HomeEventsInterview#Interview: Rethinking Security Operations Centers (SOCs): Towards a New Generation of Cyber...

#Interview: Rethinking Security Operations Centers (SOCs): Towards a New Generation of Cyber Defense in Africa

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

This interview explores the evolution of Security Operations Centers (SOCs) across Africa, examining how organizations are strengthening cyber defense capabilities, adopting AI-driven security operations, addressing talent shortages, and building resilient cyber ecosystems. The objective is to provide actionable insights for CISOs, CIOs, security leaders, policymakers, and technology professionals shaping the future of cyber defense on the continent.

Biography: Yannick KPAKI-EMILE

Yannick KPAKI-EMILE is a senior executive specializing in cybersecurity, IT governance, and risk management, with more than 16 years of experience in technology and telecommunications environments.

As Manager Security Capabilities & CISO at Groupement Orange Services, he has expertise spanning operational security, infrastructure security, and cyber governance. He has notably contributed to the implementation and management of a SOC covering several Orange entities across Africa and the Middle East.

He has also led major ISO 27001 certification initiatives, including the transition to ISO 27001:2022, and is certified as an ISO 27001 Lead Implementer.

Passionate about cyber resilience and leadership, Yannick KPAKI-EMILE advocates for an approach to cybersecurity that is integrated into business strategy, combining technology, governance, risk management, and skills development.

1. Introduction / Introduction

Question 1

Could you introduce yourself to our readers and share your professional background, current role, and experience in cybersecurity operations and Security Operations Centers (SOCs)?

First of all, thank you for the opportunity to discuss cybersecurity, which is more relevant than ever today, particularly in Africa, where organizations are accelerating their digital transformation while facing increasingly sophisticated cyber threats.

As for my career, I would start by saying that I entered the world of cybersecurity somewhat by chance.

I am a network engineer by training, with an academic background built around a combination of university education and engineering school, through a collaboration between Pierre and Marie Curie University in Paris and ENST Paris, now Télécom Paris.

I began my career with an approximately 18-month experience at SNCF, working in networking and telecommunications applied to the railway sector. I then joined Orange Group as a project manager, with professional experiences in Paris, Niamey, and then Abidjan, where I joined Groupement Orange Services in 2012.

My real transition into cybersecurity came in 2018. After contributing to the construction of the ITN environment of a data center – a project that gave me a very practical understanding of critical infrastructure and its security challenges – I was entrusted with conducting a proof of concept to assess the implementation of a shared SOC for several Orange operators in the MEA region.

The POC was a real success, and the Group decided to roll out the initiative more broadly. I then had the opportunity to take responsibility for this SOC.

When I started this journey, we had three subsidiaries. Two years later, when I left the role, we had successfully integrated 15 entities into the program. It was an extremely enriching experience because it allowed me to work simultaneously on technology, detection and incident response processes, as well as the organizational and human dimensions of a SOC operating in an international and shared environment.

After this experience, I continued my career in operational security, deepening my knowledge of security protection, detection, and incident management capabilities.

For the past five years, I have also expanded my scope into cybersecurity governance, with responsibilities covering risk management, compliance, infrastructure security, and the definition of security policies and strategies.

Today, my role gives me a fairly comprehensive view of cybersecurity, from highly operational and technical considerations to governance and strategic challenges.

Question 2

Security Operations Centers have become a strategic pillar of organizational cyber defense. How do you view the evolution of SOCs across Africa over the past few years?

I believe there has been a genuine increase in awareness in Africa in recent years. Large companies, but also SMEs and public organizations, have understood that cyber risk has become a reality that can affect any organization, regardless of its size.

It is no longer enough simply to protect yourself; organizations must also be able to anticipate, monitor, detect, and respond rapidly to threats. It is within this context that the SOC has become one of the most effective responses.

We are also seeing two trends: some large organizations are choosing to develop their own SOC, while others prefer to outsource the service to specialized providers. This is helping a genuine cybersecurity ecosystem emerge in Africa.

In Côte d’Ivoire, for example, the market is particularly dynamic, with several players offering innovative SOC services, including Orange with OCCS, 3R Technologies, Talentys, among others.

I believe the next step will be to make these services even more accessible, particularly to medium-sized companies, and to evolve SOCs toward greater automation and stronger response capabilities. This evolution will contribute to strengthening the long-term cyber resilience of African organizations.

2. The Current State of SOCs in Africa

Question 3

How would you assess the current maturity level of SOCs across African enterprises, government institutions, and critical infrastructure?

I would say that the level of maturity remains quite uneven and depends heavily on regions, industries, and the resources available to organizations.

