SOC
SOC (Security Operations Center) is a specialized unit responsible for continuous monitoring, detection, analysis, and response to cybersecurity incidents within an organization.
What is SOC?
TL;DR — what is a SOC and how it works
A SOC (Security Operations Center) is a centralized cybersecurity unit that monitors, detects, and responds to incidents 24/7 across an organization’s IT/OT environment. A SOC combines people (L1/L2/L3 analysts, threat hunters, IR specialists), processes (playbooks, MTTD/MTTR KPIs, NIS2/DORA compliance) and technology (SIEM, SOAR, EDR/XDR, threat intel).
- Models: in-house SOC (your own team), Managed SOC / MSSP (full outsource), Hybrid / Co-managed SOC, Virtual SOC (vSOC remote), SOC-as-a-Service.
- 2026 KPIs: MTTD <5 min top-tier, MTTR <30 min for P1 incidents, dwell time global median 6 days (Mandiant M-Trends 2024), false positive rate <5%, MITRE ATT&CK coverage 60-80%.
- Regulatory drivers: NIS2 Art. 21 (EU-wide cybersecurity baseline, essential and important entities), DORA Art. 17 (EU financial sector, in force since 17 January 2025), NIST CSF 2.0 Detect + Respond functions, ISO 27001:2022 Annex A.5.25 Incident Management, US FISMA / FedRAMP for federal contractors.
- Stack: SIEM (Splunk, Sentinel, Elastic, Wazuh, QRadar) + SOAR (Splunk SOAR, Tines, XSOAR) + EDR/XDR (CrowdStrike, SentinelOne, Defender, Cortex) + NDR (Vectra, Darktrace) + TIP (MISP) + UEBA (Exabeam, Securonix).
Definition
SOC — SOC (Security Operations Center) is a specialized unit responsible for continuous monitoring, detection, analysis, and response to cybersecurity incidents within an organization.
What is a SOC — formal definition and history
A SOC (Security Operations Center) is a centralized organizational function delivering continuous security monitoring — collecting telemetry from the entire IT/OT environment, correlating events, detecting incidents, performing triage, investigation, and response according to documented procedures and SLAs. A SOC is the operational arm of the security program (the CISO sets strategy, the SOC executes it 24/7) and is primarily responsible for the Detect and Respond functions in the NIST Cybersecurity Framework 2.0.
The history of the SOC concept unfolds in four phases:
- Phase 1 (1980s-1990s) — first NORAD-style command centers in the US military (Cheyenne Mountain, DEFCON levels), later adopted by DoD and intelligence agencies. Commercial SOCs emerged in large banks (Citibank, JP Morgan) as fraud-detection centers.
- Phase 2 (2000s-2010s) — the SIEM era — with the development of ArcSight (HP), QRadar (IBM), Splunk (2003), and RSA enVision, commercial SIEM appeared as the correlation platform. The first MSSPs (Managed Security Service Providers) emerged: Symantec MSS, IBM ISS, Dell SecureWorks, Verizon Cybertrust. The SOC became a market product.
- Phase 3 (2010s-2020s) — XDR and cloud — EDR appeared (Carbon Black, CrowdStrike, SentinelOne), later XDR consolidating endpoint + network + email. Microsoft Azure Sentinel (2019) introduced cloud-native SIEM with no servers to maintain. MITRE ATT&CK became the lingua franca of detection.
- Phase 4 (2020-2026) — AI-augmented SOC — generative AI (Microsoft Security Copilot 2023, Google Gemini for Security 2024, CrowdStrike Charlotte AI) entered triage, analytical assistance, and runbook automation. Detection-as-Code (Sigma rules, KQL in git with tests) became the standard for mature SOCs. Gartner predicts that by 2027, 60% of MSSPs will use XDR as their base platform (vs <30% in 2024).
SOC vs NOC (a critical distinction often confused in smaller organizations):
| Dimension | SOC | NOC |
|---|---|---|
| Goal | Security (CIA Triad) | Availability and performance (uptime, SLA) |
| Operational question | ”Is someone trying to attack us?" | "Are the systems running?” |
| KPIs | MTTD, MTTR detection, dwell time, FPR | Uptime 99.9%+, outage MTTR, latency p95/p99 |
| Tools | SIEM, SOAR, EDR/XDR, NDR, TIP, UEBA | Nagios, Zabbix, PRTG, Datadog, SolarWinds, NetFlow |
| Skills | Security analysts (CySA+, GCIA, OSCP, CISSP) | Sysadmins, network engineers (CCNA/CCNP, RHCE) |
| Anomaly response | Investigation (is this an attack?) | Restoration (bring the service back) |
| Outsourcing | MSSP, MDR | NOCaaS, MSP |
SOC architecture — People, Process, Technology
A mature SOC rests on three pillars (the People-Process-Technology model), none of which can exist without the others. Mixing the proportions — especially over-investing in technology without hiring people or writing procedures — is the most common cause of failed SOC implementations.
