From MSSP to MCOP, Part 3: Regional Resilience and the Cybersecurity Lifecycle
with Michael Pegues, former CIO, City of Aurora
How the MCOP model scales into a regional security operations center, and how the cybersecurity lifecycle and tabletop exercises keep a program from going stagnant.
The final part moves from a single city to the regional security operations center (RSOC), a shared cybersecurity utility where municipalities pool costs and share threat intelligence in real time. Cyrus Walker explains the cybersecurity lifecycle — governance, process and procedure, and technical infrastructure management — and why those three components have to stay in balance. Michael Pegues describes how Aurora built incident response and tabletop exercises into its continuity of operations plan, and both close on why trust between a municipality and its provider is what makes the model work.
In parts one and two, we explored why traditional MSSPs fall short when free programs expire and how the MCOP model helped Aurora, Illinois build continuous cyber operations and regain control of risk, cost, and staffing. In this final segment, we zoom out from a single city to the regional security operations center or RSOC, a shared cyber security utility where municipalities pool resources, share intelligence, and strengthen each other's defenses in real time. From there, we'll close with a cyber security life cycle and a 90-day action plan leaders can use to sustain resilience long after the grants and awareness campaigns end. Let's get back into the conversation. It's actually amazing because once that foundation is in place, it doesn't stop at one city's borders.
What we're really talking about is an evolution from a single deployment to a regional security operation center or RSOC. A shared service model where multiple municipalities can collaborate, share costs, strengthen each other's defenses in real time. Now, Cyrus, expanding on that for us, how does the MCOP framework and specifically the successful launch of Data Defenders regional SOC utility make that kind of shared intelligence and threat response possible across communities? Yeah, that's an important distinction there that that shared services model which makes adopting a comprehensive solution much more easier and palatable for those smaller municipalities. One of the unspoken benefits of a shared services model is also the shared intelligence that comes along with that.
So for instance, if something is happening at a city like Aurora, that intelligence can be automatically shared across various tenants for surrounding communities like Naperville or Woodridge or Palatine or Lisle or or any of those surrounding communities to Naperville to help them strengthen their their defenses immediately to the to the threat that's been identified. And uh in that MCOP model, it it allows for that seamless transfer of information immediately. Again, unlike a MSSP that is siloed because the point solution is only allocated to that particular customer and so you only have that information that um can be used for that customer in the MCOP model particularly in the DataShield Cybersecurity 360 model that we develop there's a back plane of intelligence that happens and intelligence sharing that happens that allows for our security operators is to be able to immediately scale up and and intensify services when it's needed and then scale it down when it's not needed. And that's just one of the specific benefits when you actually look at it from trying to leverage the impact in that shared service model, right? Also, you got regional cost sharing opportunities where you the you know the larger municipalities may pick up the bulk of the cost, right? where the smaller villages don't have to pay, they're just paying a much smaller percentage and they join into that joint contract.
So those costs are shared proportionately, you know, based on and they can be shared proportionally based on the population, the budget, you know, the system size and then those smaller cities gain access to more advanced cyber security capabilities without having to bear that full, you know, financial cost as well. That's where that you know that shared service model is very very beneficial in regional areas or where you have larger municipalities um like something like the city of Chicago and then you have you know uh thousands of cities and villages that can you know piggyback for lack of a better word that particular model you know that's that whole kind of regional SOC as a service approach on to being smart about your cyber security. Yeah, that's that's an excellent point. There is a a weighted cost that uh can be applied to the municipality based on uh various parameters like number of residents, size of the technology, infrastructure, number of endpoints that so it's not a one-sizefits-all kind of scenario. Um it's it's it's very be bespoke to the municipality or to the the the unit of government.
Um but and which allows for that waiting delivery of services and and and resulting cost that comes along with that. You know, Cyrus, that's a really great breakdown and it really highlights how flexibility and scalability are built into the MCOP framework. For example, each municipality gets a solution tailored to its size, infrastructure, and resources rather than a one-sizefits-all model. But scalability protection is only part of the story. True resilience isn't just about managing costs.
It's about building discipline, turning strategy into daily practice that continuously improves over time. So with that said, let's shift gears from how the MCOP model operates to how leaders can sustain it. So this brings us to our third pillar, the cyber security life cycle and 90-day action plan. Cyrus, can you walk us through what the cyber security life cycle really means and why it's so essential for long-term operational resilience? So, yeah.
So, the cyber security life cycle is a methodology that identifies the important aspects of a cyber security operation and the the important considerations made about the daily operations. So the life cycle itself basically means that you know you go through this process you come back to the starting point you start all over again. The whole point of that is evolution. Hopefully as you've gone through that process once you've learned a lot you can then add that information back into the stream of operation which should translate into an evolution of the operation. So it's getting better and and that operates in in either a generalistic perspective or in a a very in in time real time perspective.
