---
title: "What Is a SOC? Security Operations Center | Bytes Unlimited"
description: "A SOC is the staffed function that watches security alerts 24/7 and acts on them. Here"
canonical: https://www.bytesunlimited.com/glossary/soc/
---

![](/images/hero-illustration.svg)

GLOSSARY · Security

# Security Operations Center SOC 

The staffed function — people, process, and tooling — that watches security alerts around the clock, investigates what matters, and takes containment action. It can be your own team, or a provider's.

## Detailed definition

A **Security Operations Center** is not a room with screens on the wall. It is a staffing model. Strip away the furniture and a SOC is three things: someone is watching, that someone knows what normal looks like in your environment, and that someone has the authority to act at 3 AM without waking you up first.

Tools do not make a SOC. [EDR](/glossary/edr/), [XDR](/glossary/xdr/), and [SIEM](/glossary/siem/) generate the signal a SOC consumes — but a detection platform with nobody reading it is a very expensive logging system.

## The headcount math nobody quotes you

This is the part that decides the build-versus-rent question, so it’s worth doing honestly.

Covering 24 hours a day, 365 days a year, takes roughly 4.2 full-time people to fill a single seat once you account for vacation, sick time, training, and turnover. One seat is the bare minimum — a lone analyst per shift with no second opinion and no escalation path. A SOC that can actually investigate rather than just acknowledge alerts wants at least two analysts on shift plus a lead.

Call it five to nine security people, hired in a market where they are scarce and expensive, before you have bought a single tool. That is the number that makes in-house SOCs a decision for organizations with thousands of employees, not thirty.

## What a SOC actually does on a normal day

* **Triage** — every alert gets classified as benign, suspicious, or active threat by a human, not left in a queue
* **Investigation** — building the process tree, the network path, and the account trail behind a suspicious signal
* **Threat hunting** — going looking for indicators nobody alerted on, rather than waiting
* **Containment** — isolating an endpoint, killing a session, disabling an account while the attack is still in progress
* **Detection engineering** — tuning the rules so tomorrow’s version of today’s false positive doesn’t fire
* **Reporting** — the evidence trail that satisfies auditors, underwriters, and your own board

## In-house, outsourced, or co-managed

Most organizations under about 2,000 employees end up in one of three places: an outsourced SOC delivered as [MDR](/glossary/mdr/); a co-managed arrangement where the provider’s SOC handles round-the-clock coverage and the internal IT lead keeps context and business judgment in the loop; or — most commonly, and least discussed — **no SOC at all**, with an MSP operating the security platform properly during working hours.

That third option is a legitimate answer, not a failure to buy the real one. A SOC buys you the overnight hours. If your realistic threat arrives by email on a Tuesday and your prevention layer handles it automatically, the overnight hours may not be what your money should buy first. What is not legitimate is a provider selling the third arrangement in language that implies the first.

Co-management is the underrated option when you already have a capable IT person. A fully managed model that treats you as a passive recipient of notifications wastes the one thing an outside SOC can never have: knowledge of what your business actually does on a Tuesday. The mature versions of this define, in writing, which actions the provider takes on its own authority, which require your sign-off, and which stay yours.

## The one question that reveals the most

Before the feature list, ask: **what can your SOC do without calling me first?**

An analyst who has to reach a customer contact before isolating a compromised laptop is running a notification service, not a response capability — and the difference only becomes visible during an incident, which is the worst possible time to discover it. A real answer names specific actions and who authorizes each one.

The broader set of questions worth putting to any outsourced SOC — how response metrics are defined, how the breach warranty is structured, where the threat intelligence actually comes from — is covered under [MDR](/glossary/mdr/), since that’s the form most SMBs buy a SOC in. We ask them on our clients’ behalf before putting anyone’s environment behind one; see [Security & Compliance](/services/security/) for how that fits the rest of the stack.

HOW WE HELP

## Related Bytes Unlimited services

* [Security & Compliance PCI DSS, HIPAA, and general security posture work. Endpoint protection, MFA, awareness training, audit-ready documentation.](/services/security/)
* [Bitdefender GravityZone Bitdefender GravityZone Cloud MSP Security — endpoint detection and response for SMB fleets, managed centrally.](/services/bitdefender-gravityzone/)

RELATED TERMS

## See also

* [MDR](/glossary/mdr/)
* [SIEM](/glossary/siem/)
* [EDR](/glossary/edr/)
* [XDR](/glossary/xdr/)

AUTHORITATIVE SOURCES

## External references

* [MITRE — 11 Strategies of a World-Class Cybersecurity Operations Center  (opens in new tab)](https://www.mitre.org/news-insights/publication/11-strategies-world-class-cybersecurity-operations-center)
* [NIST SP 800-61 Rev. 2 — Computer Security Incident Handling Guide  (opens in new tab)](https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final)

## Need help applying SOC to your business?

We've done this kind of work across New York. First conversation is free.

[Get In Touch](/contact/) [Back to Glossary](/glossary/)

## Sitemap

- [Site map](https://www.bytesunlimited.com/sitemap.md)
- [llms.txt](https://www.bytesunlimited.com/llms.txt)
- [Canonical URL list](https://www.bytesunlimited.com/sitemap.xml)
