Skip to content
Cybersecurity

SOC

SOC (Security Operations Center) is a specialized unit responsible for continuous monitoring, detection, analysis, and response to cybersecurity incidents within an organization.

What is SOC?

TL;DR — what is a SOC and how it works

A SOC (Security Operations Center) is a centralized cybersecurity unit that monitors, detects, and responds to incidents 24/7 across an organization’s IT/OT environment. A SOC combines people (L1/L2/L3 analysts, threat hunters, IR specialists), processes (playbooks, MTTD/MTTR KPIs, NIS2/DORA compliance) and technology (SIEM, SOAR, EDR/XDR, threat intel).

  • Models: in-house SOC (your own team), Managed SOC / MSSP (full outsource), Hybrid / Co-managed SOC, Virtual SOC (vSOC remote), SOC-as-a-Service.
  • 2026 KPIs: MTTD <5 min top-tier, MTTR <30 min for P1 incidents, dwell time global median 6 days (Mandiant M-Trends 2024), false positive rate <5%, MITRE ATT&CK coverage 60-80%.
  • Regulatory drivers: NIS2 Art. 21 (EU-wide cybersecurity baseline, essential and important entities), DORA Art. 17 (EU financial sector, in force since 17 January 2025), NIST CSF 2.0 Detect + Respond functions, ISO 27001:2022 Annex A.5.25 Incident Management, US FISMA / FedRAMP for federal contractors.
  • Stack: SIEM (Splunk, Sentinel, Elastic, Wazuh, QRadar) + SOAR (Splunk SOAR, Tines, XSOAR) + EDR/XDR (CrowdStrike, SentinelOne, Defender, Cortex) + NDR (Vectra, Darktrace) + TIP (MISP) + UEBA (Exabeam, Securonix).

Definition

SOC — SOC (Security Operations Center) is a specialized unit responsible for continuous monitoring, detection, analysis, and response to cybersecurity incidents within an organization.

What is a SOC — formal definition and history

A SOC (Security Operations Center) is a centralized organizational function delivering continuous security monitoring — collecting telemetry from the entire IT/OT environment, correlating events, detecting incidents, performing triage, investigation, and response according to documented procedures and SLAs. A SOC is the operational arm of the security program (the CISO sets strategy, the SOC executes it 24/7) and is primarily responsible for the Detect and Respond functions in the NIST Cybersecurity Framework 2.0.

The history of the SOC concept unfolds in four phases:

  • Phase 1 (1980s-1990s) — first NORAD-style command centers in the US military (Cheyenne Mountain, DEFCON levels), later adopted by DoD and intelligence agencies. Commercial SOCs emerged in large banks (Citibank, JP Morgan) as fraud-detection centers.
  • Phase 2 (2000s-2010s) — the SIEM era — with the development of ArcSight (HP), QRadar (IBM), Splunk (2003), and RSA enVision, commercial SIEM appeared as the correlation platform. The first MSSPs (Managed Security Service Providers) emerged: Symantec MSS, IBM ISS, Dell SecureWorks, Verizon Cybertrust. The SOC became a market product.
  • Phase 3 (2010s-2020s) — XDR and cloud — EDR appeared (Carbon Black, CrowdStrike, SentinelOne), later XDR consolidating endpoint + network + email. Microsoft Azure Sentinel (2019) introduced cloud-native SIEM with no servers to maintain. MITRE ATT&CK became the lingua franca of detection.
  • Phase 4 (2020-2026) — AI-augmented SOC — generative AI (Microsoft Security Copilot 2023, Google Gemini for Security 2024, CrowdStrike Charlotte AI) entered triage, analytical assistance, and runbook automation. Detection-as-Code (Sigma rules, KQL in git with tests) became the standard for mature SOCs. Gartner predicts that by 2027, 60% of MSSPs will use XDR as their base platform (vs <30% in 2024).

