can play a vital role in creating an additional layer of security while also making it easier to manage your data in a way that most cloud services can’t do today.
Organizations across industries and business models use cloud services for activities such as processing their data, performing analytics, and deploying systems. VPC Service Controls can empower an organization when deciding how users and data can cross the perimeter of the supported cloud services, if at all. While VPC Service Controls are designed to help stop attackers, they can also enable contextual trusted data sharing (similar to how Zero Trust allows contextual access).
What are VPC Service Controls
VPC Service Controls help administrators define a security perimeter around Google-managed services, which can control communication to and between those services. The Service Controls isolate your Google Cloud resources from unauthorized networks, including the internet. For example, this can help you keep a clear separation between services that are allowed to run in production and services that are not.
VPC Service Controls can help you prevent mistakes that lead to costly data breaches because they control access to your data at a granular level. They add context-aware access controls on these services, and can help you achieve your organization’s Zero Trust access goals.

Example of the fine-grained policies based on access context that can be implemented with VPC Service Controls.
Like wearing two layers of clothing made from different fabrics to protect you from winter weather, VPC Service Controls may appear similar to Identity and Access Management (IAM) but they come from a different approach to implementing security. IAM enables granular identity based access control; VPC Service Controls create a security perimeter that protects your cloud resources and sets up private connectivity to Google Cloud’s APIs and services. While it’s recommended to use both, VPC Service Controls have an added bonus: They can support blocking data theft during a breach.
The additional layer of security that VPC Service Controls offer customers is challenging to achieve with on-premise systems or even with other cloud providers. You can think of it as an firewall for APIs that also adds a logical security control around three paths that data can take:
- From the public internet to your resources
- Inside your VPC and the cloud service perimeter
- For service-to-service communication (for example, denying access to someone who wants to load data to BigQuery or exfiltrate data from a BigQuery instance.)
How VPC Service Controls can help stop attackers
VPC Service Controls are used to enforce a security perimeter. They can help isolate resources of multi-tenant Google Cloud services, which can help reduce the risk of data exfiltration or a data breach.
For example, a bank that migrated financial data processing to Google Cloud can use VPC Service Controls to isolate their processing pipeline from public access (or any unauthorized access) by defining a trusted service perimeter.
How VPC Service Controls can enable trusted sharing
VPC Service Controls are used to securely share data across service perimeters with full control over what resource can connect to other resources, or outside the perimeter. This can help mitigate data exfiltration risks stemming from stolen identities, IAM policy misconfigurations, some insider threats, and compromised virtual machines.
Returning to our bank example, that same bank using VPC Service Controls may securely share or access data across Service Perimeters and Organizations. They may allow access to specific partners and for specific operations.

Example of allowing an authorized device plus authorized access.
How VPC Service Controls support Zero Trust access
VPC Service Controls deliver Zero Trust access to multi-tenant Google Cloud services. Clients can restrict access to authorized IPs, client context, user identity, and device parameters while connecting to multi-tenant services from the internet and other services.
A bank can use moving its services to the public cloud as an opportunity to abandon outdated access management approaches and adopt Zero Trust access. VPC Service Controls let them create granular access control policies in Access Context Manager based on attributes such as user location and IP address. For example, it would allow an analyst to only access Big Query from a corporate device on the corporate network during business hours. These policies can help ensure the appropriate security controls are in place when granting access to cloud resources from the Internet.
Next steps with VPC
Check out these pages to learn more about VPC Service Controls for your sensitive cloud deployments, especially for regulated workloads. This blog is the third in our Best Kept Security Secrets series, which includes how to tap into the power of Organization Policy Service and how Cloud EKM can help resolve the cloud trust paradox.
Connected Data is the Lifeblood of Today’s Retailers: IDC’s 2022 Research

