The Value of Cybersecurity Operations by Christopher Crowley

The Value of Cybersecurity Operations by Christopher Crowley

A security operations center is often judged at the wrong moment: after an incident, when leaders want to know why an attack was not stopped sooner. That question matters, but it can obscure the daily work required to reduce exposure before an event becomes a business problem. The Value of Cybersecurity Operations, Christopher Crowley’s new book, addresses the larger issue: how organizations should understand, direct, and communicate the value created by cybersecurity operations.

This is not a narrow discussion of tools, alert volume, or staffing models in isolation. It is a treatment of security operations as a business function responsible for preserving the confidentiality, integrity, and availability of digital assets. For security leaders, practitioners, and executives, that distinction is essential. A SOC is not valuable because it produces activity. It is valuable when its activities prevent, contain, and reduce the consequences of loss.

Why cybersecurity operations need a value narrative

Cybersecurity teams frequently have no shortage of evidence that they are busy. They can report alerts investigated, systems patched, vulnerabilities identified, incidents escalated, and controls deployed. Each metric may be useful operationally. None automatically explains whether the organization is better protected.

That gap creates a familiar tension. Executives need to make decisions about priorities, budget, operating models, and risk acceptance. Security teams need adequate people, authority, visibility, and technology to carry out their mission. When both groups speak only in technical measures, the conversation can become transactional: more tools requested, more reports delivered, and little shared understanding of what the operation is protecting or how its work changes risk.

The book’s central subject is valuable because it directs attention to that shared understanding. Cybersecurity does not create a conventional financial return in the way a revenue-producing initiative might. Its purpose is loss prevention. It helps an organization avoid or limit outcomes such as fraud, operational disruption, theft of sensitive information, regulatory exposure, physical safety impacts, and damage to customer confidence.

This framing is more precise than broad claims that cybersecurity “enables the business.” It does enable business activity, but security leaders earn credibility when they can describe the specific assets, processes, obligations, and consequences at stake. The relevant question is not whether a SOC handled a large number of alerts. It is whether the operation is positioned to detect material threats, make sound decisions under pressure, and limit harm when preventive controls fail.

The Value of Cybersecurity Operations is a leadership topic

A mature security operation depends on more than capable analysts. It requires clear direction from leadership. The organization must determine what needs protection, what degree of risk is acceptable, who has authority during an incident, and how security priorities relate to operational realities.

That is why the value of cybersecurity operations cannot be assigned solely to the SOC manager. The SOC can monitor, investigate, coordinate, and respond, but it cannot independently define business priorities or correct systemic weaknesses. If asset ownership is unclear, logging is incomplete, change management is inconsistent, or incident decisions require prolonged approval cycles, the operation inherits constraints created elsewhere.

For executive audiences, the practical implication is straightforward: a SOC should be assessed as part of a broader security capability, not as an isolated monitoring desk. Its effectiveness depends on identity management, asset visibility, network and endpoint telemetry, vulnerability management, incident response authority, engineering support, and accountable business owners. A well-staffed team cannot compensate indefinitely for missing foundational controls.

For practitioners, this perspective can also improve internal communication. Analysts and engineers often understand the technical chain of events but may not have language for the business consequence. Connecting an investigation to a critical service, a regulated data set, a production environment, or a contractual obligation makes the work more legible to decision-makers without diluting its technical substance.

Measures should support decisions, not decorate reports

A useful security measure has a defined audience and a decision attached to it. An alert closure rate may help a SOC leader understand workload or process quality. Mean time to contain may help assess response execution. Coverage metrics may show whether critical systems are observable. Findings from exercises may identify gaps in coordination.

The trade-off is that metrics can create false confidence when they are treated as universal proof of effectiveness. Faster closure is not always better if cases are being closed without sufficient investigation. A lower incident count may reflect improved security, reduced visibility, inconsistent classification, or a quieter reporting period. Numbers require context, and trends require interpretation.

A value-oriented approach therefore combines operational measures with evidence of protection priorities. Leaders should be able to see which critical assets are covered, where detection and response gaps remain, what recurring incident patterns reveal, and which improvements will most reduce exposure. This does not eliminate uncertainty. Cybersecurity decisions are made under uncertainty. It makes that uncertainty visible and manageable.

What readers can apply to their own SOC

The strongest use of a book on cybersecurity operations is not simply to adopt its terminology. It is to use its ideas to ask better questions about the operation already in place or the one being designed.

Start with mission clarity. A SOC mission should state whom it serves, what it protects, and what it is expected to do when threats emerge. “Monitor the environment” is incomplete. Monitoring is a means, not an outcome. A mission tied to protection and loss prevention gives analysts, engineers, service providers, and leadership a common reference point when priorities compete.

Next, examine the connection between business criticality and operational coverage. Many organizations collect large volumes of telemetry while retaining limited visibility into their most consequential services. The answer is not automatically to collect everything. More data increases cost, complexity, privacy considerations, and analyst workload. The answer is to identify high-value assets and processes, determine the threats that matter most to them, and establish the detection, investigation, and response capabilities needed for those scenarios.

Then test whether the operation can act. Detection without authority or coordination is an incomplete capability. During a serious event, teams need established paths for escalation, containment, legal and compliance involvement, executive communication, and recovery decisions. Tabletop exercises are useful when they expose real friction rather than merely confirm a scripted plan. A difficult exercise that identifies an unclear decision owner may be more valuable than a smooth exercise that avoids meaningful choices.

Finally, review the operating model honestly. An internal SOC, managed service, co-managed model, or distributed structure can each be appropriate. The right choice depends on organizational scale, required coverage, internal expertise, regulatory constraints, technology environment, and tolerance for dependence on external providers. Outsourcing monitoring does not outsource accountability. Leadership still needs to define priorities, validate service quality, and retain informed authority over material risk decisions.

A resource for different professional audiences

The subject has relevance beyond the security team. Newer practitioners can use it to understand why procedures, triage decisions, and escalation discipline matter. SOC leaders can use it to frame capability development around mission outcomes rather than a collection of products. Executives and board-facing leaders can use it to distinguish meaningful security investment from activity that looks impressive but does not address important exposure.

The format also matters for working professionals. A reference book supports focused study and team discussion, while audio and webcast learning may better fit travel, commutes, or structured professional development. Montance® makes The Value of Cybersecurity Operations available across professional-friendly formats, allowing readers to select the format that best supports how they absorb and apply the material.

From activity to accountable protection

Security operations will always involve urgent work: suspicious logins, endpoint alerts, phishing reports, vulnerability findings, and incidents that demand immediate attention. That urgency should not prevent leaders from asking the larger question of value. A SOC must be able to show how its work contributes to protecting what the organization cannot afford to lose.

Christopher Crowley’s focus on the value of cybersecurity operations is timely because the profession needs more than another argument for accumulating technology. It needs a disciplined way to connect mission, risk, operational capability, and decision-making. The useful next step is to take one current SOC report, identify the business decision it is meant to support, and revise it until the connection is unmistakable.