People — SOC team structure
The traditional three-tier model still dominates, though in 2025-2026 it is being partly replaced by a role-based model (fusion teams):
- L1 analyst (Tier 1, triage analyst) — first line, ~60-70% of team workload. Alert triage (true/false positive), escalation to L2, initial logging in case management. Targets: ~150-300 alerts per shift, classification in <15 minutes. Requirements: 1-3 years of experience, CompTIA Security+, CySA+, ISC2 CC.
- L2 analyst (Tier 2, investigation analyst) — deep investigation of escalated alerts, reactive threat hunting, coordination with IT on containment. Writes IR reports. Requirements: 3-5 years, GCIA, GCIH, GMON, BTL1/BTL2 (Blue Team Level).
- L3 analyst (Tier 3, threat hunter / IR specialist) — proactive threat hunting (hypothesis-driven queries), incident response on P1, contact with law enforcement (national CERT, sector CSIRTs), forensics. Requirements: 5+ years, GCFA, GREM, OSCP, CISSP, SANS GIAC.
- Detection Engineer — writes and maintains detection rules (Sigma, KQL, SPL, YARA-L), introduces Detection-as-Code with git and tests, maps detections to MITRE ATT&CK. In 2026 this is the key role distinguishing a mature SOC from an “alert factory”.
- Threat Intelligence Analyst — aggregates IOCs from TIPs, OSINT, dark-web monitoring, maps current actor TTPs to the client environment. Requirements: GCTI, CTIA, experience with MISP / Recorded Future.
- SOC Manager — runs shifts, KPIs, SLAs, capacity planning, recruiting, escalation to CISO. Often holds an MBA plus CISSP/CISM.
- IR Coordinator / IR Lead — runs major incidents (P1, breaches), coordinates with legal, PR, executive board, regulators (data-protection authorities, financial supervisors, national CERTs).
2026 staffing reality: a full 24/7 in-house SOC requires a minimum of 8-12 FTE (3 shifts × 2-3 people + manager + detection engineer + threat intel + IR; plus buffer for vacation, sickness, training). L1-L2 turnover reaches 30-40% per year in mature labor markets — this is the main reason mid-market companies choose MSSPs instead of in-house.
Process — playbooks, runbooks, frameworks
A SOC without documented processes is a chaotic group of firefighters — resilience grows in steps with every playbook written:
- NIST CSF 2.0 (February 2024) — five core functions plus the new Govern: Govern (program governance, added in v2.0), Identify (asset inventory, risk), Protect (preventive controls), Detect (continuous monitoring, alerting), Respond (containment, IR), Recover (BCP, lessons learned). A SOC owns mainly Detect and Respond, but integrates with the others.
- NIST SP 800-61 Rev 2 — Computer Security Incident Handling Guide — the foundational IR lifecycle document: Preparation → Detection & Analysis → Containment, Eradication & Recovery → Post-Incident Activity. Every SOC should have a playbook per incident category (ransomware, BEC, malware, lateral movement, data exfiltration, DDoS, insider threat).
- MITRE ATT&CK — taxonomy of TTPs (Tactics, Techniques, Procedures) with 14 tactics from Initial Access to Impact. Detection rules should be mapped to ATT&CK techniques (e.g. T1059 Command and Scripting Interpreter, T1486 Data Encrypted for Impact). Coverage matrix (which techniques are covered) is the key maturity metric.
- Per-category playbooks: ransomware playbook (isolation → variant identification → backup verification → law enforcement → comms), BEC playbook (wire-transfer block → finance team alert → email-header forensics), APT playbook (extended dwell, scope assessment, multi-domain investigation).
- KPI dashboard — MTTD, MTTR, dwell time, FPR, coverage rate, alert volume, investigation rate. Measured weekly, reported monthly to CISO/board.