In North Africa, in countries such as Morocco, the SOC is now a fundamental component of cybersecurity, particularly in sectors such as telecommunications, banking, and critical infrastructure. We are also seeing the emergence of more advanced technologies, particularly artificial intelligence, to improve threat detection and analysis.

In Sub-Saharan Africa, there is still some way to go, particularly in terms of skills and qualified human resources. But things are evolving rapidly. Organizations are becoming more aware of the challenges and are gradually investing in cybersecurity technologies, skills, and services.

I therefore believe that the overall momentum is clearly positive, even though the level of maturity remains highly heterogeneous from one country and organization to another.

Question 4

What are the biggest challenges African organizations face when establishing or modernizing a SOC?

I believe technology is no longer really the main challenge when an organization wants to establish or modernize a SOC. The solutions exist and are becoming increasingly accessible.

The real challenge lies more in the skills and organizational capabilities that will allow the SOC to operate effectively over the long term.

The key is the people who will run it. Their skills will make it possible to define the right processes, conduct a relevant risk analysis of the platforms and services being monitored, and above all build use cases adapted to the threats to which the organization is actually exposed.

Question 5

How are today’s cyber threats reshaping the priorities of SOC teams across Africa?

Cyber threats are evolving extremely rapidly today, sometimes at lightning speed. This evolution forces SOC teams to maintain a constant posture of anticipation and vigilance.

In a sense, they must remain continuously in a “state of war,” meaning they need to learn to think like an attacker: understand their methods, anticipate their movements, and identify signals that can help detect an attack before it produces its effects.

SOC priorities are therefore naturally shifting toward better threat knowledge, continuous improvement of use cases, automation of certain detection activities, and, above all, the ability to detect faster and respond more effectively.

Today, the question is no longer only how to protect ourselves, but also how an attacker could bypass our defenses and how we can detect them before they achieve their objectives.

3. Building Effective SOCs

Question 6

What are the essential components of a modern SOC capable of responding effectively to today’s cyber threats?

The choice of technology solutions remains obviously important. A modern SOC must be able to rely on a combination of technologies such as SIEM, EDR, Threat Intelligence, and now artificial intelligence, but above all these different components must work coherently and be able to communicate with one another.

Beyond technology, however, I believe the real effectiveness of a SOC rests on organization, skills, and processes. These must be flexible enough to adapt quickly to evolving threats and enable the most appropriate response.

In short, an effective and modern SOC is not simply an accumulation of technologies: it is the combination of technology, people, and processes capable of evolving rapidly in response to the threat.

Question 7

Which technologies do you consider indispensable for a modern SOC, such as SIEM, SOAR, XDR, EDR, Threat Intelligence, and UEBA?

As I mentioned earlier, the most important factor is above all the selection and combination of the different solutions. These components must be able to operate coherently and, especially, communicate with one another so that information can be shared effectively and certain actions can be automated.

For me, the minimum foundation today consists of a SIEM, a SOAR, and an EDR, combined with Threat Intelligence and, increasingly, artificial intelligence capabilities to improve threat detection, analysis, and response.

The objective is therefore not to accumulate technologies, but to build a coherent and integrated ecosystem capable of rapidly transforming data into detection, and then detection into action.

Question 8

To what extent do cloud-based SOCs, hybrid SOC models, and Managed Security Service Providers (MSSPs) represent an opportunity for African organizations?

I tend to believe that large organizations, particularly those managing critical infrastructure, should seek to retain a certain degree of autonomy and independence in managing their cybersecurity.

For medium-sized companies and very small businesses, however, cloud solutions, hybrid SOCs, and managed services offered by MSSPs can represent an excellent solution. They provide access to technologies and skills that can sometimes be difficult to acquire or maintain internally, while helping control costs.

I therefore believe these models are particularly relevant for Africa, but ultimately not only for Africa: the right model depends primarily on the size of the organization, its maturity level, its resources, and the criticality of its activities.

4. AI and the Future of SOC Operations

Question 9

Artificial Intelligence is transforming cybersecurity operations. How do you see AI impacting African SOCs?

Artificial intelligence is already here and deeply embedded in our lives, whether we want it or not. African SOCs, like others, will not be able to avoid it.

For me, the choice is quite simple: either we accept this evolution, adapt, and learn to make the most of artificial intelligence, or we risk falling behind very quickly.

Because one thing must be kept in mind: the other side is also using artificial intelligence, increasingly and continuously, to automate attacks, search for vulnerabilities, and bypass defensive measures.

The challenge for African SOCs will therefore be not to suffer this evolution, but to use it to their advantage, particularly to improve detection, accelerate analysis, and strengthen response capabilities.

