@GossiTheDog "look for abnormal" ... Many IT teams can't define what's "normal" because they don't review their own logs. Expecting cybersecurity teams to spot abnormalities in that context is unrealistic. We need to stop pushing the message that monitoring is just the SOC’s job. Non-technical IT leaders see that messaging and shift responsibility wholly to the SOC who don’t understand the systems they're supposed to monitor.