SOC vs NOC (a critical distinction often confused in smaller organizations):

DimensionSOCNOC
GoalSecurity (CIA Triad)Availability and performance (uptime, SLA)
Operational question”Is someone trying to attack us?""Are the systems running?”
KPIsMTTD, MTTR detection, dwell time, FPRUptime 99.9%+, outage MTTR, latency p95/p99
ToolsSIEM, SOAR, EDR/XDR, NDR, TIP, UEBANagios, Zabbix, PRTG, Datadog, SolarWinds, NetFlow
SkillsSecurity analysts (CySA+, GCIA, OSCP, CISSP)Sysadmins, network engineers (CCNA/CCNP, RHCE)
Anomaly responseInvestigation (is this an attack?)Restoration (bring the service back)
OutsourcingMSSP, MDRNOCaaS, MSP

SOC architecture — People, Process, Technology

A mature SOC rests on three pillars (the People-Process-Technology model), none of which can exist without the others. Mixing the proportions — especially over-investing in technology without hiring people or writing procedures — is the most common cause of failed SOC implementations.

People — SOC team structure

The traditional three-tier model still dominates, though in 2025-2026 it is being partly replaced by a role-based model (fusion teams):

  • L1 analyst (Tier 1, triage analyst) — first line, ~60-70% of team workload. Alert triage (true/false positive), escalation to L2, initial logging in case management. Targets: ~150-300 alerts per shift, classification in <15 minutes. Requirements: 1-3 years of experience, CompTIA Security+, CySA+, ISC2 CC.
  • L2 analyst (Tier 2, investigation analyst) — deep investigation of escalated alerts, reactive threat hunting, coordination with IT on containment. Writes IR reports. Requirements: 3-5 years, GCIA, GCIH, GMON, BTL1/BTL2 (Blue Team Level).
  • L3 analyst (Tier 3, threat hunter / IR specialist) — proactive threat hunting (hypothesis-driven queries), incident response on P1, contact with law enforcement (national CERT, sector CSIRTs), forensics. Requirements: 5+ years, GCFA, GREM, OSCP, CISSP, SANS GIAC.
  • Detection Engineer — writes and maintains detection rules (Sigma, KQL, SPL, YARA-L), introduces Detection-as-Code with git and tests, maps detections to MITRE ATT&CK. In 2026 this is the key role distinguishing a mature SOC from an “alert factory”.
  • Threat Intelligence Analyst — aggregates IOCs from TIPs, OSINT, dark-web monitoring, maps current actor TTPs to the client environment. Requirements: GCTI, CTIA, experience with MISP / Recorded Future.
  • SOC Manager — runs shifts, KPIs, SLAs, capacity planning, recruiting, escalation to CISO. Often holds an MBA plus CISSP/CISM.
  • IR Coordinator / IR Lead — runs major incidents (P1, breaches), coordinates with legal, PR, executive board, regulators (data-protection authorities, financial supervisors, national CERTs).

2026 staffing reality: a full 24/7 in-house SOC requires a minimum of 8-12 FTE (3 shifts × 2-3 people + manager + detection engineer + threat intel + IR; plus buffer for vacation, sickness, training). L1-L2 turnover reaches 30-40% per year in mature labor markets — this is the main reason mid-market companies choose MSSPs instead of in-house.

Process — playbooks, runbooks, frameworks

A SOC without documented processes is a chaotic group of firefighters — resilience grows in steps with every playbook written:

