Cosive
Why work with us

We’ve built security operations teams before

Deep SecOps experience building and running teams internationally — our consultants have established security operations teams across sectors and countries, from national CERTs to enterprise SOCs
SIM3 assessors who know what effective teams look like — we use the Security Incident Management Maturity Model to benchmark and design teams, so you start with a clear picture of what good looks like
Practical, right-sized advice — we don’t give you a one-size-fits-all blueprint. We tailor our recommendations to your budget, timeline, and organisational context
Senior practitioners you work with directly — no junior consultants reading from a playbook. You get experienced people who’ve spent their careers in security operations
Cosive's Prescott Pym speaking at AUSCERT
Cosive's Prescott Pym speaking at AUSCERT.

Figure out what functions your SecOps team needs to provide

Before you hire anyone, you need to understand what your organisation actually needs from a security operations team. We help you map out the functions, capabilities, and tools required — so you build a team that fits your risk profile and budget, not someone else’s template.

Every organisation is different. A team of three looks very different to a team of fifteen, and both can be effective if they’re focused on the right things.

Discuss your requirements
Two people reviewing documents at a table
01

SecOps functions mapping

Identify which security operations functions your team actually needs to provide. Not every organisation needs the same set of capabilities — we help you focus on what matters for your risk profile and industry.

02

Team size and structure

Right-size your team for your organisation. We help you work out how many people you need, what roles to create, and how to structure the team so it can operate effectively from day one.

03

Capability assessment

Work out which capabilities are essential for your team versus nice-to-have. We help you prioritise so you can build incrementally rather than trying to do everything at once.

04

Technology requirements

Understand what tools and platforms you’ll need to support your team. We give you practical, vendor-neutral advice based on your budget and what your team will actually use.

Plan your cybersecurity operations team build out

We can perform a SecOps assessment to figure out exactly what shape your team needs to be in order to be effective. From there, we build you a phased implementation roadmap — so you know what to do first, what can wait, and how to measure progress along the way.

This isn’t an abstract strategy document. It’s a practical plan you can start executing immediately, with clear milestones and realistic timelines.

01

SIM3 baseline assessment

A structured assessment of what your organisation needs from a security operations team. We use frameworks like SIM3 to give you an objective baseline and clear targets to build towards.

02

Implementation roadmap

A phased plan for standing up your team over time. We break the build into manageable stages so you can show progress early and adjust as you learn what works.

03

Process design

Design your core operational processes — incident response, triage, escalation, and handover. We help you get the fundamentals right so your team can hit the ground running.

04

Framework adoption

Help choosing and operationalising the right frameworks for your team. Whether it’s SIM3, SOC-CMM, ATT&CK, or a combination — we help you adopt what’s useful without drowning in process.

People working on laptops with notebooks
Discuss your build plan

Hire the right people for your cybersecurity operations team

Not sure what traits make a good incident responder? We can help you choose the best team to provide a good range of skills. From writing job descriptions that attract the right candidates to sitting in on interviews — we make sure you hire people who can actually do the job.

Getting your first hires right is critical. The people you bring in early set the culture and capability of your team for years to come.

Discuss your hiring needs
Two people sitting and talking on a rooftop
01

Role definition

Define the roles your team needs and write job descriptions that attract the right candidates. We help you describe what you actually need — not a wish list of every security certification in existence.

02

Skills assessment

Identify the right mix of skills for your team. A good SecOps team needs a balance of technical depth, analytical thinking, and communication — we help you work out what that looks like for your context.

03

Interview support

We can sit in on candidate interviews and help you select the best people. Our experience hiring and managing security teams means we know what to look for beyond the CV.

04

Onboarding planning

Help structure onboarding for your new security hires. Good onboarding accelerates time-to-value and helps new team members feel confident and productive from the start.

Common questions about starting a cybersecurity operations team

How do I start a cybersecurity operations team from scratch?

Starting a cybersecurity operations team begins with understanding what your organisation actually needs to protect. Map out the functions your team will provide — such as monitoring, detection, incident response, and vulnerability management — then match those functions to realistic team sizes and budgets.

Most effective teams start small, with two or three people covering the highest-priority functions, and grow deliberately as processes mature. A structured assessment using a framework like SIM3 gives you an objective baseline to plan from, and a phased roadmap helps you avoid trying to do everything at once.

How many people do I need on a security operations team?

There is no single answer — it depends on the functions your team needs to cover, your organisation’s risk profile, and your coverage requirements. Some organisations run effective security operations with three people; others need fifteen or more. The key is matching team size to your priority functions.

Start by identifying what your team must do (e.g. 24/7 monitoring vs business-hours triage), then factor in which tasks can be automated or outsourced. It is better to have a small team doing the right things well than a larger team spread too thin.

What roles do I need to hire for a new SOC or SecOps team?

The roles you need depend on the functions your team will provide. Most new teams start with a mix of incident responders and security analysts who can triage alerts, investigate potential incidents, and maintain detection rules. As the team matures, you may add dedicated roles for threat intelligence, detection engineering, vulnerability management, and security automation.

When hiring, look for people with strong analytical thinking and communication skills — technical knowledge can be trained, but the ability to investigate and communicate clearly is harder to teach.

What frameworks should I use to build a security operations team?

The most widely used frameworks for planning and maturing a security operations team are SIM3 and SOC-CMM. SIM3 (Security Incident Management Maturity Model) assesses your team across four dimensions — organisation, human, tools, and processes — and is widely used to benchmark and certify CSIRTs and SOCs internationally. SOC-CMM (SOC Capability Maturity Model) is designed specifically for SOC-focused teams and evaluates capabilities across business alignment, people, process, technology, and services.

MITRE ATT&CK is also valuable for mapping your detection coverage and identifying gaps. The right choice depends on your team structure and goals.

Should I outsource security operations or build an in-house team?

Both approaches can work, and many organisations use a hybrid model. An in-house team gives you direct control, deeper organisational knowledge, and the ability to handle sensitive investigations internally. Outsourcing (e.g. to a managed SOC) can provide 24/7 coverage and specialist expertise that a small internal team cannot sustain.

The decision often comes down to which functions require internal context — incident response and threat intelligence benefit from people who understand your business — versus which can be commoditised, such as first-tier alert monitoring. Starting with a small in-house team supplemented by external support is a common and effective approach.

Airport control tower and terminal building under blue sky

Start building your security operations team

Tell us where you’re at and we’ll help you figure out the right next steps for building your SecOps team.