- Tabletop exercises — quarterly tabletops (e.g. “ransomware hits on Friday 17:00, payment requested in 6h”, “insider exfiltrates 5 GB to personal Dropbox”). DORA Art. 25 explicitly requires resilience testing for financial entities.
- Compliance mapping — every playbook should map to specific requirements (ISO 27001 Annex A.5.25, NIS2 Art. 21(2)(b), DORA Art. 17, GDPR Art. 33-34 breach notification).
Technology — the 2026 SOC stack
| Layer | Tool class | 2026 market leaders | Function |
|---|---|---|---|
| Log aggregation + correlation | SIEM | Splunk Enterprise Security, Microsoft Sentinel, Elastic Security, Wazuh (OSS), IBM QRadar, Sumo Logic, Chronicle | Log collection, correlation, alert generation, dashboards, compliance reports |
| Automation + orchestration | SOAR | Splunk SOAR (Phantom), Microsoft Sentinel Logic Apps, Palo Alto Cortex XSOAR, Tines, Torq, Swimlane | Playbook automation, API integration, ticket creation, response actions |
| Endpoint detection | EDR / XDR | CrowdStrike Falcon, SentinelOne Singularity, Microsoft Defender for Endpoint, Palo Alto Cortex XDR, Trend Micro Vision One | Malware detection, lateral movement, behavioral analysis, response (isolate, kill process) |
| Network detection | NDR | Vectra AI, Darktrace, ExtraHop, Corelight (open Zeek), Cisco Stealthwatch | East-west traffic analysis, ML anomaly detection, encrypted traffic analysis |
| Threat intelligence | TIP | MISP (open-source standard), ThreatConnect, Anomali, Recorded Future, Mandiant Advantage | IOC aggregation, TTP mapping, intel feeds (commercial + community + ISAC) |
| Behavior analytics | UEBA | Exabeam, Securonix, Microsoft Sentinel UEBA, Splunk UBA | Insider threat detection, account compromise, user behavior anomalies |
| Identity threats | ITDR | CrowdStrike Falcon Identity, Microsoft Defender for Identity, Semperis, Quest | Identity-first SOC — Kerberoasting, Golden Ticket, DCSync, Pass-the-Hash detection |
| Case management | SOC platform | TheHive + Cortex (OSS), ServiceNow SIR, Jira Service Management Security | Incident tracking, collaboration, evidence chain, post-mortem |
| Vulnerability mgmt | VM platform | Tenable Nessus / Tenable.io, Qualys VMDR, Rapid7 InsightVM | Continuous vulnerability scanning, prioritization (EPSS, CISA KEV) |
| Deception | Honeypots | Thinkst Canary, TrellixDeception (formerly Attivo), TrapX | Honeypot tokens, decoy assets, early-stage attacker detection |
| AI augmentation (2025-2026) | GenAI SecOps | Microsoft Security Copilot, Google Gemini for Security, IBM watsonx for cybersecurity, CrowdStrike Charlotte AI, SentinelOne Purple AI | Triage acceleration, runbook generation, natural-language queries, summary generation |
SOC models — comparison
| SOC Model | Deployment time | Annual cost (typical, USD 2026) | Best for | Trade-offs |
|---|---|---|---|---|
| In-house SOC | 6-12 months | $500k-$3M+ | Banks, critical infra, defense, organizations with proprietary OT/ICS | High CapEx, analyst retention, hiring is hard in a tight market |
| Managed SOC (MSSP) | 4-8 weeks | $50k-$400k | SMB, mid-market, organizations without a seasoned CISO | Less contextual knowledge of the environment, log transfer to vendor |
| Co-managed SOC | 8-16 weeks | $100k-$500k | Mid-size organizations with internal IT, gradual maturity ramp-up | Requires clear GRC with the vendor, complex contracts |
| Virtual SOC (vSOC) | 4-12 weeks | $80k-$250k | Distributed teams, multi-region organizations | No physical war room, Slack/Teams coordination can slow IR |
| SOC-as-a-Service | 2-6 weeks | $30k-$150k | Startups, SMB <200 endpoints, compliance-driven organizations | Limited customization, rigid playbooks, less flexible SLA |
| Hybrid SOC | 6-12 months | $400k-$1M | Mid/large companies with own L3 + outsourced L1-L2 (follow-the-sun) | Integration complexity, two teams to coordinate |
Which to choose (practical decision tree):
- <50 endpoints, no regulation → MDR (Managed Detection and Response) instead of a full SOC, ~$20k-$80k per year.
