SOC Operations

What is a SOC?

A Security Operations Centre is the team and tooling responsible for monitoring an organisation’s systems, triaging alerts, and responding to security incidents - either in-house or delivered as a managed service.

2 min read

A SOC is the function that watches for attacks and does something when one appears. It is people and process first; the tooling - siem, edr, xdr - exists to serve them.

What the work looks like

The traditional structure is tiered:

Tier 1 triages the alert queue. Most alerts are benign, and the job is deciding quickly which are not. This is where volume lives and where burnout starts.

Tier 2 investigates what Tier 1 escalates: what happened, how far it went, what else the attacker touched.

Tier 3 handles the hardest cases, builds and tunes detections, and does proactive threat-hunting rather than waiting for alerts.

Coverage is the expensive part. Genuine 24/7 requires roughly eight to twelve analysts for continuous shifts with leave and turnover. That headcount is why most organisations under a few hundred people do not run their own.

Alert fatigue is the real failure mode

Under-tuned tooling produces thousands of alerts a day, nearly all false positives. Analysts learn - correctly, from experience - that alerts are usually nothing. The genuine one then arrives into a queue where the default response is to close it.

This is not a discipline problem. It is a design problem. Several major breaches involved a correct alert that fired and was dismissed among the noise. A SOC that cannot tune its detections will eventually miss the alert that mattered, no matter how good its people are.

In-house, managed, or hybrid

In-house gives you context nobody else has - your systems, your normal, your business. Expensive and hard to staff.

Managed (MDR/MSSP) buys coverage immediately at predictable cost. The trade-off is context: an external analyst does not know that the finance team always runs that unusual export on the last day of the month. Expect a tuning period, and judge providers on how they handle escalation, not on dashboards.

Hybrid - outsourced monitoring, internal ownership of response - is where most growing companies land.

Before you buy one

If you have no edr, no MFA, and no central logging, a SOC has nothing useful to watch. Those foundations come first. And a SOC only matters if there is an incident-response plan for what happens after the phone rings.

Next Step

Want this checked on your own systems?

We run the assessments this was written from. Tell us your stack and we will scope it - no commitment.

Mutual NDA before scoping · Reply within 4 business hours