In my view, tomorrow, a SOC that does not integrate artificial intelligence into its operations may simply no longer be able to keep pace with the threat.

Question 10

What tangible benefits can AI bring in threat detection, automated response, and reducing incident response times?

The first benefit, in my view, is that by adopting artificial intelligence, we give ourselves the means to fight the attacker on more equal terms.

AI can learn rapidly from past events and incidents, identify recurring patterns, and help us prepare more effectively when a similar threat reappears.

It can also save enormous amounts of time in event analysis, correlation, and alert qualification, while automating certain response actions.

Beyond technology, I see another major benefit: allowing human capital to move away from repetitive tasks and focus on tomorrow’s challenges, anticipation, and the most complex threats.

Question 11

What risks or limitations should organizations consider when integrating AI into SOC operations?

In my opinion, the greatest risk would be to try to replace human intelligence with artificial intelligence.

AI can analyze, correlate, learn, and automate certain tasks, but it can never completely replace human intelligence, experience, judgment, or an analyst’s instincts when facing a complex situation.

AI should therefore remain a decision-support tool, rather than becoming the decision-maker.

It is therefore essential to integrate it into the SOC’s tools, processes, and organization while keeping humans at the center of the system. This complementarity between artificial intelligence and human intelligence will allow organizations to gain the greatest value from AI while managing its limitations.

5. Cyber Talent and SOC Teams

Question 12

The cybersecurity skills shortage remains a major challenge. How can organizations attract, train, and retain SOC analysts in Africa?

In my opinion, there are two essential levers on which organizations should rely.

The first is to identify senior profiles and key managers who can pass on their experience and play a mentoring role. Organizations must also make these professionals want to join the journey by clearly presenting the organization’s project, its vision, and, above all, the strategic importance of the SOC in protecting the company and its customers.

The second lever concerns young IT professionals who have a genuine interest in cybersecurity and artificial intelligence. Organizations need to be able to identify them, train them, and, above all, show them the career opportunities offered by a path within a SOC.

Finally, to retain these talents, compensation and benefits remain important, but they are not the only criteria. Career prospects, continuous training, technical challenges, and the feeling of contributing to a meaningful mission are also essential.

By combining the experience of senior professionals with the energy of young talent, we can gradually build the cybersecurity capabilities Africa needs.

Question 13

Which technical and soft skills will be most valuable for SOC analysts over the coming years?

We have discussed this several times throughout the interview: artificial intelligence will be at the heart of the evolution of SOC roles.

Beyond the traditional skills of a SOC analyst, professionals with expertise in AI, data management and analysis, as well as scripting and task automation, will provide significant added value in the future.

But beyond technical skills, interpersonal capabilities will remain more important than ever, particularly for experienced analysts and Level 3 experts. Adaptability, analytical thinking, the ability to step back and see the bigger picture, and especially communication will be decisive.

During a crisis, for example, an expert must be able not only to quickly understand what is happening, but also to translate a technical problem into clear and understandable information for decision-makers.

Question 14

What role should universities, training institutions, governments, and the private sector play in developing Africa’s future SOC professionals?

I believe one of the weaknesses of our education system in Africa remains the lack of practical experience. Today, we need professionals who are operational as soon as they complete their training, and this requires the current model to evolve.

We need to bring academic education closer to business realities by giving students the opportunity to gain genuine practical experience from the earliest years of their training. This is notably what is done in several European countries through apprenticeship and work-study programs.

This is precisely where governments and the private sector must work together in a win-win partnership: develop more cybersecurity training programs, but above all training that enables students to put their knowledge into practice quickly.

The need for skills is real and the opportunities are numerous. We now need to create bridges between universities and companies. The talent is there; we need to give them the means to become operational quickly.

6. Collaboration, Threat Intelligence and Resilience

Question 15

How important is threat intelligence sharing in improving the effectiveness of African SOCs?

I would even say that it is critical. African organizations, whether public or private, have had to accelerate their digitalization significantly, sometimes without having enough time to anticipate and address all the risks, particularly those related to cyber threats.

I am convinced that we share many common risks and threats. It is therefore essential to share experience, information, and best practices so that everyone can be better prepared to face attacks.

There are already some strong initiatives, notably the creation of CERTs and national cybersecurity agencies in several countries. But these structures must also learn to cooperate and share more in order to collectively strengthen our level of defense.

We are also seeing the emergence of cybersecurity professional associations in several countries. I am fortunate to be part of one of them in Côte d’Ivoire, which also supports similar initiatives in other countries.

Ultimately, I believe it is the synergy of all these initiatives – states, CERTs, national agencies, companies, SOCs, and professional communities – that will enable us to better understand the threat and, above all, make our SOCs more effective and better prepared.