- 50-200 endpoints, GDPR + standard industry → SOC-as-a-Service or basic MSSP, $30k-$150k per year.
- 200-1,000 endpoints, NIS2 important entity + no own CISO → Managed SOC (MSSP), $50k-$300k per year.
- 200-1,000 endpoints, NIS2 + own CISO and IT → Co-managed SOC, $100k-$500k per year.
- >1,000 endpoints, NIS2 essential / DORA / critical infrastructure → Hybrid SOC with own L3 or In-house SOC, $400k-$3M+ per year.
- Bank, insurer, critical-infra operator → In-house SOC plus external threat-intel and IR retainer, $1M-$5M+ per year.
MTTD, MTTR and key SOC metrics
A mature SOC is measured through a KPI set spanning detection, response, quality, and coverage. Without metrics every SOC stagnates — alerts pile up, dwell time grows, and the team burns out from alert fatigue.
- MTTD (Mean Time To Detect) — from initial compromise (initial access per ATT&CK) to incident confirmation. The 2024 global median for ransomware detection (Mandiant M-Trends): ~24 hours after ransomware deployment. Top-tier SOCs with strong EDR + behavioral analytics achieve <5 minutes for most post-exploitation techniques.
- MTTR (Mean Time To Respond / containment) — from detection to threat isolation (e.g. disconnecting an endpoint, disabling an AD account, blocking an IP at the firewall). P1 target: <30 minutes. This value dramatically reduces cost-of-breach — IBM Cost of a Data Breach 2024 reports that organizations with MTTR <200 days pay on average $1.02M less per incident than those with MTTR >200 days.
- MTTR (Mean Time To Recover) — from containment to full eradication and recovery. For a single endpoint = hours. For a full ransomware breach = days to weeks (rebuild, backup restore, post-incident audit).
- Dwell time — total attacker presence from initial access. The 2024 global median per Mandiant M-Trends: 6 days (a dramatic improvement from 16 days in 2022 and 10 days in 2023). APT and state-sponsored attackers can maintain dwell times measured in months (the longest Mandiant-recorded case: 1,581 days, or roughly 4.3 years).
- False positive rate (FPR) — percentage of alerts requiring full investigation that turn out to be non-issues. Mature-SOC target: <5%. Weak SOCs have FPR >40%, driving alert fatigue and mass-acknowledge without analysis (the main cause of missed breaches — Target 2013, Equifax 2017 both had alerts ignored).
- Coverage rate — percentage of the environment actually monitored by SIEM + EDR. Target: >95% endpoints, >90% servers, >80% cloud workloads. Hybrid environments often have shadow IT and mobile/BYOD blind spots — the first 6 months of any new SOC are usually spent onboarding coverage.
- Alert volume vs investigation rate — a healthy SOC investigates >80% of high-priority alerts (P1/P2). Dropping below 60% is a red flag for alert fatigue.
- MITRE ATT&CK coverage — percentage of matrix techniques covered by active detection rules. A mature SOC reaches 60-80% coverage of the Enterprise Matrix. Tooling: ATT&CK Navigator + Sigma converters.
- Detection-as-Code maturity — whether detection rules live in git with tests and code review (a DevSecOps signal).
For a deeper comparison of MTTD vs MTTR with concrete benchmarks and industry examples, see the dedicated article: MTTD vs MTTR — difference and 2026 benchmarks.
SOC use cases by industry
Financial services (banks, insurers, payment institutions):
- DORA Art. 17 requirement (Digital Operational Resilience Act, in force since 17 January 2025): continuous security monitoring, reporting of major ICT incidents to EBA / national supervisors within 4-72h (escalating window), quarterly resilience testing.
- National banking regulators (e.g. KNF in Poland, BaFin in Germany, FCA in the UK, OCC and FFIEC in the US) require continuous monitoring of systems supporting financial operations.
- AML/KYC alerting integrated with the SOC (transaction monitoring + behavioral analytics + sanctions screening).
- Typical stack: Splunk Enterprise Security + CrowdStrike + MISP + custom Detection-as-Code in git.
- Dwell time benchmark: top-tier banks <1h for fraud detection.
Healthcare (hospitals, healthcare networks, MedTech):
- Drivers: GDPR Art. 32 (special data categories = higher duty of care), NIS2 (healthcare explicitly listed as essential entity), HIPAA Security Rule in the US.