  • NIST CSF 2.0 (February 2024) — five core functions plus the new Govern: Govern (program governance, added in v2.0), Identify (asset inventory, risk), Protect (preventive controls), Detect (continuous monitoring, alerting), Respond (containment, IR), Recover (BCP, lessons learned). A SOC owns mainly Detect and Respond, but integrates with the others.
  • NIST SP 800-61 Rev 2 — Computer Security Incident Handling Guide — the foundational IR lifecycle document: Preparation → Detection & Analysis → Containment, Eradication & Recovery → Post-Incident Activity. Every SOC should have a playbook per incident category (ransomware, BEC, malware, lateral movement, data exfiltration, DDoS, insider threat).
  • MITRE ATT&CK — taxonomy of TTPs (Tactics, Techniques, Procedures) with 14 tactics from Initial Access to Impact. Detection rules should be mapped to ATT&CK techniques (e.g. T1059 Command and Scripting Interpreter, T1486 Data Encrypted for Impact). Coverage matrix (which techniques are covered) is the key maturity metric.
  • Per-category playbooks: ransomware playbook (isolation → variant identification → backup verification → law enforcement → comms), BEC playbook (wire-transfer block → finance team alert → email-header forensics), APT playbook (extended dwell, scope assessment, multi-domain investigation).
  • KPI dashboard — MTTD, MTTR, dwell time, FPR, coverage rate, alert volume, investigation rate. Measured weekly, reported monthly to CISO/board.
  • Tabletop exercises — quarterly tabletops (e.g. “ransomware hits on Friday 17:00, payment requested in 6h”, “insider exfiltrates 5 GB to personal Dropbox”). DORA Art. 25 explicitly requires resilience testing for financial entities.
  • Compliance mapping — every playbook should map to specific requirements (ISO 27001 Annex A.5.25, NIS2 Art. 21(2)(b), DORA Art. 17, GDPR Art. 33-34 breach notification).

Technology — the 2026 SOC stack

LayerTool class2026 market leadersFunction
Log aggregation + correlationSIEMSplunk Enterprise Security, Microsoft Sentinel, Elastic Security, Wazuh (OSS), IBM QRadar, Sumo Logic, ChronicleLog collection, correlation, alert generation, dashboards, compliance reports
Automation + orchestrationSOARSplunk SOAR (Phantom), Microsoft Sentinel Logic Apps, Palo Alto Cortex XSOAR, Tines, Torq, SwimlanePlaybook automation, API integration, ticket creation, response actions
Endpoint detectionEDR / XDRCrowdStrike Falcon, SentinelOne Singularity, Microsoft Defender for Endpoint, Palo Alto Cortex XDR, Trend Micro Vision OneMalware detection, lateral movement, behavioral analysis, response (isolate, kill process)
Network detectionNDRVectra AI, Darktrace, ExtraHop, Corelight (open Zeek), Cisco StealthwatchEast-west traffic analysis, ML anomaly detection, encrypted traffic analysis
Threat intelligenceTIPMISP (open-source standard), ThreatConnect, Anomali, Recorded Future, Mandiant AdvantageIOC aggregation, TTP mapping, intel feeds (commercial + community + ISAC)
Behavior analyticsUEBAExabeam, Securonix, Microsoft Sentinel UEBA, Splunk UBAInsider threat detection, account compromise, user behavior anomalies
Identity threatsITDRCrowdStrike Falcon Identity, Microsoft Defender for Identity, Semperis, QuestIdentity-first SOC — Kerberoasting, Golden Ticket, DCSync, Pass-the-Hash detection
Case managementSOC platformTheHive + Cortex (OSS), ServiceNow SIR, Jira Service Management SecurityIncident tracking, collaboration, evidence chain, post-mortem
Vulnerability mgmtVM platformTenable Nessus / Tenable.io, Qualys VMDR, Rapid7 InsightVMContinuous vulnerability scanning, prioritization (EPSS, CISA KEV)
DeceptionHoneypotsThinkst Canary, TrellixDeception (formerly Attivo), TrapXHoneypot tokens, decoy assets, early-stage attacker detection
AI augmentation (2025-2026)GenAI SecOpsMicrosoft Security Copilot, Google Gemini for Security, IBM watsonx for cybersecurity, CrowdStrike Charlotte AI, SentinelOne Purple AITriage acceleration, runbook generation, natural-language queries, summary generation

