SoC

Ihr Angreifer arbeitet nicht zwischen 9 und 17 Uhr. Ihr SOC schon.

Stellen Sie sich vor, Ihre Werkshalle wäre genau dann unbesetzt, wenn die Diebe kommen. Genau das ist der Zustand der IT-Sicherheit in 90 % der deutschen Mittelständler. Der größte ungelöste strukturelle Fehler in der Cybersecurity des Mittelstands ist nicht technischer, sondern temporaler Natur: Wir verteidigen 40 Stunden in der Woche – Angriffe laufen 24/7 rund um die Uhr. Diese Asymmetrie ist kein Zufall. Sie ist die Geschäftsstrategie der Angreifer. Der Arctic Wolf Security Operations Report 2025 hat über 330 Billionen Sicherheitsbeobachtungen ausgewertet. Das Ergebnis: 51 Prozent aller Alerts traten außerhalb der Geschäftszeiten auf, 15 Prozent am Wochenende. Darktrace dokumentiert noch deutlicher: In 76% der Ransomware-Infektionen beginnt der Verschlüsselungsprozess entweder nach Feierabend oder am Wochenende. Das Angreifer-Playbook ist dabei subtiler, als viele denken: Bedrohungsakteure dringen zu Zeiten ein, wenn möglichst viele Nutzerinnen und Nutzer aktiv sind, um unerkannt zu bleiben. Doch die eigentliche Ausführung des Angriffs erfolgt dann nach Geschäftsschluss. Initial Access zwischen 10:00 und 16:00 Uhr (im Rauschen des Tagesgeschäfts), Lateral Movement abends, Verschlüsselung um 03:00 Uhr Samstagnacht – wenn der erste Mitarbeiter Montag ins Büro kommt, läuft der Vorfall bereits 60 Stunden. Ein EDR-Tool, das niemand um 02:47 Uhr Sonntag liest, ist eine sehr teure Voicemail. NIS2 §32 BSIG verlangt eine 24-Stunden-Erstmeldung an das BSI – wer den Vorfall erst Montag um 09:30 Uhr bemerkt, ist bereits 36 Stunden zu spät. Die richtige Frage ist nicht „haben wir ein SIEM?“, sondern „wer schaut dort um 04:00 Uhr Sonntag rein?“ Die ehrlichen Antworten sind drei Maßnahmen: Alles andere ist Selbstbetrug. Haben Sie eine dokumentierte Eskalationskette für 03:00 Uhr Sonntag – inklusive Stellvertreter, Notfall-Mobilnummern und vorab definierter Containment-Befugnisse? Oder steht im Plan: „IT-Leiter informieren“? Erwartete Gegenargumente & Konter: Stimmt. Für den Schichtbetrieb eines eigenen Security Operations Centers (SOC) sind mindestens acht Analysten nötig, um Wochenenden, Feiertage, Urlaub und Krankheit abzudecken. Hinzu kommen 1-2 Führungskräfte sowie die XDR Software und Threat Intelligence Databases. In Summe kann das 1.000.000 Euro pro Jahr kosten. Genau deshalb gibt es Managed-Detection-Response-Angebote (MDR/MXDR) ab fünfstelligen Jahresbeträgen. Die Frage ist nicht „eigenes SOC ja/nein“, sondern „24/7-Coverage durch wen?“  Beides arbeitet automatisiert – aber bei modernen Angriffen werden legitime Tools genutzt: Ausnutzung von RMM-Lösungen und Cloud-Speicherdiensten (OneDrive, Dropbox) für die Ransomware-Bereitstellung ohne traditionelle Malware-Binärdateien. Genau diese „Living-off-the-Land“-Angriffe erkennen automatisierte Systeme nicht. Es braucht Augen und Hirn auf dem Alert. Genau das ist der Trugschluss. Backup-Jobs, Update-Fenster, automatische Replikationen, Cloud-Sync-Vorgänge laufen nachts. Angreifer wissen das und tarnen sich darin. Ohne Baseline und 24/7-Triage ist „auffällig“ nur lautes Rauschen. Cyberversicherer prüfen seit 2025 zunehmend, ob ein 24/7-Monitoring vertraglich zugesagt war. Antwortzeiten sind in vielen neuen Policen Obliegenheit – verspätete Reaktion = Leistungskürzung.  Charmante Idee, in der Praxis selten umsetzbar (Logistik, Produktion, Cloud-Services, Außendienst). Und: Ein Angreifer, der bereits im System ist, wartet einfach. Air-Gap löst Initial Access, aber nicht Lateral Movement. Weitere Einblicke finden Sie im Video unten.