- 2024-2026 wave of ransomware against hospitals (ALPHV/BlackCat, LockBit, Akira) — in the US, Change Healthcare breach 2024 (>$872M total cost); in Europe and elsewhere, repeated hospital outages disrupted surgery scheduling and patient records.
- A hospital SOC must monitor not only IT but also medical OT (infusion pumps, MRI, PACS imaging).
- Typical stack: Microsoft Sentinel (Azure-native) + Defender for Endpoint + NDR for OT (Claroty, Medigate).
Energy and critical infrastructure:
- Drivers: NIS2 (essential entity), IEC 62443 for OT/ICS, national critical-infrastructure regulations.
- Purdue model segmentation — the SOC must monitor from Level 0 (sensors, actuators) through Level 3 (operations) up to Level 4 (enterprise IT) with different tools per level.
- 2022-2026 saw growth in state-sponsored APT activity (Volt Typhoon against US critical infrastructure, Sandworm against Ukrainian energy).
- Typical stack: Splunk + Claroty (OT) or Nozomi Networks + Dragos + dedicated ICS detection rules.
Public administration:
- Drivers: national cybersecurity acts (NIS2 transposition, US FISMA, UK NCSC guidance), coordination with national CERTs and CSIRTs.
- 2024-2026 wave of attacks on ministries, agencies, and local government using APT TTPs (TA505, Cozy Bear, Ghostwriter).
- Limited budgets → typically MSSP plus EU/national grants.
- Typical stack: Wazuh (OSS) + Elastic Security + community threat intel (MISP via national CERT).
Manufacturing and Industry 4.0:
- OT/ICS via SIEM integration — Purdue model + Zeek/Suricata + ICS protocol parsers (Modbus, DNP3, OPC UA).
- Risk: ransomware against production lines (NotPetya 2017 caused ~$10B in global losses — Maersk, Merck, Mondelez), supply-chain attacks (SolarWinds 2020).
- Typical stack: Microsoft Sentinel + Dragos or Claroty + EDR on engineering endpoints.
E-commerce, SaaS, B2C fintech:
- Risk: payment fraud, account takeover (ATO), credential stuffing (Have I Been Pwned database 12B+ credentials), API abuse, scraping.
- Typical stack: Cloudflare + Datadog Cloud SIEM + cloud-native EDR + bot management (Cloudflare Bot Fight, DataDome, PerimeterX).
- Industry-specific KPIs: fraud rate per transaction, ATO rate, API abuse incidents.
2026 SOC trends
- AI-augmented SOC — generative AI in triage, summarization, runbook automation. Microsoft Security Copilot, Google Gemini for Security, CrowdStrike Charlotte AI, IBM watsonx for cybersecurity, SentinelOne Purple AI. Triage time reductions of 40-60% per vendor case studies. Caveat: hallucinations + lack of deterministic output → AI as L1 assistance, with human-in-the-loop for final decisions.
- XDR consolidation — Gartner predicts that by 2027, 60% of MSSPs will use XDR as their base platform (vs <30% in 2024). XDR consolidates EDR + NDR + email + cloud + identity into a single vendor stack.
- Identity-first SOC (ITDR) — Identity Threat Detection and Response becomes a separate class alongside EDR/NDR. Why: 80% of modern attacks use legitimate credentials (Verizon DBIR 2024), which classic EDR will not catch. Leaders: CrowdStrike Falcon Identity, Microsoft Defender for Identity, Semperis.
- Cloud-native SOC — Microsoft Sentinel, Chronicle Security Operations (Google), Sumo Logic Cloud SIEM — no servers to maintain, scale to petabytes of logs, pay-per-GB ingestion.
- Detection-as-Code — detection rules in git, code review, unit tests (e.g. via Atomic Red Team emulation), CI/CD pipelines. Standards: Sigma rules (cross-SIEM), KQL (Sentinel/Defender), YARA-L (Chronicle), SPL (Splunk). Industry data: organizations with mature DaC ship new detections 3x faster than manual workflows.
- Continuous Threat Exposure Management (CTEM) — Gartner framework linking SOC, vulnerability management, and red teaming. Cycle: Scoping → Discovery → Prioritization → Validation → Mobilization. CTEM replaces once-a-year pentests with continuous validation.
- MITRE ATT&CK Evaluations — annual EDR/XDR evaluations by MITRE Engenuity. In 2024, emulations covered APT29 (Cozy Bear) and Volt Typhoon. SOCs should use results to choose and maintain their stack.