4679
Of your peers have already read this article.
4:00 Minutes
The most insightful time you'll spend today!
For a look ahead at the trends that will animate the retail industry this year, let’s take a look back at the 2022 National Retail Federation (NRF) “Big Show” in NYC.
Attendees at January’s event were treated to tangible examples of how retail challenges are being solved today, including new solutions to help them parse customer expectations and buying patterns, adapt stores into omni-channel experience hubs, and improve data visibility and actionability.
NRF 2022 also took the “omni-channel everything” theme of last year’s show to the logical next level: Enabling the best hybrid experiences. The message came through loud and clear of the importance of integration and interoperability in this new hybrid world – making everything work well together.
The need for modern digital infrastructure to enable this blending of physical and digital retail smoothly is paramount. To that end, technology vendors demonstrated how digital transformation initiatives, such as contactless and real time IoT and mobile applications, need to be built on cloud, edge, and secure connectivity to allow retailers to achieve the modern seamless hybrid retail that today’s consumer wants.
Other prominent themes and technologies highlighted at NRF included: extending engagement in the metaverse, sustainability, physical and digital security, and the agility and adaptability imperative.
The Metaverse and Hybrid (Omni-channel) Experiences
Today, the metaverse is an extension of our lives, enhanced by technology, which exists as a series of virtual worlds. In the future, the metaverse will be an interconnected, endless world where digital and physical lives fully converge. Imagine waiting for an appointment at a real booth on the NRF show floor while your avatar roams a fully fleshed-out digital NRF, meeting other virtual attendees, stopping for coffee at the digital Starbucks, and paying for a coffee that an in-the-flesh Starbucks employee brings to them. Digital and physical selves merge seamlessly in the metaverse, as the worlds draw closer together.
In the metaverse, brands have a digital presence, too. Nike filed seven trademarks late last year, including those for “Nike,” “Just Do It,” and its swoosh logo, and posted openings for virtual designer roles, indicating its intent to make and sell virtual branded sneakers and apparel. It subsequently purchased RTFKT Studios, a company that already makes and sells NFTs and digital sneakers. (In one collaboration with teenage artist FEWOCiOUS, the company sold 600 pair/NFTs of sneakers in just six minutes to the tune of more than $3.1 million.)
The metaverse also opens possibilities for gathering data about consumers and product demand. Imagine a sneaker drop in the virtual world. Certain styles of new kicks sell like gangbusters, giving the brand insight into what might sell IRL, intelligence that leads to trend-right production and less inventory headed for markdown or landfills. The metaverse can be a vehicle for more sustainable operations.
The metaverse further bridges the narrowing gap between digital worlds and physical worlds. Most consumers aren’t outfitting an avatar, but they are moving between online and offline and expect retailers to accommodate those hybrid omni-channel journeys seamlessly. Those demands have accelerated around last-mile delivery and experiences such as buying online and picking up in store (BOPIS) or at curbside, shopping in store and returning merchandise online, adding items to a BOPIS purchase when at the store, or communicating a substitution to the third-party grocery delivery service
Hybrid experiences open opportunities to please the consumer in new ways, but they also add expense and complexity. The need to meet this demand while enabling profitability was a major theme behind many of the technologies discussed at NRF. These included artificial intelligence (AI) for recommending the right product, return logistics software for defining and guiding product-specific reverse logistics workflows, order orchestration and fulfillment applications for omni-channel shopping, and last-mile delivery visibility for optimizing customer experience, to name a few. Also on display were task management applications help to improve and optimize in-store employee engagement, as well as touch-free applications to allow for faster payments and customer self-service checkout. RFID continues to improve inventory accuracy and inventory locating on the shelf, throughout the store, and the supply chain.
Sustainability
NRF 2022 saw a strong focus on sustainability. An NRF/IBV study released at the show highlighted the significant embrace of sustainable shopping by consumers. According to the survey, 62% of shoppers are “willing to change their purchasing habits to reduce environmental impacts.” About half indicated a willingness to pay a premium – on average a 70% premium – for sustainable products and brands.
Retailers are working to improve sustainability and reduce carbon footprint across operations by using sustainable sourcing through the supply chain, the store, and even returns. Tech vendors unveiled a variety of solutions enabled by cloud/edge, AI, computer vision, and IoT/RFID to allow retailers to effectively measure and record their environmental efforts, with the goal of reducing their impact.
Several cloud and digital infrastructure providers showcased sustainability clouds and other technology aimed at asset management with the goal of reducing energy consumption, water usage, waste. Examples included using IoT sensors to reduce water usage, optimizing re-use of store assets, and dashboards that allow retailers to accurately monitor and measure carbon output. However, such sustainability solutions can be most successful when running on the next-generation digital infrastructure that helps retailers better compete and differentiate in today’s omni-channel world.
Physical and Digital Security
According to a 2021 NRF survey, 57% of U.S. retailers reported the pandemic led to an increase in organized retail crime, while 50% reported an increase in shoplifting. When IDC’s Future Enterprise Resiliency & Spending Survey, Wave 10 (November 2021) asked retailers which digital infrastructure investments would provide the greatest strategic advantage in 2022, their #1 response was “cybersecurity and recovery investments.”
A wide range of technology vendors acknowledged retailer concerns with regards to security, fraud, and loss prevention:
- Networking, connectivity, and edge vendors highlighted multilayer security solutions that promise to protect data from a range of IoT applications that utilize customer and associate data. Many offer security consulting services to address varied threats including ransomware, retail crime, and loss prevention.
- Security and e-commerce security vendors showcased solutions to prevent fraud and abuse in e-commerce applications as well as omni-channel applications such as BOPIS and curbside pickup, using AI-based analysis for identifying “bad”/risky customers and mitigating risk.
- Cloud vendors highlighted how retail clouds provide consistent, reliable identity management and data security.
- POS/payments/store technology vendors emphasized their ability to handle payments securely from any platform with multifactor tokenization, improved identity techniques such as biometrics and voice authentication, as well as AI-enabled and computer vision solutions for loss prevention at checkout and at the door.
The Agility and Adaptability Imperative
On display at the show were multiple flavors of the digital infrastructure technology that retailers need to achieve agile, personalized, data-driven, integrated seamless operations across the many channels of today’s retail landscape. The emphasis was apt. More than half of retailers plan to boost investment in business agility and operational agility over the next 12 months, according to IDC’s Future Enterprise Resiliency & Spending Survey, Wave 10 (November 2021).
Technology vendors highlighted their connectivity investments to enable business and operational agility and their technology investments for better ease of integration, scalability, and the ability to more easily swap out or mix and match applications with integrated platforms, open systems, hybrid cloud, and retail industry clouds.
Vendors also showed off infrastructure to better harness data while enabling its visibility, maximizing its value, and providing the data-driven personalization essential for competitive advantage and differentiation. Highlights included fast, secure connectivity, 5G and Wifi-6, and edge- and cloud-enabled data and AI platforms to generate real-time insights – all designed to enable today’s omni-channel retail.
Advice for the technology buyer
Retailers should consider these key themes from NRF 2022 when making technology investment decisions for 2022 and beyond. To avoid lagging behind those retailers already moving toward thriving into the future, take action to:
- Enable the seamless, contactless omni-channel approach that today’s consumers want and expect.
- Replace legacy infrastructure that was not built to handle the modern retail environment that requires the agility and adaptability to seamlessly connect rapidly increasing volumes of data securely and more quickly than ever.
Whether sustainability, adaptability, the metaverse, or security are top concerns, addressing business needs holistically and strategically should be job #1.
Continue the conversation by downloading our Transforming retail and CPG markets whitepaper today.
How to overcome the 5 most common SecOps challenges