Ihr Angreifer arbeitet nicht zwischen 9 und 17 Uhr. Ihr SOC schon. Weiterlesen »

Your attacker doesn’t work from 9 to 5. Your SOC does.

Imagine your production facility was left unattended exactly when the burglars decided to strike. That is effectively the state of IT security in 90% of German mid-sized companies. The biggest unresolved structural weakness in SMB cybersecurity is not technical – it is temporal. We defend our environments for roughly 40 hours a week, while attackers operate 24/7. This asymmetry is no coincidence; it is part of the attackers‘ business model. The Arctic Wolf Security Operations Report 2025 analyzed more than 330 trillion security observations. The findings are striking: 51% of all security alerts occurred outside regular business hours, and another 15% during weekends. Darktrace reports an even clearer pattern: in 76% of ransomware incidents, the encryption process begins either after business hours or over the weekend. The attackers‘ playbook is more subtle than many organizations realize. Threat actors typically gain initial access while employees are actively working, allowing them to blend into normal business activity. The actual attack, however, is executed after hours. Initial access may occur between 10:00 a.m. and 4:00 p.m., lateral movement during the evening, and ransomware encryption at 3:00 a.m. on Saturday night. By the time the first employee returns to the office on Monday morning, the incident may already have been unfolding for 60 hours. An EDR platform that nobody checks at 2:47 a.m. on a Sunday is nothing more than an extremely expensive voicemail system. Under the NIS2 Directive, organizations are required to report significant cybersecurity incidents within 24 hours. If an incident is only discovered on Monday at 9:30 a.m., the organization may already have missed that deadline by more than a day. The real question is not, „Do we have a SIEM?“ It is, „Who is looking at it at 4:00 a.m. on a Sunday?“ The honest answer usually comes down to three options: Everything else is wishful thinking. Do you have a documented escalation process for 3:00 a.m. on a Sunday – including deputies, emergency mobile numbers, and pre-approved containment authority? Or does your incident response plan simply say: „Notify the IT Manager“? Expected objections – and the reality That’s true. Running an in-house Security Operations Center around the clock typically requires at least eight analysts to cover shifts, weekends, vacations, public holidays, and sick leave. Add one or two team leads, XDR technology, and threat intelligence platforms, and annual costs can easily exceed €1 million. This is exactly why Managed Detection and Response (MDR/MXDR) services exist and are available for a fraction of that investment. The real question is not „Should we build our own SOC?“ but „Who provides our 24/7 security coverage?“ Both operate automatically. Modern attackers know this and increasingly rely on legitimate administrative tools, remote management software (RMM), and cloud storage services such as OneDrive or Dropbox to deliver ransomware without deploying traditional malware binaries. These so-called Living-off-the-Land attacks often evade automated detection. Ultimately, security alerts still require experienced human analysts who can distinguish real threats from background noise. Unfortunately, that’s a common misconception. Backup jobs, software updates, replication processes, cloud synchronization, and other scheduled activities routinely run overnight. Attackers deliberately hide their activity within this legitimate background traffic. Without behavioral baselines and continuous 24/7 triage, „unusual“ quickly becomes indistinguishable from normal operational noise. Cyber insurance providers are increasingly verifying whether organizations actually maintain the 24/7 monitoring capabilities promised in their applications and policies. Many newer policies define response times as contractual obligations. Delayed detection or response may therefore result in reduced coverage or denied claims. It’s an attractive idea, but rarely practical for organizations that depend on logistics, manufacturing, cloud services, or field operations. More importantly, an attacker who has already established a foothold inside your environment will simply wait. Air-gapping systems may reduce exposure to initial compromise, but it does not stop lateral movement by an adversary who is already inside your network. More insights can be found in the video below.

