Start a new cybersecurity ops team

Been asked to build a cybersecurity operations team and not sure where to start? We help you figure out what you need, plan the right team size and structure, and even sit in on interviews to make sure you hire well.

Pipedrive form will go here.

What would you like to know?

Why work with us

We’ve built security operations teams before

Deep SecOps experience building and running teams internationally — our consultants have established security operations teams across sectors and countries, from national CERTs to enterprise SOCs
SIM3 assessors who know what effective teams look like — we use the Security Incident Management Maturity Model to benchmark and design teams, so you start with a clear picture of what good looks like
Practical, right-sized advice — we don’t give you a one-size-fits-all blueprint. We tailor our recommendations to your budget, timeline, and organisational context
Senior practitioners you work with directly — no junior consultants reading from a playbook. You get experienced people who’ve spent their careers in security operations
Cosive's Prescott Pym presenting on security operations at AUSCERT.
understand your needs

Figure out what functions your SecOps team needs to provide

Before you hire anyone, you need to understand what your organisation actually needs from a security operations team. We help you map out the functions, capabilities, and tools required — so you build a team that fits your risk profile and budget, not someone else’s template.

Every organisation is different. A team of three looks very different to a team of fifteen, and both can be effective if they’re focused on the right things.

Discuss your goals
01

SecOps functions mapping

Identify which security operations functions your team actually needs to provide. Not every organisation needs the same set of capabilities — we help you focus on what matters for your risk profile and industry.

02

Team size and structure

Right-size your team for your organisation. We help you work out how many people you need, what roles to create, and how to structure the team so it can operate effectively from day one.

03

Capability assessment

Work out which capabilities are essential for your team versus nice-to-have. We help you prioritise so you can build incrementally rather than trying to do everything at once.

03

Technology requirements

Understand what tools and platforms you’ll need to support your team. We give you practical, vendor-neutral advice based on your budget and what your team will actually use.

plan the build out

Plan your cybersecurity operations team build out

We can perform a SecOps assessment to figure out exactly what shape your team needs to be in order to be effective. From there, we build you a phased implementation roadmap — so you know what to do first, what can wait, and how to measure progress along the way.

This isn’t an abstract strategy document. It’s a practical plan you can start executing immediately, with clear milestones and realistic timelines.

01

SIM3 baseline assessment

A structured assessment of what your organisation needs from a security operations team. We use frameworks like SIM3 to give you an objective baseline and clear targets to build towards.

02

Implementation roadmap

A phased plan for standing up your team over time. We break the build into manageable stages so you can show progress early and adjust as you learn what works.

03

Process design

Design your core operational processes — incident response, triage, escalation, and handover. We help you get the fundamentals right so your team can hit the ground running.

04

Framework adoption

Help choosing and operationalising the right frameworks for your team. Whether it’s SIM3, SOC-CMM, ATT&CK, or a combination — we help you adopt what’s useful without drowning in process.

Discuss your build plan
Help with hiring

Hire the right people for your cybersecurity operations team

Not sure what traits make a good incident responder? We can help you choose the best team to provide a good range of skills. From writing job descriptions that attract the right candidates to sitting in on interviews — we make sure you hire people who can actually do the job.

Getting your first hires right is critical. The people you bring in early set the culture and capability of your team for years to come.

Discuss your hiring needs
01

Role definition

Define the roles your team needs and write job descriptions that attract the right candidates. We help you describe what you actually need — not a wish list of every security certification in existence.

02

Skills assessment

Identify the right mix of skills for your team. A good SecOps team needs a balance of technical depth, analytical thinking, and communication — we help you work out what that looks like for your context.

03

Interview support

We can sit in on candidate interviews and help you select the best people. Our experience hiring and managing security teams means we know what to look for beyond the CV.

03

Onboarding planning

Help structure onboarding for your new security hires. Good onboarding accelerates time-to-value and helps new team members feel confident and productive from the start.

Frequently asked questions

Common questions about starting a cybersecurity operations team

get in touch

Start building your security operations team

Tell us where you’re at and we’ll help you figure out the right next steps for building your SecOps team.

Pipedrive form will go here.