So for instance with threat hunting you know as you are are learning more about new threats or persistent threats you are adding that information back into your operation to create a stronger defense a stronger response to that threat. But the life cycle itself we've identified that there are three major components of any cyber security operation and as I mentioned earlier there's the governance aspect which is the strategy the planning then there's the process and procedure aspect which is the action part of the operation and then there's the technical infrastructure management piece which is the response and what I mean by that is you know as you identify the risks in your environ you're responding to those risks by building a cyber security operation or cyber security infrastructure that can help you to mitigate or counter those risks. And as you are operating your op as you're running your operations on a daily basis, those three components should be evolving and getting better over time, but they should also be informing each of the other components. For instance, your governance component is going to inform your process of procedure. meaning you're going to identify a strategy or a risk management program or policy or compliance program that's going to dictate what the other two components are going to look like. But it's going to initially directly inform the process and procedure piece uh that dictates how you go about operating and acting in your environment that is going to dictate what technology you need in order to support your action.
And that's the technical infrastructure management piece. Not and not just technology but what what people do you need in order to run this on a daily basis. And so as you are going through that process it becomes cyclical. It should never become stagnant. Anytime a cyber security operation becomes stagnant you are as vulnerable uh as as if you didn't do anything in the first place.
Why? Because that threat is always evolving. And particularly now that we're dealing with AI, AI is accelerating the evolution of those threats and and and bad guy capabilities. And so that means that this life cycle has the operation has to continue to evolve as well. There's a there's an ancillary component to all of this and that each of those components should be directly informing and indirectly informing the other components of the life cycle so that you have what's called balance.
Because if you think about a circle, if you will, or or just a wheel, you know, uh in order for a wheel to properly service or provide that service, it's got to be in balance. Otherwise, it's going to be a bumpy ride. We find that most cyber security operations are out of balance. Meaning, they've done well with the governance, but they've not done well in implementing the process procedures or the technical infrastructure management to match what the governance said. or they've grown their their architecture in an ad hoc way in response to industry threats or stuff that they've heard on the street. They go out and get the next latest and greatest point solution to address that threat, but it not it's not correctly reflected in their governance strategy or their process and procedure.
As an anecdote, we had a customer, a municipal customer that basically was a one-man shop. They were pretty large city and every time we had a meeting, we always marveled at all the monitors that were behind the CIO's desk. He had 10 monitors behind his desk and each one of those monitors was a point solution that he himself had eyes on. None of those point solutions were integrated with each other. They were they were there because he had he was responding to what he was hearing in the industry about threats and experiences that other people had and he just went out and purchased the latest and greatest point solution to help mitigate that threat.
But they still had an incident because of the lack of integration and his technical infrastructure management and alignment with the governance and process and procedure piece. So that's a that's basically the life cycle how that life cycle works. There has to be balance. There has to be alignment and there has to be comprehension across each of those three components. Before I get into the response for that, for a minute I thought Cyrus was talking about me with all those monitors behind it, but then as he went on and in his explanation, I said, "Nah, that's not me." Because I didn't go and buy anything.
So all right. I have one big monitor. No, you know, you just had one big monitor on your desk, right? Yeah, that's funny. Um, Mike, from your experience at Aurora, how do tabletop exercises and incident response planning fit into that life cycle?
And more specifically, how did you use those tools to keep your teams in your city's critical operations ready for the unexpected? Okay. So, the incident response and also the tabletop exercise is really readiness, right? you're staying consistent and you're staying updated and trained and not just you, your entire team and also those you know your stakeholders in terms of if there is a outage how do we respond to that actually how do we identify how do we detect how do we you know protect oursel and we respond to that as part of the overall uh life cycle management when we had you know that MCOP model that directly integrate into what we called Our continuity of operations plan, we called it our COOP, C-O-O-P, continuity of operations, right? The incident response plan was an artifact within the city's continuity of operations plan. Now, keep in mind, the COOP plan is basically a plan that they use or it's designed to say, how do we respond when critical services are out?
Whether it's 911 dispatch, whether it's the water treatment, whether it's the financial system is down, right? and how do we basically remain operational during that disruption and how we recover those services right so that incident respond plan of that particular artifact is how we respond in terms of you know the staff within you know the IT department but the actual management pieces I think it's all kind of integrated together because you know the city depend on those services uh to function to provide to our citizens But you know the M COP is there to make sure that that incident response is actually integrated. So that COOP plan actually requires clear procedures for responding to those emergencies and that's where the MCOP brings that structured incident response playbook that you know that's aligned to the NIST standards and probably the you know the FEMA from Department of Homeland Security guidance as well to ensure that the incident is handled with the same rigor as any other natural disaster or physical emergency that might happen. So again, as you talked about before, that resiliency piece is actually built in to make sure that those controls are there so we know how to fail over, cut back, and recover in those times of needs. So when there's that disaster and a cyber threat in the city of Aurora, we actually had it updated within our city ordinance. It is a considered you know an incident that requires the utmost importance just like a flood just like a tornado you know so the whole ideal is to make sure that resiliency is there that redundancy is there and we continue to improve those services right and again it all goes back to the public trust piece that we're actually proactively safeguarding our citizen data and services and basically we're strengthening that trust during a crisis Right, Mike.