SOC models — comparison

SOC ModelDeployment timeAnnual cost (typical, USD 2026)Best forTrade-offs
In-house SOC6-12 months$500k-$3M+Banks, critical infra, defense, organizations with proprietary OT/ICSHigh CapEx, analyst retention, hiring is hard in a tight market
Managed SOC (MSSP)4-8 weeks$50k-$400kSMB, mid-market, organizations without a seasoned CISOLess contextual knowledge of the environment, log transfer to vendor
Co-managed SOC8-16 weeks$100k-$500kMid-size organizations with internal IT, gradual maturity ramp-upRequires clear GRC with the vendor, complex contracts
Virtual SOC (vSOC)4-12 weeks$80k-$250kDistributed teams, multi-region organizationsNo physical war room, Slack/Teams coordination can slow IR
SOC-as-a-Service2-6 weeks$30k-$150kStartups, SMB <200 endpoints, compliance-driven organizationsLimited customization, rigid playbooks, less flexible SLA
Hybrid SOC6-12 months$400k-$1MMid/large companies with own L3 + outsourced L1-L2 (follow-the-sun)Integration complexity, two teams to coordinate

Which to choose (practical decision tree):

  • <50 endpoints, no regulation → MDR (Managed Detection and Response) instead of a full SOC, ~$20k-$80k per year.
  • 50-200 endpoints, GDPR + standard industry → SOC-as-a-Service or basic MSSP, $30k-$150k per year.
  • 200-1,000 endpoints, NIS2 important entity + no own CISO → Managed SOC (MSSP), $50k-$300k per year.
  • 200-1,000 endpoints, NIS2 + own CISO and IT → Co-managed SOC, $100k-$500k per year.
  • >1,000 endpoints, NIS2 essential / DORA / critical infrastructure → Hybrid SOC with own L3 or In-house SOC, $400k-$3M+ per year.
  • Bank, insurer, critical-infra operator → In-house SOC plus external threat-intel and IR retainer, $1M-$5M+ per year.

MTTD, MTTR and key SOC metrics

A mature SOC is measured through a KPI set spanning detection, response, quality, and coverage. Without metrics every SOC stagnates — alerts pile up, dwell time grows, and the team burns out from alert fatigue.

  • MTTD (Mean Time To Detect) — from initial compromise (initial access per ATT&CK) to incident confirmation. The 2024 global median for ransomware detection (Mandiant M-Trends): ~24 hours after ransomware deployment. Top-tier SOCs with strong EDR + behavioral analytics achieve <5 minutes for most post-exploitation techniques.
  • MTTR (Mean Time To Respond / containment) — from detection to threat isolation (e.g. disconnecting an endpoint, disabling an AD account, blocking an IP at the firewall). P1 target: <30 minutes. This value dramatically reduces cost-of-breach — IBM Cost of a Data Breach 2024 reports that organizations with MTTR <200 days pay on average $1.02M less per incident than those with MTTR >200 days.
  • MTTR (Mean Time To Recover) — from containment to full eradication and recovery. For a single endpoint = hours. For a full ransomware breach = days to weeks (rebuild, backup restore, post-incident audit).
  • Dwell time — total attacker presence from initial access. The 2024 global median per Mandiant M-Trends: 6 days (a dramatic improvement from 16 days in 2022 and 10 days in 2023). APT and state-sponsored attackers can maintain dwell times measured in months (the longest Mandiant-recorded case: 1,581 days, or roughly 4.3 years).
  • False positive rate (FPR) — percentage of alerts requiring full investigation that turn out to be non-issues. Mature-SOC target: <5%. Weak SOCs have FPR >40%, driving alert fatigue and mass-acknowledge without analysis (the main cause of missed breaches — Target 2013, Equifax 2017 both had alerts ignored).
  • Coverage rate — percentage of the environment actually monitored by SIEM + EDR. Target: >95% endpoints, >90% servers, >80% cloud workloads. Hybrid environments often have shadow IT and mobile/BYOD blind spots — the first 6 months of any new SOC are usually spent onboarding coverage.
  • Alert volume vs investigation rate — a healthy SOC investigates >80% of high-priority alerts (P1/P2). Dropping below 60% is a red flag for alert fatigue.
  • MITRE ATT&CK coverage — percentage of matrix techniques covered by active detection rules. A mature SOC reaches 60-80% coverage of the Enterprise Matrix. Tooling: ATT&CK Navigator + Sigma converters.
  • Detection-as-Code maturity — whether detection rules live in git with tests and code review (a DevSecOps signal).

