We continue to hear reports of cybersecurity incidents that escalate into cyber crises or even communication crises. However, the overall level of cybersecurity maturity among organisations operating in Lithuania is rising. The Cybersecurity Law of the Republic of Lithuania, updated at the end of 2024 in accordance with the EU NIS2 (TIS2) Directive, has played a significant role in this. It not only required certain organisations to implement both organisational and technical measures to strengthen their cyber resilience but also to set higher expectations for their service providers. One of the most debated requirements is cyber incident management, which is often handled by a Security Operations Center (SOC).
Augustinas Daukšas, a cybersecurity consultant at NRD Cyber Security, emphasizes that organisations have many questions regarding the need for and scope of a SOC

“We hear from organisations that have become cybersecurity entities that perhaps the most pressing question is whether a real SOC is necessary. That is, when an organisation not only collects and occasionally reviews log records but also has a dedicated team of L1, L2, and L3 analysts who respond to cybersecurity incidents, vulnerabilities, and threats, investigate them, and mitigate them. It appears that the initial technical requirements set forth in the law regarding these activities are fairly basic, making it possible to meet them immediately. Therefore, simply implementing these requirements should not lead one to expect a SOC team that functions effectively and carries out daily processes in accordance with best practices. The current cybersecurity law mandates that the monitoring of cyber threats and incidents be carried out according to a “check-the-box” approach, and therefore the need for standard and effective SOC processes is not explicitly stated. Currently, this law requires the collection of log records and their review once a month. However, high-quality SOC operations involve continuous and proactive (rather than reactive) monitoring of security events and threats. Consequently, we are hearing from cybersecurity entities that it is unclear what level of monitoring is expected.”
Deividas Stumbras, Director of the IT Department at the National Cyber Security Center (NKSC), emphasizes that the NKSC expects organizations to make informed decisions:
“The law deliberately sets only minimum security requirements: retaining log records for 90 days, reviewing them monthly, conducting vulnerability scans, reporting incidents within 24 or 72 hours, and others. SIEM and incident management systems, as well as detection and analysis solutions, are considered mandatory in all cases, while threat monitoring at the network level is recommended. However, these are only minimum requirements, and the organization must assess the actual need for efforts to enhance cyber resilience on its own, based on the risks it manages. Our expectation, as a regulatory authority, is an effective SOC that does not rely solely on the implementation of minimum technical controls, but helps the organization proactively identify cybersecurity threats, is capable of classifying incidents, and knows when and to whom to report them.”

D. Stumbras states that although the management of cyber incidents has certainly become a “hot topic” in recent years, regulation in Lithuania remains an essential driving force:
“Some organisations classified as cybersecurity entities actually view the updated cybersecurity law as a real step forward, but there is also a significant number that are simply ‘going through the motions.’ How large should the SOC team be, what technologies should be used for threat monitoring and incident management, what should the agreement on internal/external service levels be, or how many different roles should SOC processes and activities encompass—all of this must be assessed and decided by the cybersecurity entity itself.”
Edgaras Baranauskas, Head of Information Security at Energy Cells, agrees that it is not the need to comply with the law, but rather the organisation’s approach—especially that of its leaders—and its assessment of the situation that should be the key factors:
“Attention and investment in cybersecurity should first and foremost be based on the organization’s risks and its level of cybersecurity maturity. It’s not worth waiting to see what the law or a regulator will say. Regulation is an important incentive, but the principles of organizational governance and risk management remain paramount. My experience in the energy sector shows that for organizations that have consistently invested in cybersecurity and achieved a higher level of maturity, preparing for new regulations did not require starting from scratch. When an organisation has a solid foundation, complying with both current and future requirements becomes significantly easier.”

E. Baranauskas asserts that if the state has recognized an organization as a critical entity, it must assume that responsibility and sincerely strengthen its cyber resilience:
“A major advantage of the updated cybersecurity law is that it highlights the importance of third parties (the supply chain) to an organization’s cybersecurity resilience. This creates a snowball effect, where maturity increases not only within regulated organizations but also leads to greater attention being paid to cybersecurity among suppliers. Thus, the law also affects organizations that are not designated as cybersecurity entities.”
If an organisation decides to purchase security incident monitoring and management services from external providers, it must determine the level of service it will receive, the exact value it expects from the provider, the technologies that will be used, and other quality parameters.
A. Daukšas notes that while the concept of SOC services is certainly not new in the Lithuanian market, until now it has mostly been the choice of organizations that have reached a higher level of cybersecurity maturity:
“Over the past few years, the number of organizations purchasing SOC services in Lithuania has definitely increased, and the vast majority of them were doing so for the first time. The number of providers offering SOC services in Lithuania has also grown significantly—a few years ago, only a few major market players offered them, whereas today there are already more than ten providers in the market. However, the growing supply does not necessarily mean that the standard of SOC services will be uniform across the board. In recent years, there have been many interpretations of what constitutes “SOC services.” So if your organization is purchasing SOC services for the first time, we recommend choosing carefully and speaking with organizations that have been “living with” SOC operations for several years. After a few years, you’ll have gained experience and a better understanding of the value provided by SOC services, as well as the technological and procedural nuances, making it much easier to measure and interpret quality metrics for repeat purchases or service renewals.
“Organizations should have a very clear understanding of what a provider is offering and exactly what they will receive—whether it will be just basic monitoring or a full-fledged security team with all essential threat monitoring and incident management roles, as well as comprehensive support in the event of an incident. For now, there are no plans to impose requirements on providers; the market is left to self-regulate, but in the future, a decision may be made to establish a certain threshold for SOC maturity based on SIM3 or another standard.”
E. Baranauskas notes that purchasing SOC services is certainly no easy task:
“There are differences in the tools offered by vendors, the scope of services, and the promises regarding the value that their SOC services will create for the organization. Of course, pricing also varies widely. If an organization lacks the experience or expertise to evaluate vendors and the services they offer, I would strongly recommend speaking with mature organizations that have in-house SOCs or have been using external services for at least a few years. It’s also a good idea to speak with the potential vendor’s current clients. That way, it will be easier to get a general sense of both the services you’ll receive and the kind of partner you’ll be working with.”
Published in Lithuanian, 2026 09 02 at „Verslo žinios“: https://www.vz.lt/technologijos/2026/09/02/kibernetinis-saugumas-lietuvoje-dalis-organizaciju-deda-varneles-kiti-is-tiesu-auga-589468