Skip to main content

GLOSSARY · Security

Security Operations Center

The staffed function — people, process, and tooling — that watches security alerts around the clock, investigates what matters, and takes containment action. It can be your own team, or a provider's.

Detailed definition

A Security Operations Center is not a room with screens on the wall. It is a staffing model. Strip away the furniture and a SOC is three things: someone is watching, that someone knows what normal looks like in your environment, and that someone has the authority to act at 3 AM without waking you up first.

Tools do not make a SOC. EDR, XDR, and SIEM generate the signal a SOC consumes — but a detection platform with nobody reading it is a very expensive logging system.

The headcount math nobody quotes you

This is the part that decides the build-versus-rent question, so it’s worth doing honestly.

Covering 24 hours a day, 365 days a year, takes roughly 4.2 full-time people to fill a single seat once you account for vacation, sick time, training, and turnover. One seat is the bare minimum — a lone analyst per shift with no second opinion and no escalation path. A SOC that can actually investigate rather than just acknowledge alerts wants at least two analysts on shift plus a lead.

Call it five to nine security people, hired in a market where they are scarce and expensive, before you have bought a single tool. That is the number that makes in-house SOCs a decision for organizations with thousands of employees, not thirty.

What a SOC actually does on a normal day

  • Triage — every alert gets classified as benign, suspicious, or active threat by a human, not left in a queue
  • Investigation — building the process tree, the network path, and the account trail behind a suspicious signal
  • Threat hunting — going looking for indicators nobody alerted on, rather than waiting
  • Containment — isolating an endpoint, killing a session, disabling an account while the attack is still in progress
  • Detection engineering — tuning the rules so tomorrow’s version of today’s false positive doesn’t fire
  • Reporting — the evidence trail that satisfies auditors, underwriters, and your own board

In-house, outsourced, or co-managed

Most organizations under about 2,000 employees end up in one of three places: an outsourced SOC delivered as MDR; a co-managed arrangement where the provider’s SOC handles round-the-clock coverage and the internal IT lead keeps context and business judgment in the loop; or — most commonly, and least discussed — no SOC at all, with an MSP operating the security platform properly during working hours.

That third option is a legitimate answer, not a failure to buy the real one. A SOC buys you the overnight hours. If your realistic threat arrives by email on a Tuesday and your prevention layer handles it automatically, the overnight hours may not be what your money should buy first. What is not legitimate is a provider selling the third arrangement in language that implies the first.

Co-management is the underrated option when you already have a capable IT person. A fully managed model that treats you as a passive recipient of notifications wastes the one thing an outside SOC can never have: knowledge of what your business actually does on a Tuesday. The mature versions of this define, in writing, which actions the provider takes on its own authority, which require your sign-off, and which stay yours.

The one question that reveals the most

Before the feature list, ask: what can your SOC do without calling me first?

An analyst who has to reach a customer contact before isolating a compromised laptop is running a notification service, not a response capability — and the difference only becomes visible during an incident, which is the worst possible time to discover it. A real answer names specific actions and who authorizes each one.

The broader set of questions worth putting to any outsourced SOC — how response metrics are defined, how the breach warranty is structured, where the threat intelligence actually comes from — is covered under MDR, since that’s the form most SMBs buy a SOC in. We ask them on our clients’ behalf before putting anyone’s environment behind one; see Security & Compliance for how that fits the rest of the stack.

RELATED TERMS

Need help applying SOC to your business?

Questions about how this applies to your situation? Ask us — first conversation is free, no obligation.