- Threat-informed defense — focus on concrete TTPs of current actors relevant to the industry/region, instead of generic “malware detection”. TIP feeds + ISAC participation (financial sector = FS-ISAC).
- SOAR-driven automation — in 2026, a mature SOC automates 30-60% of common response actions (block IP, isolate endpoint, disable account, reset password). Humans stay for judgment calls (escalation, communications, forensics).
How nFlo helps build and run your SOC
nFlo (200+ clients / 500+ projects / 98% retention / <15 min response time / 90% risk reduction) delivers the full spectrum of SOC services — from MSSP through to design and implementation of in-house SOCs, in a fit-for-purpose model tailored to the organization’s maturity and budget:
- SOC 24/7 — Managed SOC with a local analyst team, integration with the client’s existing SIEM or deployment of a new one (Splunk, Microsoft Sentinel, Wazuh, Elastic), SLA MTTR <15 min for P1 incidents.
- Incident Response — support during active incidents (ransomware, BEC, breach), forensics, coordination with national CERT / CSIRT / law enforcement.
- Security audits — assessment of current SOC maturity against NIST CSF 2.0 and ISO 27001:2022 Annex A.
- Penetration testing — purple team exercises validating SOC detection coverage.
- ISO 27001 implementation — ISMS implementation with mapping of control A.5.25 (Incident Management) to SOC processes.
In practice our typical SOC project for a mid-size company (200-500 employees) covers: discovery and baseline assessment (2-3 weeks), SIEM + EDR + SOAR deployment (6-10 weeks), bootstrap detection rules (mapped to MITRE ATT&CK, 80%+ coverage), 24/7 monitoring go-live, and monthly KPI reporting to the CISO/board. Full deployment from kickoff to go-live: 8-16 weeks depending on environment complexity.
Related terms
- SIEM (Security Information and Event Management) — the log-correlation layer in the SOC stack, the foundation of detection
- SOAR (Security Orchestration, Automation and Response) — IR playbook automation in the SOC
- EDR (Endpoint Detection and Response) — endpoint detection, critical telemetry for the SOC
- XDR (Extended Detection and Response) — EDR evolution consolidating cross-domain detection
- NDR (Network Detection and Response) — ML-based network traffic analysis, complementing EDR
- Threat Hunting — proactive threat hunting, the core function of L3 analysts
- Incident Response — incident-response playbook, a core SOC process
- MTTD vs MTTR — key SOC metrics with 2026 industry benchmarks
- APT (Advanced Persistent Threat) — the threat class that L3 and threat hunters hunt most actively
- Security controls — the broader category of controls that a SOC operationally exercises
Explore our services
Frequently asked questions
+ What is a SOC?
A SOC (Security Operations Center) is a centralized cybersecurity unit that monitors, detects, and responds to incidents 24/7 across an organization's IT/OT environment. A SOC combines three pillars: **people** (L1 triage analysts, L2 deep-investigation analysts, L3 threat hunters + incident responders, SOC manager, threat intel analyst, detection engineer), **processes** (playbooks, runbooks, MTTD/MTTR/dwell-time KPIs, NIST SP 800-61 IR lifecycle, NIST CSF 2.0 functions Govern/Identify/Protect/Detect/Respond/Recover) and **technology** (SIEM as the log-correlation layer, SOAR for response automation, EDR/XDR on endpoints, NDR on network traffic, threat intelligence platforms such as MISP, UEBA for behavioral anomalies). A SOC can be internal (in-house), fully outsourced (Managed SOC / MSSP), hybrid (co-managed) or virtual (vSOC working remotely). In 2026 a SOC is a regulatory requirement for essential and important entities under the EU NIS2 Directive and for the financial sector under DORA.
+ How much does a SOC cost?