For a deeper comparison of MTTD vs MTTR with concrete benchmarks and industry examples, see the dedicated article: MTTD vs MTTR — difference and 2026 benchmarks.

SOC use cases by industry

Financial services (banks, insurers, payment institutions):

  • DORA Art. 17 requirement (Digital Operational Resilience Act, in force since 17 January 2025): continuous security monitoring, reporting of major ICT incidents to EBA / national supervisors within 4-72h (escalating window), quarterly resilience testing.
  • National banking regulators (e.g. KNF in Poland, BaFin in Germany, FCA in the UK, OCC and FFIEC in the US) require continuous monitoring of systems supporting financial operations.
  • AML/KYC alerting integrated with the SOC (transaction monitoring + behavioral analytics + sanctions screening).
  • Typical stack: Splunk Enterprise Security + CrowdStrike + MISP + custom Detection-as-Code in git.
  • Dwell time benchmark: top-tier banks <1h for fraud detection.

Healthcare (hospitals, healthcare networks, MedTech):

  • Drivers: GDPR Art. 32 (special data categories = higher duty of care), NIS2 (healthcare explicitly listed as essential entity), HIPAA Security Rule in the US.
  • 2024-2026 wave of ransomware against hospitals (ALPHV/BlackCat, LockBit, Akira) — in the US, Change Healthcare breach 2024 (>$872M total cost); in Europe and elsewhere, repeated hospital outages disrupted surgery scheduling and patient records.
  • A hospital SOC must monitor not only IT but also medical OT (infusion pumps, MRI, PACS imaging).
  • Typical stack: Microsoft Sentinel (Azure-native) + Defender for Endpoint + NDR for OT (Claroty, Medigate).

Energy and critical infrastructure:

  • Drivers: NIS2 (essential entity), IEC 62443 for OT/ICS, national critical-infrastructure regulations.
  • Purdue model segmentation — the SOC must monitor from Level 0 (sensors, actuators) through Level 3 (operations) up to Level 4 (enterprise IT) with different tools per level.
  • 2022-2026 saw growth in state-sponsored APT activity (Volt Typhoon against US critical infrastructure, Sandworm against Ukrainian energy).
  • Typical stack: Splunk + Claroty (OT) or Nozomi Networks + Dragos + dedicated ICS detection rules.

Public administration:

  • Drivers: national cybersecurity acts (NIS2 transposition, US FISMA, UK NCSC guidance), coordination with national CERTs and CSIRTs.
  • 2024-2026 wave of attacks on ministries, agencies, and local government using APT TTPs (TA505, Cozy Bear, Ghostwriter).
  • Limited budgets → typically MSSP plus EU/national grants.
  • Typical stack: Wazuh (OSS) + Elastic Security + community threat intel (MISP via national CERT).

Manufacturing and Industry 4.0:

  • OT/ICS via SIEM integration — Purdue model + Zeek/Suricata + ICS protocol parsers (Modbus, DNP3, OPC UA).
  • Risk: ransomware against production lines (NotPetya 2017 caused ~$10B in global losses — Maersk, Merck, Mondelez), supply-chain attacks (SolarWinds 2020).
  • Typical stack: Microsoft Sentinel + Dragos or Claroty + EDR on engineering endpoints.

