Panel | Cyber Fusion Center: The Command Center For Integrated Cyber Defense

Nullcon Goa 2025 · Panel

Overview

This Nullcon panel discussion, titled "Cyber Fusion Center: The Command Center For Integrated Cyber Defense," delves into the evolving landscape of cybersecurity operations, moving beyond traditional Security Operations Centers (SOCs). Featuring a panel of Mumbai-based cybersecurity leaders—Yogi, Madan, and Komal—the session aims to demystify the concept of a Cyber Fusion Center (CFC), which is often perceived as just another industry buzzword. Instead of complicating the already intricate cybersecurity ecosystem, the panelists endeavor to simplify and articulate the practical implications of CFCs in day-to-day operational life.

Watch on YouTube

Visual summary for Panel | Cyber Fusion Center: The Command Center For Integrated Cyber Defense
Visual summary for Panel | Cyber Fusion Center: The Command Center For Integrated Cyber Defense

Panel | Cyber Fusion Center: The Command Center For Integrated Cyber Defense

Speakers: Panel Discussion with Yogi, Madan, and Komal (Moderated)

Conference: Nullcon

YouTube: https://www.youtube.com/watch?v=_V6UZK8U4-s

Overview

This Nullcon panel discussion, titled "Cyber Fusion Center: The Command Center For Integrated Cyber Defense," delves into the evolving landscape of cybersecurity operations, moving beyond traditional Security Operations Centers (SOCs). Featuring a panel of Mumbai-based cybersecurity leaders—Yogi, Madan, and Komal—the session aims to demystify the concept of a Cyber Fusion Center (CFC), which is often perceived as just another industry buzzword. Instead of complicating the already intricate cybersecurity ecosystem, the panelists endeavor to simplify and articulate the practical implications of CFCs in day-to-day operational life.

The core premise of the talk revolves around the necessity of integrating disparate elements—people, technology, and data—to achieve timely decision-making and enhance an organization's overall cyber resilience. The discussion dissects the fundamental challenges plaguing modern cybersecurity defense, particularly focusing on the silos that exist across teams, technologies, and the data they generate. By exploring these pain points, the panel articulates how a Cyber Fusion Center acts as a strategic evolution, bringing together various security functions to foster collaboration, streamline processes, and create a unified, proactive defense posture against increasingly sophisticated threats.

Ultimately, the session serves as a critical examination of how organizations can move from reactive, point-solution-driven security to an integrated, intelligence-led approach. The panelists, drawing from their extensive leadership experiences, highlight the importance of breaking down organizational and technological barriers to improve incident response, threat intelligence sharing, and overall risk management. They underscore that in an era where adversaries are collaborating and leveraging advanced tools like AI, defenders must also adopt a collective, integrated strategy to stay ahead.

Background

The journey to the Cyber Fusion Center (CFC) is rooted in the evolution and subsequent challenges of traditional cybersecurity defense mechanisms. Historically, organizations established Security Operations Centers (SOCs), which later evolved into Cyber Defense Centers (CDCs), primarily focused on monitoring and responding to security incidents. However, as the digital landscape expanded and threats grew in complexity, these centralized models began to show limitations. The panel identifies the CFC as the "next elevation" or "evolution" of the SOC, driven by an urgent need to address systemic problems rather than merely introducing a new buzzword.

The problem statement articulated by the panelists highlights three critical dimensions: people, technology, and data.

  1. People: Cybersecurity teams often operate in silos. An organization might have separate teams for SOC, Incident Response (IR), Threat Intelligence (TI), Threat Hunting, Vulnerability Management (VM), Red Teaming, and Governance, Risk, and Compliance (GRC). This functional segregation often leads to a lack of cohesive action and knowledge sharing. Analysts, even with playbooks, may not consistently apply best practices, and the institutional knowledge gained from past incidents is rarely codified or easily accessible for future application. The absence of a shared, constantly improving knowledge base means efforts are often duplicated, and innovation in response tactics is stifled.
  2. Technology: The defense ecosystem is characterized by a "plethora of technologies." Organizations often acquire numerous point products to solve specific security problems—a Security Information and Event Management (SIEM) for log correlation, various incident response tools, threat hunting platforms, Data Loss Prevention (DLP) systems, and User and Entity Behavior Analytics (UBA) solutions. These technologies frequently operate in isolation, leading to technology silos. Each tool might have its own proprietary data format, management interface, and operational procedures, making integration and a holistic view of the security posture incredibly challenging.
  3. Data: The fragmented nature of people and technology naturally leads to data fragmentation. Different teams using different technologies generate disparate data points, making it difficult for leadership to gain a comprehensive, actionable view of security risks. The fundamental challenge of data normalization—transforming varied log formats from firewalls, proxies, and antivirus solutions into a consistent structure—remains a persistent hurdle. Without normalized and correlated data, effective analysis, threat detection, and executive reporting are severely hampered.

