"At this point, the security team can have no confidence that a given host has not been compromised -- the bad guys are already inside your environment," says Amit Yoran, CEO of security vendor NetWitness and a former White House cybersecurity adviser. "All of the threats that really matter are already inside the network."
While not all security experts agree on this philosophy, most agree that tomorrow's security teams will have to spend at least as much time analyzing logs, events, and incidents as they currently do on building perimeter defenses. That means more focus on security analytics, forensics, and incident response.
"Over time, the people in the SOC will find that they're spending more time as data analysts, rather than security analysts," says Joe Gottlieb, CEO of SenSage, a maker of security information and event management (SIEM) tools. "They'll be doing a lot more data mining to find the source of a problem.