Cost depends on deployment model and environment scale. Typical 2026 bands: (1) **SOC-as-a-Service / basic MSSP** — $30k-$150k per year for startups and small companies (50-200 endpoints), usually Microsoft Sentinel + EDR + 8x5 monitoring with 24/7 escalation, (2) **Managed SOC / full MSSP** — $50k-$400k per year for SMB and mid-market (200-1,000 endpoints), full 24/7, dedicated detection engineer, SLA MTTR <30 min for P1 incidents, (3) **Co-managed SOC** — $100k-$500k per year for mid-size organizations with internal IT (client owns the SIEM, vendor delivers analysts + threat intel), (4) **Virtual SOC (vSOC)** — $80k-$250k per year for distributed teams, fully remote analyst pool, no physical war room, (5) **In-house SOC** — $500k-$3M+ per year for banks, critical infrastructure, defense; own 3-shift team (minimum 8-12 FTE to cover 24/7 with vacation and sickness), own SIEM + SOAR + threat intel + tooling licenses. Rule of thumb: a SOC should consume **8-15% of the IT budget** for typical risk profiles and **15-25% of the IT budget** for critical operators (NIS2 essential entities, DORA-regulated banks). For most companies with 100-500 employees, a Managed SOC is cheaper than running an in-house 24/7 team with SIEM/SOAR/EDR licenses.
+ What is the difference between SOC and NOC?
SOC and NOC (Network Operations Center) are two distinct operations centers with different goals and skill sets. **NOC** focuses on **availability and performance** — it monitors whether servers are up, links stable, applications meeting SLA, and reacts to hardware failures, BGP issues, link saturation. NOC watches CPU, RAM, latency, packet loss, dropped frames. **SOC** focuses on **security** — it monitors for unauthorized access attempts, data exfiltration, malware on endpoints, APT-style behavior. SOC watches log anomalies, event correlation, IOCs (Indicators of Compromise), TTPs (MITRE ATT&CK), threat intel feeds. **Typically these are separate teams** because of different skills (NOC = network and system engineers; SOC = security analysts with CySA+, GCIA, OSCP, CISSP), different tools (NOC = Nagios/Zabbix/PRTG/Datadog/SolarWinds; SOC = SIEM/SOAR/EDR/XDR/threat intel) and different KPIs (NOC = uptime 99.9%+, outage MTTR; SOC = detection MTTD/MTTR, dwell time, false positive rate). In smaller organizations the roles may merge into a **NOC/SOC fusion center**, but in organizations >500 employees they are usually separate structures coordinated at the CIO/CISO level.
+ In-house SOC or MSSP — which is better?
There is no universal answer — the choice depends on **security maturity**, **company size**, **regulatory requirements**, and **labor-market availability** of analysts. **In-house SOC** wins when: (1) you are a bank, insurer, critical-infrastructure operator or other entity with critical regulatory exposure (DORA Art. 17, NIS2 essential entity, US FISMA High), (2) your environment has highly specific business context (proprietary OT/ICS in manufacturing, custom SCADA, legacy mainframe) that an MSSP will not know, (3) you have a budget >$2M per year and can sustain a team of 8-12 with competitive salaries (L1-L2 analyst turnover reaches 30-40% per year in mature markets), (4) you need full data ownership with no log transfer to a third party. **MSSP / Managed SOC** wins when: (1) you are SMB or mid-market without an experienced CISO and budget for an in-house team, (2) you need 24/7 coverage "starting tomorrow" — MSSPs onboard in 4-8 weeks vs 6-12 months for an in-house team, (3) you want **collective intelligence** from hundreds of other clients (MSSPs see attacks against the whole sector and recognize new TTPs much faster), (4) your requirements fluctuate — it is easier to scale an MSSP contract than to hire/fire analysts. **Co-managed SOC** is the middle ground for organizations of 200-1,000 employees with internal IT but no budget for full in-house — the client runs the SIEM and keeps contextual knowledge, the vendor delivers L2/L3 analysts and threat intel. Real-world distribution in 2026: roughly 70% of mid-market companies choose MSSP or co-managed, around 30% keep in-house (mostly financial services, energy, telco).
+ What metrics does a SOC track?
A mature SOC is measured by a set of KPIs spanning detection, response, quality, and coverage. **MTTD (Mean Time To Detect)** — average time from initial compromise to alert generation and incident confirmation by an analyst; top-tier target <5 minutes, a good SOC <1 hour, weak SOCs may have MTTD measured in days. **MTTR (Mean Time To Respond)** — average time from detection to containment (isolating the threat, e.g. disconnecting an infected endpoint); target <30 minutes for P1 (critical) incidents, <4 hours for P2 (high). **MTTR (Mean Time To Recover)** — average time to full eradication and operations restoration; may be hours (ransomware on a single endpoint) or days (full environment rebuild after an APT). **Dwell time** — total attacker presence in the environment from initial access to detection; global 2024 median per Mandiant M-Trends is **6 days** (a dramatic improvement from 10 days in 2023), but APT and ransomware attacks with living-off-the-land elements can have dwell times measured in months. **False positive rate** — percentage of alerts that turn out to be irrelevant after investigation; target <5% for a mature SOC; weak SOCs may see FPR >40%, driving alert fatigue. **Coverage rate** — percentage of the environment (endpoints, servers, cloud workloads, OT/ICS) actually monitored by SIEM/EDR; target >95%. **Alert volume vs investigation rate** — how many alerts per day vs how many were investigated; a healthy SOC investigates ~80%+ of high-priority alerts. **MITRE ATT&CK coverage** — percentage of matrix techniques covered by active detection rules; a mature SOC reaches 60-80% coverage. **Detection-as-Code maturity** — whether detection rules are versioned in git, have tests and code review (a DevSecOps signal in 2025-2026).