Furthermore, the external threat landscape has dramatically escalated. Threat actors are highly collaborative, leveraging advanced techniques and even Artificial Intelligence (AI) to enhance their attacks. This adversarial sophistication necessitates a defensive strategy that is equally integrated and intelligent. The panel emphasizes that the current siloed approach leaves defenders perpetually "behind the other side," highlighting the critical need for a more unified and adaptive defense model like the Cyber Fusion Center.

Key Findings

The panel discussion illuminated several key findings regarding the necessity and characteristics of an effective Cyber Fusion Center:

  1. Integration of Core Pillars: A Cyber Fusion Center (CFC) fundamentally aims to integrate people, technology, and data to enable timely decisions and build a robust cyber-resilience environment. This integration is crucial for breaking down existing silos and fostering a unified, "one-pointed focus" for cybersecurity efforts.
  2. Addressing Human Skill Gaps and Inconsistencies: A major challenge lies in the varied skill levels and inconsistent application of knowledge among security analysts. Playbooks, while available, are often underutilized or not updated with new learnings. The panel highlights the need for a suggestive action-driven SOC, where technology can learn from past incidents and offer analysts recommended actions, thereby standardizing processes while allowing for innovation.
  3. Evolution of SOC Architecture: The traditional monolithic SOC built around a SIEM is no longer sufficient. Madan describes an evolution towards specialized, decentralized SOCs, such as an Identity SOC (focused on Identity Threat Detection and Response (ITDR) using UBA technologies) and an Information SOC (leveraging DLP). These specialized units then feed into a "mother SOC," creating a centralized-to-decentralized-to-recentralized architecture for comprehensive coverage.
  4. Strategic Technology Management: With a "plethora of technologies" in most organizations, the key is not just acquiring more tools but ensuring leadership alignment and data connectivity across them. Yogi emphasizes the need for a proactive approach to evaluate and evolve technology stacks, investing in a few stable technologies rather than constantly adding disparate solutions. The goal is to reduce analyst fatigue by minimizing the need to jump between multiple systems.
  5. Overcoming Data Fragmentation and Interoperability: The lack of data normalization and interoperability between different security tools remains a significant hurdle. Proprietary data formats hinder effective correlation and analysis. While open standards like STIX/TAXI for threat intelligence and Software Bill of Materials (SBOM) are emerging, their widespread adoption is still a challenge. The onus often falls on defenders to decode and interpret diverse telemetry, including complex OT logs, into actionable security events.
  6. Crucial Role of Collaboration: Both internal and external collaboration are deemed indispensable. Internally, sharing data between teams (Threat Intel to VM, IR to GRC) is vital. Externally, cross-sector forums and regulatory bodies (like CERT/CISA) facilitate the sharing of Indicators of Compromise (IOCs) and advisories, fostering a collective defense against adversaries who are already collaborating effectively.
  7. AI as an Augmentative Force: Artificial Intelligence (AI) is seen as a powerful tool to augment human capabilities, not replace them. It can analyze vast amounts of historical data ("pre-historic data") to identify patterns, provide predictive insights, and suggest actions, thereby enhancing the efficiency and effectiveness of SOC operations. However, panelists acknowledge AI's "double-edged sword" nature, as threat actors also leverage it (e.g., for creating sophisticated phishing emails without spelling errors), necessitating continuous evolution in defense.
  8. Proactive Use Case Development: Instead of relying on generic use cases, the panel advocates for a proactive approach where defenders "walk the path of the attacker" or the fraudster to understand how an attack is committed. This allows for the identification of blind spots and the strategic placement of sensors or the development of specific telemetry to detect such events, moving beyond a reactive stance.

Technical Deep Dive

The technical discussions revolved around the practical implementation and challenges of achieving an integrated defense posture, focusing on the interplay of people, process, technology, and data.

People and Process Automation

The panel highlighted the critical need to optimize human effort within the security operations. Madan pointed out that analysts, even with playbooks, often deviate or fail to consult them, leading to inconsistent incident handling. The vision is for a "suggestive action-driven SOC" where AI and automation can learn from past analyst actions and incident resolutions. This system would offer real-time recommendations to analysts, enhancing consistency and efficiency. Yogi further elaborated that the ultimate goal is to "reduce the human interaction to the maximum," ensuring that analysts only engage with the most critical events that require human intelligence and decision-making. This involves leveraging automation and orchestration to handle mundane tasks and enrich incident data, presenting a "single pane of glass" to the analyst to minimize context switching and fatigue.

