Student-Powered SOCs


View of participating students in the student-powered co-managed SOC working together on the quad.
View of students entering academic building on their way to the student-powered SOC.
TekStream tBook design graphic element.

Understanding What’s at Stake

Budgets are often cited as the primary barrier for improving public sector cyber defenses. After all, running 24/7 threat monitoring on best-in-class technology can get expensive — particularly when competing with the private sector over a shrinking talent pool. But this is not a problem the public sector can buy its way out of.

Federal grants and funding provide little cover if you lack the people to run and operate the cybersecurity program. With over 900,000 cybersecurity roles currently open in the U.S., the talent gap must be addressed first to secure the digital ecosystem of public institutions.

Female student getting hands on SOC training.

TekStream tBook design graphic element
Students walking to student-powered SOC after class.

Removing the Roadblock

Solving the need for well-trained security professionals will take more than a formal education. AI has reduced the need for entry-level cyber analyst roles, making it difficult for recent graduates to successfully enter the workforce.

The solution we have developed with LSU bridges the gap. It takes the concept of the traditional tiered curriculum and enhances it with just-in-time training. Students work as TekStream employees and gain real-world cybersecurity incident response and engineering experience using Splunk SIEM/SOAR technology built on top of AWS infrastructure.

Equipped with a dashboard of actual events and activities completed in the security operations center (SOC), and a higher level of skills that aligns closer with growing market demand, students can quickly enter the workforce after graduation as mid-level cybersecurity engineers.

TekStream tBook design graphic element
Participating students in student-powered SOC gaining enhanced cybersecurity training.

How It Works:
The Student-Powered SOCs
Model at Play

Under a whole-of-state approach, each participating institution has a role to play. They leverage each other’s strengths and services to provide a unified front against cybercriminals. Higher education institutions provide the talent pipeline and the sandbox that powers the shared SOC.

State and federal agencies supply the connectivity and funding that enables proactive, shared threat response across all participating institutions. And private sector institutions provide the technology and framework to make the model work.

It’s a flexible template that inherently addresses growing financial, time and resource barriers that have historically held the public sector back in regard to cybersecurity.

Graphic view of TekStream's unique cost deferment model used in its student-powered SOC model.

Cost Efficiency at Scale

The whole-of-state and student-powered SOC concept is not new. What makes this approach novel is the investment model we have created with our technology partners, Splunk and AWS. Rather than a locked-in approach, the goal is to give public sector institutions control of their program.

As students become more proficient in identifying and resolving threats, the cost and level of our involvement diminish, resulting in lower costs and complete ownership of the program in the long term. Participating entities also gain additional cost savings by reducing the number of required licenses under a shared SOC management approach.

TekStream tBook design graphic element

The Power of a Unified Approach

The true value of public-private partnerships is in safeguarding our digital infrastructure. Our student-powered, whole-of-state approach enables public sector entities to protect their data while benefiting from shared intelligence and an enhanced security posture.

The framework we have developed leverages automation and threat intelligence to provide real-time threat monitoring and rapid incident response. It also powers collaboration and continued resilience by creating a growing, best-in-class library of assets accessible to all entities in the ecosystem.

It’s about enabling each other to evolve as threat actors become more sophisticated and new technologies emerge.

View of an academic building where a student-powered SOC can be set up.

View of Atlanta government building.