3015
Of your peers have already read this article.
3:00 Minutes
The most insightful time you'll spend today!
The success of the modern security operations center, despite the infusion of automation, machine learning, and artificial intelligence, remains heavily dependent on people. This is largely due to the vast amounts of data a security operations center must ingest—a product of an ever-expanding attack surface and the borderless enterprise brought on by the rapid rise of cloud adoption.
All those alerts coming in mean proactive and reactive human decision making remains critical.
Perhaps it should come as no surprise that the information security analyst now ranks as No. 1 News’ 100 Best Jobs Rankings, “determined by identifying careers with the largest projected number and percentage of openings through 2030, according to the U.S. Bureau of Labor Statistics.” Security, and specifically detection and response, is not only a business imperative—it is arguably the top worry on the minds of CEOs.
However, the security analyst is also one of the most likely professionals to want to leave their jobs, according to a newly released “Voice of the SOC Analyst” study conducted by Tines.
What gives? Turnover woes are attributable to several key SecOps challenges that never seem to budge.
1) Alert fatigue and false positives: Have you ever received so much spam or junk mail that you end up ignoring your new messages entirely, leading you to miss an important one? The same can happen for alerts. Too much noise is unsustainable and can lead to the real threats being missed, especially as perimeters expand and cloud adoption increases.
2) Disparate tools: Already in the company of too many point-detection tools, security operations professionals are saying hello to a few more in the era of remote work and increased cloud demands. The latest count is north of 75 security tools that need to be managed by the average enterprise.
3) Manual processes: Use case procedures that result in inconsistent, unrepeatable processes can bottleneck response times and frustrate SecOps teams. Not everything in the SOC needs to—or should be—automated, but much can be, which then frees up analysts and engineers to concentrate on higher-order tasks and be able to more easily train new employees.
4) Talent shortage: Death, taxes, and the cybersecurity skills shortage. As sure as the sun will rise tomorrow, so will the need for skilled individuals to wage the cybersecurity fight. But what happens when not enough talent is filling the seats? Teams must compensate to fill the gap.
5) Lack of visibility: Security operations metrics are critical for improving productivity and attracting executive buy-in and support, but SecOps success can be difficult to track, as reports can require a significant amount of work to pull together.
The caveat of course is that it would be rare to find a SecOps team working without the above challenges. As such, some of the immediate steps you can take to push back against these constraints focus on people-powered processes and technologies to remedy the issues.
According to a recent paper co-authored by Google Cloud and Deloitte:
Humans are—and will be—needed to both perform final triage on the most obtuse security signals (similar to conventional SOC Level 3+) and to conduct a form of threat hunting (i.e. looking for what didn’t trigger that alert).
Machines will be needed to deliver better data to humans, both in a more organized form (stories made of alerts) and in improved quality detections using rules and algorithms— all while covering more emerging IT environments.
Both humans and machines will need to work together on mixed manual and automated workflows.
So, what does this ultimately mean you must do to improve your security operations? Here are five practical suggestions:
Detect Threats More Efficiently
Efficiencies within the SOC can be realized from a SIEM solution that automatically detects threats in real-time and at scale. The right platform will support massive data ingestion and storage, relieve traditional cost and scaling limitations, and broaden the lens for anomaly and machine learning/AI-based detection. With data stored and analyzed in one place, security teams can investigate and detect threats more effectively.
Respond to Threats Automatically
SOAR can be a game-changer in terms of caseload reduction and faster (and smarter, especially when integrated with threat intelligence) response times. But before rushing headfirst into automation, you should consider your processes, review outcomes you are trying to achieve (such as reduced MTTD)–and then decide exactly what you want to automate (which can be a lot with SOAR). Once clear processes are determined where automation can contribute, SOC personnel are freed up to be more creative in their work.
Prioritize Logs
Many teams lack a strategy for collecting, analyzing and prioritizing logs, despite the fact that these sources of insight often hold the clues of an ongoing attack. To help, here are two cheat sheets featuring essential logs to monitor.
Outsource What You Can’t Do Yourself
Process improvements may help you compensate for perceived personnel shortages (for example, perhaps fixing a misconfigured monitoring tool will reduce alert noise). Of course, many organizations need additional human hands to help them perform tasks like round-the-clock monitoring and more specialized functions like threat hunting. Here is where a managed security services provider or managed detection provider can be helpful. Be realistic about your budget, however, as you may be able to introduce some solutions in-house.
Institute Career Models
Lack of management support is cited as the fourth-biggest obstacle to a fully functioning SOC model, according to the 2022 SANS Security Operations Center Survey. To overcome this, SecOps leaders must help improve workflow processes, protect innovation, keep teams absorbed in inspiring and impactful work versus mundane tasks, remain flexible with staff, and endorse training and career development. Because at the end of the day, the SOC is still distinctly human–and that is who will be the difference maker between success and failure.
More Relevant Stories for Your Company