Your attacker doesn’t work from 9 to 5. Your SOC does. Weiterlesen »

The Human Factor in the Storm – Crew Resource Management for the SOC

When experts lose track of the big picture Despite all the technology available, humans remain the most important and, at the same time, the most error-prone component in the security system. In aviation, it was recognized early on that accidents often happen not because of technical defects, but because of poor communication or wrong decisions made under stress. During a cyberattack, teams are under extreme psychological pressure. The release of cortisol and adrenaline often leads to “tunnel vision”. Analysts fixate on insignificant details while massive amounts of data are leaking elsewhere. Psychological stress reactions in cyber security The effects of stress are measurable and dangerous: Stress-Effect Impact on cybersecurity Fixation Analyst overlooks the spread in the data centre because he only checks one laptop. Cognitive overload Critical alerts are missed due to “alert fatigue.” Decision Paralysis Hesitation to disconnect the network for fear of disrupting operations. Normalcy Bias Suspicious actions are mistakenly interpreted as “normal” because thresholds are unknown or were not established in advance. The Solution: Crew Resource Management (CRM) To address this, aviation uses CRM training. In cybersecurity, we need to apply the same principles to incident response teams and SOCs. Through simulations (tabletop exercises) and red teaming, teams learn to communicate in a structured way under stress and remain confident in their actions. This is also a core ISO 27001 requirement for competence and awareness. Preventing an Economic Crash LandingThe goal of all these efforts is to avoid a “digital crash landing.” The consequences of weaknesses in information security today are ruthless: Proactive action means understanding your dependence on IT systems and having business continuity plans (ISO 27001 Control A.17) in place to ensure operations can continue during an attack. Conclusion: The CISO as Navigator Cybersecurity is a matter of professionalism, preparation, and organizational maturity. A modern CISO acts as a navigator, guiding the company through the storm on three pillars. When was the last time your crisis team trained under real stress conditions? Is your team ready for the “storm”? For more information, visit our IT-Security webpage: https://patecco.com/it-security/

The Human Factor in the Storm – Crew Resource Management for the SOC Weiterlesen »

