Skip to main content

GLOSSARY · Security

Security Operations Center

The staffed function — people, process, and tooling — that watches security alerts around the clock, investigates what matters, and takes containment action. It can be your own team, or a provider's.

Detailed definition

A Security Operations Center is not a room with screens on the wall. It is a staffing model. Strip away the furniture and a SOC is three things: someone is watching, that someone knows what normal looks like in your environment, and that someone has the authority to act at 3 AM without waking you up first.

Tools do not make a SOC. EDR, XDR, and SIEM generate the signal a SOC consumes — but a detection platform with nobody reading it is a very expensive logging system.

The headcount math nobody quotes you

This is the part that decides the build-versus-rent question, so it’s worth doing honestly.

Covering 24 hours a day, 365 days a year, takes roughly 4.2 full-time people to fill a single seat once you account for vacation, sick time, training, and turnover. One seat is the bare minimum — a lone analyst per shift with no second opinion and no escalation path. A SOC that can actually investigate rather than just acknowledge alerts wants at least two analysts on shift plus a lead.

Call it five to nine security people, hired in a market where they are scarce and expensive, before you have bought a single tool. That is the number that makes in-house SOCs a decision for organizations with thousands of employees, not thirty.

What a SOC actually does on a normal day

  • Triage — every alert gets classified as benign, suspicious, or active threat by a human, not left in a queue
  • Investigation — building the process tree, the network path, and the account trail behind a suspicious signal
  • Threat hunting — going looking for indicators nobody alerted on, rather than waiting
  • Containment — isolating an endpoint, killing a session, disabling an account while the attack is still in progress
  • Detection engineering — tuning the rules so tomorrow’s version of today’s false positive doesn’t fire
  • Reporting — the evidence trail that satisfies auditors, underwriters, and your own board

In-house, outsourced, or co-managed

Most organizations under about 2,000 employees end up in one of three places: an outsourced SOC delivered as MDR; a co-managed arrangement where the provider’s SOC handles round-the-clock coverage and the internal IT lead keeps context and business judgment in the loop; or — most commonly, and least discussed — no SOC at all, with an MSP operating the security platform properly during working hours.

That third option is a legitimate answer, not a failure to buy the real one. A SOC buys you the overnight hours. If your realistic threat arrives by email on a Tuesday and your prevention layer handles it automatically, the overnight hours may not be what your money should buy first. What is not legitimate is a provider selling the third arrangement in language that implies the first.

Co-management is the underrated option when you already have a capable IT person. A fully managed model that treats you as a passive recipient of notifications wastes the one thing an outside SOC can never have: knowledge of what your business actually does on a Tuesday. The mature versions of this define, in writing, which actions the provider takes on its own authority, which require your sign-off, and which stay yours.

The one question that reveals the most

Before the feature list, ask: what can your SOC do without calling me first?

An analyst who has to reach a customer contact before isolating a compromised laptop is running a notification service, not a response capability — and the difference only becomes visible during an incident, which is the worst possible time to discover it. A real answer names specific actions and who authorizes each one.

The broader set of questions worth putting to any outsourced SOC — how response metrics are defined, how the breach warranty is structured, where the threat intelligence actually comes from — is covered under MDR, since that’s the form most SMBs buy a SOC in. We ask them on our clients’ behalf before putting anyone’s environment behind one; see Security & Compliance for how that fits the rest of the stack.

RELATED TERMS

Need help applying SOC to your business?

We've done this kind of work across New York. First conversation is free.