E-commerce, SaaS, B2C fintech:

  • Risk: payment fraud, account takeover (ATO), credential stuffing (Have I Been Pwned database 12B+ credentials), API abuse, scraping.
  • Typical stack: Cloudflare + Datadog Cloud SIEM + cloud-native EDR + bot management (Cloudflare Bot Fight, DataDome, PerimeterX).
  • Industry-specific KPIs: fraud rate per transaction, ATO rate, API abuse incidents.
  • AI-augmented SOC — generative AI in triage, summarization, runbook automation. Microsoft Security Copilot, Google Gemini for Security, CrowdStrike Charlotte AI, IBM watsonx for cybersecurity, SentinelOne Purple AI. Triage time reductions of 40-60% per vendor case studies. Caveat: hallucinations + lack of deterministic output → AI as L1 assistance, with human-in-the-loop for final decisions.
  • XDR consolidation — Gartner predicts that by 2027, 60% of MSSPs will use XDR as their base platform (vs <30% in 2024). XDR consolidates EDR + NDR + email + cloud + identity into a single vendor stack.
  • Identity-first SOC (ITDR) — Identity Threat Detection and Response becomes a separate class alongside EDR/NDR. Why: 80% of modern attacks use legitimate credentials (Verizon DBIR 2024), which classic EDR will not catch. Leaders: CrowdStrike Falcon Identity, Microsoft Defender for Identity, Semperis.
  • Cloud-native SOC — Microsoft Sentinel, Chronicle Security Operations (Google), Sumo Logic Cloud SIEM — no servers to maintain, scale to petabytes of logs, pay-per-GB ingestion.
  • Detection-as-Code — detection rules in git, code review, unit tests (e.g. via Atomic Red Team emulation), CI/CD pipelines. Standards: Sigma rules (cross-SIEM), KQL (Sentinel/Defender), YARA-L (Chronicle), SPL (Splunk). Industry data: organizations with mature DaC ship new detections 3x faster than manual workflows.
  • Continuous Threat Exposure Management (CTEM) — Gartner framework linking SOC, vulnerability management, and red teaming. Cycle: Scoping → Discovery → Prioritization → Validation → Mobilization. CTEM replaces once-a-year pentests with continuous validation.
  • MITRE ATT&CK Evaluations — annual EDR/XDR evaluations by MITRE Engenuity. In 2024, emulations covered APT29 (Cozy Bear) and Volt Typhoon. SOCs should use results to choose and maintain their stack.
  • Threat-informed defense — focus on concrete TTPs of current actors relevant to the industry/region, instead of generic “malware detection”. TIP feeds + ISAC participation (financial sector = FS-ISAC).
  • SOAR-driven automation — in 2026, a mature SOC automates 30-60% of common response actions (block IP, isolate endpoint, disable account, reset password). Humans stay for judgment calls (escalation, communications, forensics).

How nFlo helps build and run your SOC

nFlo (200+ clients / 500+ projects / 98% retention / <15 min response time / 90% risk reduction) delivers the full spectrum of SOC services — from MSSP through to design and implementation of in-house SOCs, in a fit-for-purpose model tailored to the organization’s maturity and budget:

  • SOC 24/7 — Managed SOC with a local analyst team, integration with the client’s existing SIEM or deployment of a new one (Splunk, Microsoft Sentinel, Wazuh, Elastic), SLA MTTR <15 min for P1 incidents.
  • Incident Response — support during active incidents (ransomware, BEC, breach), forensics, coordination with national CERT / CSIRT / law enforcement.
  • Security audits — assessment of current SOC maturity against NIST CSF 2.0 and ISO 27001:2022 Annex A.
  • Penetration testing — purple team exercises validating SOC detection coverage.
  • ISO 27001 implementation — ISMS implementation with mapping of control A.5.25 (Incident Management) to SOC processes.

In practice our typical SOC project for a mid-size company (200-500 employees) covers: discovery and baseline assessment (2-3 weeks), SIEM + EDR + SOAR deployment (6-10 weeks), bootstrap detection rules (mapped to MITRE ATT&CK, 80%+ coverage), 24/7 monitoring go-live, and monthly KPI reporting to the CISO/board. Full deployment from kickoff to go-live: 8-16 weeks depending on environment complexity.

Explore our services

Frequently asked questions

+ What is a SOC?

