Two ministry systems breached, SOC "blind": why modern monitoring matters

Photo: Qeis Ismail / Unsplash
At Vietnam Security Summit in mid-2026, a national cyber agency representative disclosed two serious data breaches at ministry-level agencies — and the most worrying part: the on-site security monitoring (SOC) did not detect the attacks, while millions of records were compromised.
The lesson: having a SOC doesn't mean seeing
- Modern attacks are designed to evade traditional monitoring.
- "Blindness" is not from lacking tools, but from tools and processes not keeping up with new techniques.
- When undetected, attackers dwell longer — bigger damage.
What it takes not to be blind
- Monitor abnormal behavior, not only known signatures.
- Protect the app and API layer — a large attack surface (see cyber defense).
- Tight identity and device management; least privilege to limit damage.
Tetra
Orca WAAP protects web and APIs; Manta Security manages devices, permissions and access monitoring. To assess your current detection, book a consultation.
Related articles

Securing Dokploy: adding a WAF and IPS on the server itself
A default Dokploy install runs fine but is not safe: Traefik is not a WAF, Docker bypasses UFW, DNS-only domains leak the origin IP. Three gaps and how to close them on your own host.
Read ↗
Vietnam's 2025 Cybersecurity Law: 5-level system classification and what to do
From 1 July 2026, Cybersecurity Law 116/2025 merges two prior laws, codifies "data security" and classifies systems into 5 levels. The new obligations and what to do.
Read ↗
Hansoll hit by ransomware: how manufacturing and FDI firms defend
The ransomware case targeting Hansoll Textile shows manufacturing and FDI firms are also targets. Practical defense lessons for manufacturers.
Read ↗Personal Data Protection checklist
Review your business before the law takes effect on 01/01/2026.