Skip to content
Cyber Security Firms

What Is a SOC? Inside a Security Operations Center

A security operations center is the team that answers the alert, not the software that raised it. The distinction decides almost everything about what one costs and whether yours works.

Intermediate14 min readUpdated
What Is a SOC? Inside a Security Operations Center

At 3:14 in the morning an alert fires because an account that has never signed in outside Ohio just authenticated from a hosting provider in another country. Software can raise that alert. Software cannot decide whether the person is on vacation with a VPN, whether to lock the account of a hospital's on-call radiologist, or whether the same address has touched four other accounts this week. A security operations center is the standing arrangement of people, shifts and procedures that answers those questions before the attacker gets to the second hour.

What Is a SOC?

A security operations center is the centralized function that watches an organization's identities, endpoints, servers, networks, applications and cloud services for signs of attack, and that acts when it finds one. The classic picture is a room with a video wall. The room is optional. What is not optional is that somebody is on duty, that they can see the whole estate, and that they have the authority to disable an account at four in the morning without waiting for a meeting.

The acronym is worth pinning down because it collides. SOC as a security operations center is a team. SOC 2 is an audit report about a service provider's controls, published under a different standard by an accounting body, and the two have nothing to do with each other beyond three letters.

One more distinction that saves confusion: a network operations center watches whether systems are up and fast, while a security operations center watches whether they are being abused. The two often sit near each other and hand work across, because a sudden traffic spike is either a marketing campaign or an attack, and it takes both teams to say which.

What Does a Security Operations Center Do?

Six jobs, and only two of them are the ones people picture.

Continuous monitoring. Collecting telemetry from every system and keeping the coverage honest as the estate changes. A source that stopped reporting is a blind spot nobody declared.

Detection and triage. Deciding which alerts are real and which are the backup job again. This is where most of the hours go and where most SOCs are judged.

Incident response. Containing, eradicating, and getting systems back into service, which is the part the rest of the business notices.

Threat hunting. Looking for the intrusion that produced no alert, on the assumption that the detection rules do not cover everything yet.

Detection engineering. Turning each incident, and each phishing report from a member of staff, into a rule that would have caught it earlier.

Compliance and reporting. Retaining evidence, producing the audit trail, and notifying regulators and customers on the clock the law sets.

NIST rewrote its incident response guidance around this shape. SP 800-61 Revision 3 drops the old standalone lifecycle and recasts incident response as a Cybersecurity Framework 2.0 profile, with the stated aim of helping organizations prepare, reduce the number and impact of incidents, and improve the efficiency of detection, response and recovery. The point of the rewrite is that response is not a separate binder. It is the operational half of the same risk program.

How a SOC Responds to an Incident

The queue is the unit of work. An alert arrives, someone decides in minutes whether it is real, and everything after that is procedure.

One alert, from the queue to a closed case
  1. Attacker signs inA valid password, bought or phished. Nothing is technically broken
  2. Alert firesA rule matches: sign-in from an unfamiliar country, then a new mailbox rule
  3. Tier 1 triageReal or noise, and how urgent. Most alerts are closed here, correctly
  4. Tier 2 investigationPull every session, every device and everything the account touched
  5. ContainmentSessions revoked, account disabled, affected hosts isolated from the network
  6. EradicationThe way in is closed: credential retired, exposed service patched, rule deleted
  7. RecoverySystems returned to service with monitoring tightened on them for a while
  8. Post-incident reviewWhat was missed becomes a new detection rule. Skipping this repeats the incident
Steps three and four are what a SOC is actually paid for. Everything from step five on is procedure that can be written down and largely automated.

Federal practice puts the same sequence in writing. CISA's incident and vulnerability response playbooks, published under Executive Order 14028, give agencies a standard set of procedures to identify, coordinate, remediate, recover and track mitigations. The value of a playbook is not that it is clever. It is that at 3:14 in the morning nobody has to invent the next step.

The measurement that matters is how long the attacker had. Two reports on this site sit at opposite ends of it.

Who Works in a SOC?

Roles, not headcount. A ten-person team has all of these functions and four of the people.

  • Tier 1 analysts work the alert queue: triage, enrich, escalate. Highest volume, most turnover, and the tier most affected by automation.
  • Tier 2 analysts and incident responders take the escalations, run the investigation, and make the containment calls.
  • Tier 3, threat hunters and forensic analysts look for what produced no alert, reverse malware samples, and handle evidence that may end up in court.
  • Detection engineers write and tune the rules. In smaller teams this is the tier 2 analyst on a Friday.
  • Security engineers build and maintain the tooling itself, including the log pipeline everything else depends on.
  • The SOC manager owns the rotation, the escalation path and the metrics, and reports upward when something is genuinely bad.