AirAsia’s CIO Speaks Up: Why He Decided, What He Did
At AirAsia, we operate a fleet of more than 270 aircraft across 23 markets, fly to more than 150 destinations and carry 100m guests each year. We’ve also been named the world’s best low-cost carrier for 11 years running. To accomplish all of this, we rely heavily on our 22,000

Chrome OS’s Hybrid Work Model Powers Google’s Return to Work Strategy
The pandemic continues to deeply affect our lives around the globe. In some places, new cases are surging and returning to work is the last thing on people’s minds. In other areas, conditions are improving and companies are starting to think about transitioning their workforce back to the office. Exactly

Google Cloud’s Metric Scope Makes Multi-project Monitoring Simple
Customers need scale and flexibility from their cloud and this extends into supporting services such as monitoring and logging. Google Cloud’s Monitoring and Logging observability services are built on the same platforms used by all of Google that handle over 16 million metrics queries per second, 2.5 exabytes of logs per month, and over

Google Announces New Cloud Region in Israel to Meet Growing Customer Demands
Google has long looked to Israel for globally impactful technologies including popular Search features, Waze, Live Caption, Duplex and flood forecasting. At our Decode with Google 15RAEL event last week, we celebrated 15 years of Google innovation in Israel and our longstanding support of the country’s vibrant startup ecosystem. Over the years, we’ve expanded our enterprise