Der Faktor Mensch im Sturm – Crew Resource Management für das SOC

Wenn Experten den Überblick verlieren Trotz aller Technik bleibt der Mensch die wichtigste und zugleich fehleranfälligste Komponente im Sicherheitssystem43. In der Luftfahrt wurde früh erkannt: Unfälle passieren oft nicht wegen technischer Defekte, sondern wegen mangelnder Kommunikation oder Fehlentscheidungen unter Stress. Während eines Cyberangriffs stehen Teams unter extremem psychologischen Druck. Die Ausschüttung von Cortisol und Adrenalin führt oft zum „Tunnelblick“. Analysten fixieren sich auf unbedeutende Details, während an anderer Stelle massiv Daten abfließen. Psychologische Stressreaktionen in der Cybersicherheit Die Auswirkungen von Stress sind messbar und gefährlich: Stress-Effekt Auswirkung in der Cybersicherheit Fixierung Analyst übersieht die Ausbreitung im RZ, weil er nur einen Laptop prüft. Kognitive Überlastung Kritische Warnungen werden durch „Alert Fatigue“ übersehen. Entscheidungslähmung  Zögern bei der Netztrennung aus Angst vor Betriebsunterbrechung. Normalcy Bias Verdächtige Aktionen werden fälschlicherweise als „normal“ interpretiert, da Schwellwerte nicht bekannt oder im Vorfeld erhoben wurden. Die Lösung: Crew Resource Management (CRM) Um dem entgegenzuwirken, nutzt die Luftfahrt das CRM-Training. In der Cybersicherheit müssen wir dies auf Incident Response Teams und SOCs übertragen. Durch Simulationen (Tabletop Exercises) und Red Teaming lernen Teams, unter Stress strukturiert zu kommunizieren und handlungssicher zu bleiben. Dies ist zudem eine Kernanforderung der ISO 27001 an Kompetenz und Bewusstsein. Die Lösung: Crew Resource Management (CRM) Um dem entgegenzuwirken, nutzt die Luftfahrt das CRM-Training. In der Cybersicherheit müssen wir dies auf Incident Response Teams und SOCs übertragen. Durch Simulationen (Tabletop Exercises) und Red Teaming lernen Teams, unter Stress strukturiert zu kommunizieren und handlungssicher zu bleiben. Dies ist zudem eine Kernanforderung der ISO 27001 an Kompetenz und Bewusstsein. Die ökonomische Bruchlandung verhindern Das Ziel all dieser Anstrengungen ist die Vermeidung einer „digitalen Bruchlandung“. Die Konsequenzen von Mängeln in der Informationssicherheit sind heute gnadenlos. Proaktives Handeln bedeutet, die Abhängigkeit von IT-Systemen zu verstehen und Business Continuity Pläne (ISO 27001 Control A.17) zu haben, die den Weiterbetrieb während eines Angriffs ermöglichen. Fazit: Der CISO als Navigator Cybersicherheit ist eine Frage der Professionalität, Vorbereitung und kulturellen Reife. Ein moderner CISO fungiert als Navigator, der das Unternehmen auf drei Säulen durch den Sturm führt: Wann haben Sie Ihren Krisenstab das letzte Mal unter realen Stressbedingungen trainiert? Ist Ihr Team bereit für den „Sturm“? Weitere Informationen finden Sie auf unserer IT-Security-Seite: https://patecco.com/it-security/

Der Faktor Mensch im Sturm – Crew Resource Management für das SOC Weiterlesen »

PATECCO Achieves Delinea Gold Partner Status

We are proud to announce that PATECCO is now a Gold Partner of Delinea, a global leader in Privileged Access Management (PAM). This partnership marks a significant milestone in our strategic development and further confirms our deep expertise in the field of Identity & Access Management. Delinea offers cutting-edge PAM solutions that integrate seamlessly into complex IT environments – on-premises, hybrid, or fully cloud-based. As a long-standing IAM provider, we recognize the increasing demand for intelligent, scalable security solutions that protect privileged access and support compliance requirements. With the Gold Partner status, we not only demonstrate our technological competence but also reaffirm our commitment to helping organizations safeguard their digital identities. To ensure we continue delivering top-tier services, we will train at least three new colleagues this year in Delinea products, equipping them with the skills needed to handle any customer scenario. This ongoing investment in our team ensures that we remain agile, expert, and ready for the most complex challenges in the PAM landscape. We are also taking a big step towards strengthening our Managed Service offerings: we are currently building our own Security Operation Center (SoC) in Bochum, specifically designed to support and monitor all Delinea solutions we work with. For customers interested in a professional managed service, this means dedicated support, rapid response times, and tailored solutions – right here from Germany. Our growth doesn’t stop there – we are actively expanding our operations in Austria and Switzerland, bringing our proven expertise in PAM and IAM to a wider customer base in the DACH region. Local presence, combined with international experience, ensures our clients receive both personalized service and cutting-edge solutions. One of our key strengths is that we independently conduct all Proof of Concepts (PoCs). That means fast, efficient implementation and customized demonstrations tailored to each client’s unique infrastructure and goals. It’s a hands-on way to experience the power of Delinea solutions before going live. The Gold Partnership between PATECCO and Delinea marks a powerful alliance in the field of Identity and Access Management. With a clear focus on customer-centric solutions, continued investment in expert training, and the development of our own Security Operations Center, we are well-positioned to deliver secure, scalable, and future-ready PAM services. This is more than just a partnership – it’s a shared commitment to excellence, innovation, and trust.

PATECCO Achieves Delinea Gold Partner Status Weiterlesen »

Nach oben scrollen