Tier 1 is the usual way into the field, and it is where the certifications hiring managers name do most of their work, because the job is legible enough that a credential plus a home lab can get you an interview.

Types of SOCs

The model is a budget and coverage decision more than a technical one.

ModelWhat it meansWho it suits
In-houseYour staff, your tooling, your rotationLarge organizations that can fund overnight coverage and keep the roles filled
VirtualNo dedicated room or shift; existing staff respond on callSmall teams that accept slower nights in exchange for cost
ManagedA provider monitors and responds under contractMost companies below a few hundred staff
HybridInternal team in business hours, provider overnight and at weekendsMid-sized companies that want ownership without a night shift
GlobalSeveral regional centers following the sun, coordinated centrallyMultinationals, where the handover between centers is the hard part

The honest read on this table is that the second row is where most organizations actually live and few admit it. A virtual SOC is what you have when the answer to "who is watching this weekend" is a phone that may be on silent.

What Is a SIEM vs SOC?

A SIEM is software and a SOC is people. The security information and event management platform collects logs from across the organization, correlates them and raises alerts. The SOC is the team that reads those alerts and decides what they mean.

They need each other in one direction more than the other. A SOC with no central platform is a team switching between a dozen consoles and missing the connection between them. The SIEM the team lives in is what makes one timeline out of many systems. A platform with nobody working its queue, though, is the more expensive mistake, because it produces the paperwork of a security program and none of the effect.

Myth vs reality
What people believe
Buy the platform and the security operations center follows. The tooling is the hard part.
What actually happens
The tooling is the part with a price list. The hard part is a staffed rotation with the authority to act, an escalation path that works at 3 a.m., and someone whose job is tuning the rules. Organizations that buy in that order end up with dashboards nobody opens; the ones that decide who responds first buy less tooling and get more from it.

What Tools Does a SOC Use?

Layers of increasingly refined signal, all of it aimed at putting one decision in front of a person.

The stack a SOC works through
SensorsEDR agents, identity providers, firewalls, DNS, cloud audit trails, email security
Collection and correlationThe SIEM: normalization, correlation rules, behavioral analytics, retention
AutomationSOAR playbooks that enrich the alert and take the first containment action
Case managementThe queue, the ticket, the timeline, the handover between shifts
The analyst's decision
Each layer exists to get one question to a person sooner: is this real, and how bad is it.

Threat intelligence sits alongside all four, telling the team which of the thousand possible things is currently being done to organizations like theirs. Vulnerability data sits there too, and it is the layer most often neglected: IBM's 2026 breach study found more than half of organizations using agents for threat detection and containment while only 18 percent applied them to vulnerability management, which leaves known exposures open while the detection side gets faster.

An empty desk with a single chair and two blank monitors, viewed straight on

SOC vs MSSP vs MDR

Three ways to buy the same outcome, sold as one category and priced very differently.

What you getWhat it does not include
In-house SOCComplete control, your own detection content, immediate business contextNights, weekends and holidays unless you fund three shifts
MSSPManaged security services: device management, log collection, alerting, reportingInvestigation and hands-on response are frequently extra or absent
MDRManaged detection and response: monitoring plus analysts who investigate and containBroad log retention for compliance, unless you pay for the data separately

The question that separates an MSSP from an MDR provider in a sales call is simple: when something is confirmed at two in the morning, do you contain it yourself, or do you send us an email. Get the answer in the contract with a response time attached, because both categories describe themselves the same way in marketing.

What Are the Benefits of a SOC?

The benefit is time. Everything an attacker accomplishes after the first login is a function of how long they get uninterrupted, and a SOC is the only control that shortens that number after prevention has already failed.

Alongside that: an audit trail that exists before you need it, a single team that knows the environment well enough to spot what is abnormal for you specifically, and a documented response that keeps regulatory notification inside its deadline.

The challenges are real and every honest practitioner names the same three. Alert fatigue, where a queue that is mostly noise trains people to close things unread. The staffing market, where the tier 2 analyst you trained is the one a larger company hires. And scope creep, because the threats a SOC watches for keep expanding: the 2026 Verizon Data Breach Investigations Report found breaches involving a third party up 60 percent and now 48 percent of all breaches, which means the queue now includes systems your organization does not own.