Evolving Technology Architecture

The discussion underscored a significant shift in SOC architecture. Madan described moving beyond a single, comprehensive SIEM as the "mother of all" to a more specialized, distributed model. He detailed the implementation of distinct SOCs:

  • Infra SOC: Focused on infrastructure-level security, likely leveraging traditional SIEM capabilities for correlating logs from noisy sources like firewalls, Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), and Web Application Firewalls (WAF).
  • Identity SOC: Uniquely built for Identity Threat Detection and Response (ITDR), often leveraging technologies like User and Entity Behavior Analytics (UBA) rather than a traditional SIEM. This specialization allows for deep analysis of account compromises and access patterns, mapping directly to early stages of the cyber kill chain or Mitre ATT&CK framework.
  • Information SOC: Focused on data exfiltration and sensitive information protection, with Data Loss Prevention (DLP) at its core.

These decentralized SOCs, each with its distinct technology stack, still need to feed into a "mother SOC" or a central orchestrator. This "centralized to decentralized to re-centralized" approach aims to provide both specialized depth and a comprehensive, holistic view, requiring robust integration capabilities.

Data Normalization and Interoperability

A persistent technical challenge highlighted was the normalization of data. When diverse technologies—from different OEMs—generate proprietary log and event formats, correlating them effectively is nearly impossible. The panel discussed the concept of interoperability, emphasizing the need for common standards for data input and output. While standards like STIX/TAXI for threat intelligence sharing and Software Bill of Materials (SBOM) for supply chain transparency are emerging, their adoption is not universal. Madan specifically pointed out the difficulty in integrating Operational Technology (OT) logs into a traditional SOC, as OT technicians generate logs in formats often "unsto" (unstructured or unknown) by security analysts, requiring significant effort to decode and interpret as security events. This highlights a gap where the burden of translation often falls on the defense side, requiring custom parsers and enrichment engines.

The Role of AI in Operations

Artificial Intelligence (AI) was presented as a transformative technology for the CFC. Madan emphasized its potential for analyzing "pre-historic data"—years of collected logs and incident data—to identify patterns, predict future attack vectors, and suggest alternative defensive strategies. This is distinct from real-time incident response; AI can perform continuous, deep analysis on archived data that humans would find impossible. Yogi also noted AI's role in enriching incident data and automating initial triage, allowing human analysts to focus on higher-level decision-making. The discussion implicitly touched on the need for robust data pipelines and storage solutions to make this vast historical data accessible and usable for AI models.

Demo / Proof of Concept

This session was a panel discussion and did not include a live demonstration or a proof of concept. The panelists shared their insights and experiences through a moderated conversation.

Defensive Implications

The insights from the Nullcon panel provide several critical implications for cybersecurity defenders aiming to build a robust and integrated defense posture:

  1. Break Down Silos and Foster Collaboration: The most fundamental implication is the urgent need to dismantle functional silos within security teams. Organizations must actively encourage and facilitate collaboration between SOC, IR, Threat Intelligence, Vulnerability Management, Red Teaming, and GRC teams. This includes establishing shared communication channels, common objectives, and integrated workflows to ensure that intelligence from one team (e.g., threat intel) immediately informs and benefits others (e.g., VM for triaging exploits).
  2. Invest in Human Capital and Knowledge Management: Defenders must prioritize the continuous development of their security analysts. This involves creating a centralized, easily accessible knowledge base that captures learnings from past incidents and best practices. Furthermore, exploring and implementing "suggestive action-driven SOC" technologies can significantly enhance analyst efficiency, reduce fatigue, and standardize response actions while allowing for innovation. The goal is to reduce manual intervention to only the most critical, human-dependent decisions.
  3. Strategic Technology Adoption and Integration: Instead of accumulating disparate point products, organizations should adopt a strategic approach to technology. This means investing in platforms that prioritize interoperability and data connectivity, allowing for seamless integration across the security stack. Continuous evaluation of existing tools and a proactive approach to adopting new, evolving technologies are essential. The panel's concept of distinct, specialized SOCs feeding into a "mother SOC" suggests a need for architectural foresight to ensure comprehensive coverage and unified visibility.
  4. Prioritize Data Normalization and Correlation: The ability to effectively analyze security events hinges on high-quality, normalized data. Defenders must invest in solutions and processes that can ingest, normalize, and correlate data from a diverse range of sources, including traditional IT infrastructure, cloud environments, and specialized systems like OT. This includes advocating for industry standards like STIX/TAXI and SBOM to improve data exchange and reduce the burden of proprietary data formats.
  5. Embrace AI for Augmentation and Prediction: Artificial Intelligence (AI) is not a replacement for human analysts but a powerful augmentative tool. Defenders should explore how AI can be leveraged for analyzing vast historical datasets to identify trends, predict future attacks, and automate mundane tasks. This requires ensuring robust data pipelines and storage to feed AI models effectively. However, it's crucial to also acknowledge and prepare for AI-driven adversarial tactics (e.g., sophisticated phishing), ensuring defensive AI capabilities evolve in parallel.
  6. Strengthen Collective Defense: Recognizing that "bad guys are collaborating," defenders must also foster collective defense. This means actively participating in cross-sector forums, sharing Indicators of Compromise (IOCs) and threat intelligence with trusted peers, and leveraging advisories from regulatory bodies (like CERT/CISA). This external collaboration significantly enhances an organization's ability to anticipate and respond to emerging threats.
  7. Proactive Threat Modeling and Use Case Development: Rather than relying on generic security controls, defenders should adopt a proactive stance by "walking the path of the attacker" or fraudster. This approach involves understanding attack methodologies (e.g., for CFO fraud originating from spear-phishing or whaling attacks) to identify specific blind spots in current defenses. This enables the development of tailored use cases, strategic sensor placement, and the collection of relevant telemetry to detect and prevent sophisticated attacks.