+ What technologies does a SOC use?
A mature SOC stack in 2026 includes: (1) **SIEM (Security Information and Event Management)** — central log correlation platform; market: **Splunk Enterprise Security** (Gartner MQ leader 2024), **Microsoft Sentinel** (cloud-native, Azure), **Elastic Security**, **Wazuh** (open-source), **IBM QRadar**, **Sumo Logic Cloud SIEM**, **Chronicle Security Operations** (Google), (2) **SOAR (Security Orchestration, Automation and Response)** — IR playbook automation; **Splunk SOAR** (formerly Phantom), **Microsoft Sentinel Logic Apps**, **Palo Alto Cortex XSOAR**, **Tines**, **Torq**, **Swimlane**, (3) **EDR/XDR (Endpoint/Extended Detection and Response)** — endpoint detection plus cross-domain correlation; **CrowdStrike Falcon** (XDR leader), **SentinelOne Singularity**, **Microsoft Defender for Endpoint**, **Palo Alto Cortex XDR**, **Trend Micro Vision One**, (4) **NDR (Network Detection and Response)** — ML-based network traffic analysis; **Vectra AI**, **Darktrace**, **ExtraHop**, **Corelight** (open Zeek), (5) **TIP (Threat Intelligence Platform)** — IOC and TTP aggregation; **MISP** (open-source industry standard), **ThreatConnect**, **Anomali**, **Recorded Future**, (6) **UEBA (User and Entity Behavior Analytics)** — behavioral anomaly detection; **Exabeam**, **Securonix**, **Microsoft Sentinel UEBA**, (7) **Case management** — incident tracking; **TheHive + Cortex** (open-source), **ServiceNow SIR**, **Jira Service Management**, (8) **Vulnerability management** — Tenable Nessus, Qualys VMDR, Rapid7 InsightVM, (9) **Deception** — honeypots and decoys; Thinkst Canary, Attivo (TrellixDeception), (10) **AI-augmented SOC tools (2025-2026)** — Microsoft Security Copilot, Google Gemini for Security, IBM watsonx for cybersecurity, CrowdStrike Charlotte AI; these reduce triage time by 40-60% and help L1 analysts investigate without escalating to L3.
+ Does my company need a SOC?
You need a SOC (in-house, MSSP, or co-managed) if you meet at least one of these criteria: (1) **Regulatory** — you are an essential or important entity under the EU **NIS2 Directive** (energy, transport, banking, healthcare, digital infrastructure, public administration, managed ICT providers), a financial-sector entity under **DORA Art. 17** (banks, insurers, payment institutions), a subject under your national cybersecurity framework, or you process sensitive data under **GDPR Art. 32** at a scale that requires continuous monitoring, (2) **Risk-based** — you process customer financial data (PCI DSS), health records (HIPAA, GDPR special categories), high-value intellectual property, or classified data, (3) **Scale-based** — you have >200 endpoints, >50 business applications, a hybrid on-prem + multi-cloud environment, OT/ICS, distributed offices, (4) **Geopolitical** — you are an APT target (strategic significance for the state, defense, energy, telco), you have already had an incident or near-miss, leadership demands security visibility, (5) **Client-driven** — your enterprise clients require a 24/7 SOC as part of due diligence (typical in B2B procurement, SIG questionnaires, ISO 27001 Annex A.5.25 Information Security Incident Management audits). **You do not need a full SOC** if you are very small (<50 employees, <50 endpoints, no critical data) — then a managed EDR (MDR) plus an email security gateway plus a good IT outsourcer with on-demand incident response is sufficient. The threshold at which MDR stops being enough and you need a real SOC is typically 100-200 endpoints OR any regulatory requirement.