Does Your Business Need a SOC?

You need the function. Whether you need to build it is a different question, and for most organizations the answer is no.

How to Build a SOC

Building one is mostly a sequence of decisions about coverage and authority. The tooling is the easy half.

Then rehearse it. A tabletop exercise twice a year finds the gaps that documentation hides, and the most common finding is not technical: it is that nobody knows who declares an incident. If you get there without ever needing the plan, what to do after a data breach is the document you will be glad someone already read.

Key takeaways

  • A SOC is the team and the function that monitors, investigates and responds. The room is optional; the coverage is not.
  • The work is a queue: triage, investigate, contain, eradicate, recover, review. The first two steps are where the skill is.
  • A SIEM is the platform a SOC works inside. Buying the platform without staffing the queue is the standard expensive failure.
  • Most organizations should buy the function rather than build it. Managed detection and response is the usual answer between fifty and five hundred staff.
  • Ask an MSSP or MDR provider what they do at two in the morning when something is confirmed, and get the answer into the contract.
  • Dwell time is the metric. Three days and eight months are both real outcomes from this year's breach reports.
  • Alert fatigue, staff turnover and expanding scope are the three problems every SOC has. Tuning and post-incident review are what keep them survivable.

Common questions

What does SOC stand for?

Security operations center. It describes both the team responsible for monitoring and responding to threats and, where one exists, the facility they work from. Many organizations run one with no dedicated room at all, which is why the function matters more than the location.

What does a security operations center do?

It monitors systems continuously, triages the alerts that monitoring produces, investigates the ones that look real, contains and eradicates confirmed incidents, restores affected systems, and turns what it learned into new detection rules. It also holds the evidence and reporting that regulators and customers ask for afterward.

What is the difference between a SOC and a NOC?

A network operations center watches availability and performance: is the network up, is it fast, why did that link fail. A security operations center watches for abuse: is this login legitimate, is that traffic exfiltration. They overlap because an outage and an attack can look identical at first, and mature organizations have the two teams talk constantly.

What is a SIEM vs SOC?

The SIEM is software that collects and correlates log data and raises alerts. The SOC is the team that works those alerts. One is a purchase, the other is a rotation. A SIEM with nobody reading its output is the most common form of wasted security budget.

Who works in a SOC?

Tiered analysts who triage and investigate, incident responders who contain, threat hunters and forensic specialists who look for what produced no alert, detection engineers who write and tune the rules, security engineers who maintain the tooling, and a manager who owns the rotation and the metrics. In small teams one person holds several of those roles.

What is the difference between a SOC and an MSSP?

A managed security service provider runs security tooling on your behalf: device management, log collection, alerting and reporting. That is a subset of what a SOC does. The gap is investigation and hands-on response, which many MSSP contracts do not include, so an alert arrives in your inbox and the work of deciding what it means is still yours.

What is a SOC vs MDR?

Managed detection and response is a SOC you rent. The provider monitors, investigates and, under most contracts, contains confirmed threats on your systems. The trade is that the detection content and the data retention are theirs, so ask what happens to your logs and your rules if you change providers.

What are the 5 steps of incident response?

There is no single official five, and the number varies by framework. The best-sourced version is CISA's: preparation, detection and analysis, containment, eradication and recovery, and post-incident activity, which is the sequence an incident response plan is written around. NIST's current guidance, SP 800-61 Revision 3, drops the old standalone lifecycle and organizes incident response around the Cybersecurity Framework 2.0 functions instead. The seven steps in the diagram above are what a SOC works shift to shift.

Is SOC 2 the same as a security operations center?

No, and the collision causes real confusion. SOC 2 is an audit report on a service organization's controls over security, availability, confidentiality, processing integrity and privacy, issued under an accounting standard. A security operations center is a team. A company can hold a SOC 2 report and have no SOC, and the reverse is just as common.

Does a small business need a SOC?

It needs the function, not the building. Under about fifty staff, multi-factor authentication, endpoint detection with alerts going somewhere a person reads, tested backups and a written call list cover most of the ground. CISA publishes Logging Made Easy free for organizations of that size. The next step up is a managed service rather than a hire.

What are the benefits of a SOC?

Shorter dwell time, which is the only variable that reliably reduces the damage of an incident once prevention has failed. Alongside that: an audit trail that already exists when a regulator asks, a team that knows what normal looks like in your specific environment, and a response that runs to a plan rather than to whoever happens to be awake.

On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →