What is Security operations centre (SOC)?
The team, processes and technology responsible for monitoring an organisation’s environment, detecting security incidents and coordinating the response.
How it works
A SOC can be in-house, outsourced or a mix. Its core job is continuous: collect security telemetry, triage alerts, investigate suspicious activity and escalate or contain incidents.
Building a 24/7 in-house SOC typically needs several analysts to cover shifts, plus detection engineering, tooling and management. That is why many mid-sized organisations use an external SOC through an MDR service.
Key points
- Runs continuously, usually 24/7/365
- Combines analysts, playbooks and tooling such as SIEM and XDR
- Measured on time to detect and time to respond
- Can be internal, outsourced or hybrid
Common questions
How many people does a 24/7 SOC need?
Covering every hour of the year with at least one analyst usually takes five or more people once leave and training are included.
What is a virtual SOC?
An outsourced SOC delivered remotely by a provider, typically as part of an MDR service.
Talk to someone who does this every day
Questions about SOC? Our team will give you a straight answer.