Key Takeaways

  • Cyber Fusion Centers (CFCs) represent the necessary evolution of traditional SOCs, integrating people, technology, and data to achieve timely decision-making and robust cyber resilience.
  • Breaking down silos across security teams and technologies is paramount, fostering collaboration and sharing of intelligence to create a unified defense posture against sophisticated adversaries.
  • Artificial Intelligence (AI) is a critical augmentative tool for analysts, enabling the analysis of vast historical data for predictive insights and automating mundane tasks, thereby reducing human fatigue and enhancing operational efficiency.
  • Strategic investment in technology and data governance is essential, focusing on interoperability, data normalization, and a proactive approach to adopting evolving solutions rather than accumulating disparate point products.
  • Both internal and external collaboration are vital for collective defense, leveraging cross-sector forums and regulatory advisories to share threat intelligence and learn from peers.
  • Adopting a "suggestive action-driven SOC" model can significantly enhance analyst consistency and skill development, ensuring that institutional knowledge is effectively captured and reapplied.

About the Speaker(s)

The panel featured experienced cybersecurity leaders who shared their insights from diverse roles within the industry. While specific titles and companies were not detailed for each, their contributions reflected a wealth of knowledge in managing complex security operations.

  • Madan (Panelist): Described his experience in setting up and operating distinct, specialized SOCs (Identity SOC, Infra SOC, Information SOC) and the challenges of integrating them into a "mother SOC." His perspective highlighted the architectural evolution of security operations and the strategic use of technologies like UBA and DLP. He also touched upon the philosophical differences in motivation between attackers and defenders.
  • Yogi (Panelist): Emphasized the importance of leadership alignment and data connectivity in managing a diverse technology footprint. He also spoke about the need to protect human resources in security operations by reducing analyst fatigue and presenting information in a single, coherent view. Yogi's insights also covered the dual nature of AI, acknowledging its benefits while recognizing its use by threat actors.
  • Komal (Panelist): Shared perspectives from a regulatory background, stressing the importance of timely reporting of incidents (e.g., within 6 hours to a regulator) and the need for comprehensive visibility for CXOs and boards. Komal highlighted the critical role of collaboration, both within organizations and across sectors, in sharing experiences and collective defense.
  • Moderator: Facilitated the discussion, guiding the panelists through the core themes of people, technology, and data challenges in the context of Cyber Fusion Centers. The moderator set the stage by introducing the concept as an evolution rather than just a buzzword.

Collectively, the panelists offered a comprehensive, practitioner-oriented view of the challenges and strategic imperatives in building integrated cyber defense capabilities.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A panel that correctly identifies real operational pain points — silos, data normalization, analyst fatigue — but never moves past the diagnosis. Every observation here is available in a Gartner brief, a vendor whitepaper, or a five-year-old RSA keynote, and the moderator never pushed anyone to say something they couldn't have said on LinkedIn.

Heather Calloway (CISO) — WEAK

A practitioner panel that correctly diagnoses the right organizational problem — silos, fragmented data, inconsistent human process — but never gets past the diagnosis. The conversation stays at the level of framework and aspiration, never producing a decision, a tradeoff, or a usable model for anyone trying to actually build or govern one of these programs.

→ Top-rated talks at Nullcon Goa 2025

All talks from Nullcon Goa 2025