Skip to content
Getting Digital

Security Operations Centre (SOC)

Also: SOC, security operations, blue team, managed detection and response, MDR

A security operations centre is the team, tooling and process that monitors an organisation's systems for security events around the clock, triages alerts, and starts the response to those that are real.

Our take. A security operations centre is a staffing problem disguised as a technology purchase. Tools generate alerts at any hour; people who can tell a real one from noise, at three in the morning, on the third night shift, are scarce and expensive, and most organisations should buy that capacity from a specialist rather than pretend to build it.

The tools produce the alerts; the centre decides what they mean. An analyst on the first tier looks at each alert, checks it against the known false positives, and either closes it, enriches it with context, or escalates it. The second tier investigates the escalations, pulling logs from the SIEM, telemetry from the endpoints and history from the identity provider to decide whether something is really happening and how far it reaches. The third tier hunts: it looks for what the detections missed, writes new ones, and takes the hardest cases. Around them sit the engineers who keep the tooling running and the detections current, and above them sits the incident response process that takes over when a case is confirmed.

  • Tier one: triage. Volume, speed, and a good list of what to ignore. The role with the highest turnover in the industry.
  • Tier two: investigation. Reading logs across sources, forming a hypothesis, confirming or discarding it.
  • Tier three: hunting and detection engineering. Finding what the rules missed and turning it into a rule.
  • Engineering: the SIEM, the endpoint platform, the automation that handles the routine so analysts handle the rest.
  • Management: the metrics, the shift pattern, the escalation to incident response, and the argument for budget.

Around the clock is the expensive part. Covering every hour of the year with at least two people who can do this work needs a team of ten or more, plus the tooling, plus the training, and the alerts do not arrive politely during office hours. Managed detection and response providers sell exactly that coverage, watching many customers' telemetry from one centre, and for most organisations below a few thousand staff the honest comparison is between a provider's shared team and an internal team that will be understaffed at night. The certifications that lead into this work, the vendor-neutral analyst paper and Microsoft's operations exam, both describe the tier-two skills: read the query, say what it returns, decide what it means.

What to keep in house even when you outsource

The provider watches; someone inside has to act. Containment on your systems, the decision to disable an executive's account or take a service offline, the knowledge of which server is the payroll system and which is a test box, and the ownership of the response plan cannot be bought from outside. A managed service with nobody inside who can act on its calls is an expensive way to be told about a breach.

In practice

A company of eight hundred people hires two analysts and calls it a security operations centre. They work office hours, the alerts queue overnight, and a compromise that begins at eleven on a Friday evening is seen at nine on Monday, by which time the attacker has been in the network for fifty-eight hours. The redesign keeps the two analysts as the people who know the environment and can act, contracts a managed detection provider for round-the-clock monitoring with a fifteen-minute escalation to an on-call rota, and writes down exactly what the provider may do alone, such as isolating a workstation, and what needs the internal on-call, such as disabling an account. The next Friday-night compromise is isolated at eleven twenty.

Often confused with

SIEM (Security Information and Event Management)
The SIEM is the tool that gathers logs and raises alerts; the security operations centre is the team that works them. Buying a SIEM without staffing the centre produces an archive of unread alerts.
Incident Response
The centre detects and triages, and often handles early containment. Incident response is the wider process, involving legal, communications and leadership, that takes over once a case is confirmed as an incident.
Intrusion Detection and Prevention (IDS/IPS)
An intrusion detection system is one source of alerts among several the centre watches. The sensor produces; the analysts consume, tune and decide.

Key takeaways

  • Tools raise alerts; tiers of analysts decide what they mean and what to do.
  • Round-the-clock coverage needs ten or more people; most organisations should buy it and keep the acting in house.
  • Whoever watches, someone inside must be able to act on the call at any hour.

Certifications that test this

Vendor exams whose syllabus covers this concept — facts, cost and a preparation path on each page.

More courses from these shelves

A rotating selection from the course directory, drawn from the subcategories where this concept is taught rather than picked for it. Details, price and the provider link are on the course page.

ISO/IEC 42001: Artificial Intelligence Management System

ISO/IEC 42001: Artificial Intelligence Management System is a comprehensive course designed for professionals looking t…

Udemy

C_THR82: SuccessFactors Performance & Goals Implementation

Are you ready to pass the SAP Certified Associate - SAP SuccessFactors Performance and Goals (C_THR82) exam and take yo…

Udemy

Networking Full Course & Network + certification

This Class of Full Networking Fundamentals, will be fully illustrated with video lessons and sample to which it will ma…

Udemy

Python And Django Framework For Beginners Complete Course

Learn Python From Scratch Beginner to Expert Python.Start from the Python basics and go all the way to creating your ow…

Udemy

The Ultimate AWS Networking Training Course: All In One

Unlock the Future of Cloud: Master AWS Networking and Propel Your Career Forward!In a world powered by the cloud, Amazo…

Udemy

Salesforce Certified Data Cloud Consultant Practice Exams

Get certified with Salesforce Data Cloud Consultant certification by practicing actual exam type questions. This Course…

Udemy

FAQ

SOC or managed detection and response?
A security operations centre is the function; managed detection and response is buying that function from a provider who runs one for many customers. The provider watches and escalates; the customer still has to be able to act.
Is tier-one analyst a good entry into security?
It is the commonest entry and a demanding one: high volume, shift work, and a steep learning curve in reading alerts. People who use it to learn the environment and move to investigation within a year or two do well; the role's turnover comes from those who stay in triage.
How many people does a round-the-clock SOC need?
Enough to keep at least two qualified analysts on every shift of every day, allowing for leave, sickness and training, which in practice means ten or more before engineering and management. That figure is why most organisations below a few thousand staff buy the coverage rather than build it.

Sources

The primary text this definition rests on. Read it before you trust ours.

  • MITRE, 11 Strategies of a World-Class Cybersecurity Operations Center (2022)
  • NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide (2012)

Last reviewed 13 September 2026 · Getting Digital