Detection & response

What is Security operations centre (SOC)?

Definition

The team, processes and technology responsible for monitoring an organisation’s environment, detecting security incidents and coordinating the response.

How it works

A SOC can be in-house, outsourced or a mix. Its core job is continuous: collect security telemetry, triage alerts, investigate suspicious activity and escalate or contain incidents.

Building a 24/7 in-house SOC typically needs several analysts to cover shifts, plus detection engineering, tooling and management. That is why many mid-sized organisations use an external SOC through an MDR service.

Key points

  • Runs continuously, usually 24/7/365
  • Combines analysts, playbooks and tooling such as SIEM and XDR
  • Measured on time to detect and time to respond
  • Can be internal, outsourced or hybrid

Common questions

How many people does a 24/7 SOC need?

Covering every hour of the year with at least one analyst usually takes five or more people once leave and training are included.

What is a virtual SOC?

An outsourced SOC delivered remotely by a provider, typically as part of an MDR service.

Talk to someone who does this every day

Questions about SOC? Our team will give you a straight answer.

Contact us