A SOC (Security Operations Center) is a centralized cybersecurity unit that monitors, detects, and responds to incidents 24/7 across an organization's IT/OT environment. A SOC combines three pillars: **people** (L1 triage analysts, L2 deep-investigation analysts, L3 threat hunters + incident responders, SOC manager, threat intel analyst, detection engineer), **processes** (playbooks, runbooks, MTTD/MTTR/dwell-time KPIs, NIST SP 800-61 IR lifecycle, NIST CSF 2.0 functions Govern/Identify/Protect/Detect/Respond/Recover) and **technology** (SIEM as the log-correlation layer, SOAR for response automation, EDR/XDR on endpoints, NDR on network traffic, threat intelligence platforms such as MISP, UEBA for behavioral anomalies). A SOC can be internal (in-house), fully outsourced (Managed SOC / MSSP), hybrid (co-managed) or virtual (vSOC working remotely). In 2026 a SOC is a regulatory requirement for essential and important entities under the EU NIS2 Directive and for the financial sector under DORA.

+ How much does a SOC cost?

Cost depends on deployment model and environment scale. Typical 2026 bands: (1) **SOC-as-a-Service / basic MSSP** — $30k-$150k per year for startups and small companies (50-200 endpoints), usually Microsoft Sentinel + EDR + 8x5 monitoring with 24/7 escalation, (2) **Managed SOC / full MSSP** — $50k-$400k per year for SMB and mid-market (200-1,000 endpoints), full 24/7, dedicated detection engineer, SLA MTTR <30 min for P1 incidents, (3) **Co-managed SOC** — $100k-$500k per year for mid-size organizations with internal IT (client owns the SIEM, vendor delivers analysts + threat intel), (4) **Virtual SOC (vSOC)** — $80k-$250k per year for distributed teams, fully remote analyst pool, no physical war room, (5) **In-house SOC** — $500k-$3M+ per year for banks, critical infrastructure, defense; own 3-shift team (minimum 8-12 FTE to cover 24/7 with vacation and sickness), own SIEM + SOAR + threat intel + tooling licenses. Rule of thumb: a SOC should consume **8-15% of the IT budget** for typical risk profiles and **15-25% of the IT budget** for critical operators (NIS2 essential entities, DORA-regulated banks). For most companies with 100-500 employees, a Managed SOC is cheaper than running an in-house 24/7 team with SIEM/SOAR/EDR licenses.

+ What is the difference between SOC and NOC?

SOC and NOC (Network Operations Center) are two distinct operations centers with different goals and skill sets. **NOC** focuses on **availability and performance** — it monitors whether servers are up, links stable, applications meeting SLA, and reacts to hardware failures, BGP issues, link saturation. NOC watches CPU, RAM, latency, packet loss, dropped frames. **SOC** focuses on **security** — it monitors for unauthorized access attempts, data exfiltration, malware on endpoints, APT-style behavior. SOC watches log anomalies, event correlation, IOCs (Indicators of Compromise), TTPs (MITRE ATT&CK), threat intel feeds. **Typically these are separate teams** because of different skills (NOC = network and system engineers; SOC = security analysts with CySA+, GCIA, OSCP, CISSP), different tools (NOC = Nagios/Zabbix/PRTG/Datadog/SolarWinds; SOC = SIEM/SOAR/EDR/XDR/threat intel) and different KPIs (NOC = uptime 99.9%+, outage MTTR; SOC = detection MTTD/MTTR, dwell time, false positive rate). In smaller organizations the roles may merge into a **NOC/SOC fusion center**, but in organizations >500 employees they are usually separate structures coordinated at the CIO/CISO level.

+ In-house SOC or MSSP — which is better?

