Security operationsSecurity Operations CentreSecurity Operations Center

SOC (Security Operations Centre)

A SOC is the team, process and tooling responsible for monitoring, triaging and responding to security events for an organisation.

Updated 2 Sept 2026

In more detail

A SOC exists to shorten the time between something happening and someone doing the right thing about it. In practice that means an alert pipeline fed by a SIEM and EDR, documented triage playbooks, tiered analysts or a flatter on-call rotation, and defined escalation into incident response. SOCs may be in-house, outsourced to a managed provider, or a hybrid where a provider handles overnight coverage.

Why SOC (Security Operations Centre) matters

Detection tooling produces far more signals than any organisation can chase. The SOC is the function that decides which ones matter, and its quality is measured in dwell time and mean time to respond rather than alert volume. For anyone entering security, SOC analyst is still the most common first role because it exposes you to the whole estate.

How it works

Telemetry from endpoints, identity providers, network devices and cloud platforms lands in a SIEM. Detection rules raise alerts; an analyst validates each one against a playbook, gathers context, and either closes it as benign or escalates it as an incident with containment actions such as isolating a host or disabling an account. Findings feed back into rule tuning.

Examples

  • A tier-1 analyst triaging an impossible-travel sign-in alert and disabling the account pending verification.
  • An escalation from EDR ransomware-behaviour detection to a full incident with host isolation.
  • A weekly detection-tuning review that suppresses a noisy rule generating false positives from a backup agent.

How it is detected or measured

SOC effectiveness is assessed with metrics such as mean time to detect, mean time to respond, escalation accuracy, and coverage of the MITRE ATT&CK techniques relevant to the organisation.

Where this matters

  • SOC Analyst

    What a SOC analyst does hour to hour, the skills that get you hired, and the realistic route from tier 1 to detection engineering.

  • Security Analyst

    A broader remit than the SOC: risk, controls, vulnerabilities and awareness. What the title really covers, and how to read the job advert.

  • How to Start a Cybersecurity Career

    The sequence that keeps working: fundamentals, one specialism, demonstrable work, then applications aimed at roles that actually hire juniors.

Sources

Related terms