That's a very important reminder because in in the end, cyber security isn't just about systems. It's about trust and public confidence depends on how well we prepare, respond, and recover, especially when the stakes are high. So, for leaders who want to start putting their readiness into action, we've created a companion resource, the IRP tabletop checklist and executive oversight dashboard. It's available in the show notes below. It walks you through a 90-day action plan on how to run your first dependency sprint, track tabletop exercises, and clearly report outcomes to leadership and council members.
So, before we wrap up with our final segment, Cyrus, Mike, any closing thoughts you'd like to add? Yeah, so you know, the the the thing that is most important about the MCOP model is the initial consideration of trust. You know, again, I talked about the idea of control, but the the consideration of trust allows for the municipality or or customer to be able to relinquish that control in a in a controlled way, you know, to use that word for double meaning. um and trust the the the that the vendor is going to do what the vendor is going to do which is to to manage and and deliver operations while the customer controls the governance and strategy aspect of it with input from the from the vendor from the MCOP vendor. And so what that does is it rightly places both the customer and the vendor in the right places in this cyber security operation which allows it to move forward in a very fluid and cohesive and expedited way. Without that trust, you're going to have you're going to naturally have conflict.
And when you have conflict, things don't work. I remember I had a customer back in the day. They had rolled out a $10 million network upgrade using this vendor called Bay Networks and the network wasn't performing like it was it was a New England based provider. They didn't have any had zero trust from the vendor because the network kept shutting down across the New England area from Maine all the way down to New York. They were ready to throw out the vendor and spend another $10 million to bring in Cisco.
But it wasn't until I came in and identified that there was an issue of trust between the two, the customer and the vendor, that we began to work on reestablishing that trust, that we were able to actually find out what the problem was, why the network was shutting down the way that it was. And we were able to fix the problem and save the account for both the the vendor and the customer. So that's an example of how trust can bring right alignment in the relationship to allow for people to do what they're meant to do in in the structure of the relationship. Yep. Yeah.
And I would just like to add why the tabletop exercise you know helps the continuity of operations by ensuring you know that those cyber disruption are treated with the same rigor as any particular natural disaster. But I think more importantly, why does it matter for municipalities? You know, with regards to the tabletop exercise, I think embedding that tabletop exercise into that MCOP life cycle makes the cyber security more of a living breathing operational aspect and not just hey, let me check the box type of compliance, right? So, I think that tabletop exercise becomes kind of like that validation engine of that life cycle. So it's almost like a pressure test for each phase.
It tries to identify those different blind spots and drives that continuous service improvement, you know, making that whole process very sustainable, you know, and operational viable for municipality as it actually moves forward. And again, that's what we did in the city of Aurora, right? I mean, everything we're talking about is is practical and it's real, right? What we've heard today makes one thing clear. Resilience doesn't come from tools or technology alone.
It comes from trust, alignment, and operational maturity. The MCOP model and a regional SOC utility aren't just technical frameworks. They represent a new way for leaders to partner, plan, and protect continuously. And as both of our guests shared, it's the trust between provider and municipality that allows cyber security to evolve from a control mindset into a collaborative one. Cyrus, Michael, thank you both for your time and for the work that you're doing to strengthen cyber security resilience and ultimately safeguarding the communities we all depend on.
Yeah, thank you Tracy. Thank you for for having us and we we look forward to uh conversations in the future. Thank you both. Thank you. I'm Tracy Francis, your host.
Thank you again for joining us today on the Cyber Resilience Report. In the spirit of cyber security awareness month, remember that staying secure is no longer about reacting to threats. It's about building operations that never stop. Across the cyber resilience report series, from vulnerability to resilience to the CBS 60-minute brief, one truth stands out. The MCOP model extended through the regional SOC utility transforms cyber security from an IT expense into a mission-critical capability.
If you miss those episodes, no problem. You can listen or watch anytime at data-defenders.com/podcasts or wherever you get your podcasts. To explore deeper, download the companion resources mentioned throughout this episode and engage at your own pace with our AI enabled expert powered by Google NotebookLM, an intelligent companion that summarizes, explains, and responds with actual insights rooted in verified Data Defenders content. Until next time, protect and secure what matters.
Key takeaways
- In a regional SOC, a threat identified at one city can immediately strengthen the defenses of every neighboring community — something siloed MSSP point solutions cannot do.
- Costs are weighted by population, budget, infrastructure size and number of endpoints, so larger cities can carry most of the cost while smaller villages pay a proportional share.
- The cybersecurity lifecycle has three parts: governance, process and procedure, and technical infrastructure management. Buying point solutions that aren’t tied to governance and process leaves an organization out of balance and still vulnerable.
- Aurora made its incident response plan part of the city’s continuity of operations plan, and its city ordinance treats a cyber incident with the same urgency as a flood or tornado.
- Tabletop exercises pressure-test each phase of the lifecycle and expose blind spots, which keeps cybersecurity an ongoing operation rather than a compliance checkbox.