Question 16

How can collaboration be strengthened between national CERTs, government SOCs, private organizations, and international partners?

For me, three elements are essential to strengthening this collaboration.

The first is communication. Secure channels must be established to enable rapid sharing of information about threats, incidents, and best practices among the different stakeholders.

The second is experience sharing, particularly through regular crisis exercises and cyber simulations bringing together public and private organizations. By preparing together, we learn to respond better together.

Finally, there is the regulatory framework. States must establish legislation that encourages, and where necessary requires, information sharing and cooperation between public and private stakeholders, while ensuring the protection of sensitive data.

Cybersecurity can no longer be approached in isolation. Faced with a threat that knows no borders, our response must also be collective.

Question 17

With cyberattacks targeting critical infrastructure on the rise, what priorities should guide SOCs over the next five years?

I believe this question ultimately summarizes much of what we have discussed throughout the interview. Four priorities seem essential to me.

The first is to leverage new technologies, particularly artificial intelligence, to improve SOC efficiency, accelerate detection, and reduce response times.

The second is to adopt a genuine Zero Trust approach. Trust does not exclude control, and this philosophy must be applied at every level of our organizations and IT infrastructures.

The third, and for me the fundamental one, concerns skills. We can have the best technologies on the market, but without the men and women capable of using them, their effectiveness will remain limited. We therefore need to invest in training, attract talent, and above all develop genuine local cybersecurity expertise.

Finally, the fourth priority is collaboration. Faced with threats that are becoming increasingly organized and transnational, no actor can be effective alone. SOCs must therefore strengthen their cooperation with CERTs, national agencies, private companies, and all stakeholders within their ecosystem.

Ultimately, I would say that tomorrow’s SOCs will need to be smarter, more agile, and above all more connected to their ecosystem. It is under these conditions that we can sustainably strengthen the resilience of critical infrastructure in Africa.

7. Vision for Africa’s SOC Ecosystem

Question 18

Which sectors across Africa should prioritize investments in SOC capabilities to strengthen their cyber resilience?

I believe that today three sectors are particularly exposed and represent priority targets for cyber attackers.

The first is banking and fintech, because they directly handle money and the financial data of individuals and companies.

The second is telecommunications, which is a vital sector for the functioning and economy of a country. A major attack against an operator can quickly have consequences extending far beyond the company itself.

Finally, there is government, particularly through essential services such as tax administration, public administration, and critical public infrastructure. Their rapid digitalization also makes them important targets.

These sectors must therefore strengthen their detection and response capabilities. The threat is already here and continues to grow. It is no longer a question of whether we will be attacked, but whether we will be ready when it happens.

Question 19

What strategic vision would you recommend to African leaders to accelerate the development of a sustainable, sovereign, and high-performing SOC ecosystem?

In the world we live in today, the value of information is priceless. It is therefore essential to protect it, but also to constantly know what is happening around it and within the infrastructures that carry it.

Naturally, this “eye” that we need is the SOC. A SOC is a powerful combination of people and technology, but it is not enough simply to install it: we must know how to operate it, evolve it, and above all organize it so that it can anticipate threats and counter them effectively.

For African decision-makers, the challenge is therefore to build SOCs adapted to our realities, capable of developing local skills and fostering cooperation among the different stakeholders in the ecosystem.

Question 20

Finally, how do you envision African Security Operations Centers by 2030? Which innovations will have the greatest impact on their evolution?

It is quite simple: what I would like to see by 2030 is African SOCs that collaborate, share their experiences, and jointly define common tools and capabilities to better fight cyber threats.

I would also like to see SOCs capable of continually reinventing themselves and agile enough to adapt rapidly to changes in the techniques used by cyber attackers.

I also envision them being powered by well-trained human capital, capable of ingenuity and innovation, because technology alone will never make the difference.

Finally, I would like to see SOCs that have learned to master artificial intelligence not as a miracle solution, but as a fully integrated tool capable of delivering real added value to teams in their daily fight against cyber threats.

Ultimately, by 2030 I envision African SOCs that are more collaborative, more agile, more autonomous, and more intelligent. SOCs that will no longer simply react to attacks, but will be capable of anticipating them.

And if we succeed in bringing together human intelligence, technology, and the power of collaboration, I am convinced that Africa will have everything it needs to build its own model of cyber resilience.

Closing

Thank you sincerely for sharing your expertise and strategic vision with the global CyberCory.com community. Your insights will help advance the discussion on the evolution of Security Operations Centers and the strategies required to strengthen Africa’s cyber resilience against emerging threats. Together, we can help build a safer, more innovative, and more resilient digital ecosystem for future generations.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img