There is no universal answer — the choice depends on **security maturity**, **company size**, **regulatory requirements**, and **labor-market availability** of analysts. **In-house SOC** wins when: (1) you are a bank, insurer, critical-infrastructure operator or other entity with critical regulatory exposure (DORA Art. 17, NIS2 essential entity, US FISMA High), (2) your environment has highly specific business context (proprietary OT/ICS in manufacturing, custom SCADA, legacy mainframe) that an MSSP will not know, (3) you have a budget >$2M per year and can sustain a team of 8-12 with competitive salaries (L1-L2 analyst turnover reaches 30-40% per year in mature markets), (4) you need full data ownership with no log transfer to a third party. **MSSP / Managed SOC** wins when: (1) you are SMB or mid-market without an experienced CISO and budget for an in-house team, (2) you need 24/7 coverage "starting tomorrow" — MSSPs onboard in 4-8 weeks vs 6-12 months for an in-house team, (3) you want **collective intelligence** from hundreds of other clients (MSSPs see attacks against the whole sector and recognize new TTPs much faster), (4) your requirements fluctuate — it is easier to scale an MSSP contract than to hire/fire analysts. **Co-managed SOC** is the middle ground for organizations of 200-1,000 employees with internal IT but no budget for full in-house — the client runs the SIEM and keeps contextual knowledge, the vendor delivers L2/L3 analysts and threat intel. Real-world distribution in 2026: roughly 70% of mid-market companies choose MSSP or co-managed, around 30% keep in-house (mostly financial services, energy, telco).

+ What metrics does a SOC track?

A mature SOC is measured by a set of KPIs spanning detection, response, quality, and coverage. **MTTD (Mean Time To Detect)** — average time from initial compromise to alert generation and incident confirmation by an analyst; top-tier target <5 minutes, a good SOC <1 hour, weak SOCs may have MTTD measured in days. **MTTR (Mean Time To Respond)** — average time from detection to containment (isolating the threat, e.g. disconnecting an infected endpoint); target <30 minutes for P1 (critical) incidents, <4 hours for P2 (high). **MTTR (Mean Time To Recover)** — average time to full eradication and operations restoration; may be hours (ransomware on a single endpoint) or days (full environment rebuild after an APT). **Dwell time** — total attacker presence in the environment from initial access to detection; global 2024 median per Mandiant M-Trends is **6 days** (a dramatic improvement from 10 days in 2023), but APT and ransomware attacks with living-off-the-land elements can have dwell times measured in months. **False positive rate** — percentage of alerts that turn out to be irrelevant after investigation; target <5% for a mature SOC; weak SOCs may see FPR >40%, driving alert fatigue. **Coverage rate** — percentage of the environment (endpoints, servers, cloud workloads, OT/ICS) actually monitored by SIEM/EDR; target >95%. **Alert volume vs investigation rate** — how many alerts per day vs how many were investigated; a healthy SOC investigates ~80%+ of high-priority alerts. **MITRE ATT&CK coverage** — percentage of matrix techniques covered by active detection rules; a mature SOC reaches 60-80% coverage. **Detection-as-Code maturity** — whether detection rules are versioned in git, have tests and code review (a DevSecOps signal in 2025-2026).

+ What technologies does a SOC use?

A mature SOC stack in 2026 includes: (1) **SIEM (Security Information and Event Management)** — central log correlation platform; market: **Splunk Enterprise Security** (Gartner MQ leader 2024), **Microsoft Sentinel** (cloud-native, Azure), **Elastic Security**, **Wazuh** (open-source), **IBM QRadar**, **Sumo Logic Cloud SIEM**, **Chronicle Security Operations** (Google), (2) **SOAR (Security Orchestration, Automation and Response)** — IR playbook automation; **Splunk SOAR** (formerly Phantom), **Microsoft Sentinel Logic Apps**, **Palo Alto Cortex XSOAR**, **Tines**, **Torq**, **Swimlane**, (3) **EDR/XDR (Endpoint/Extended Detection and Response)** — endpoint detection plus cross-domain correlation; **CrowdStrike Falcon** (XDR leader), **SentinelOne Singularity**, **Microsoft Defender for Endpoint**, **Palo Alto Cortex XDR**, **Trend Micro Vision One**, (4) **NDR (Network Detection and Response)** — ML-based network traffic analysis; **Vectra AI**, **Darktrace**, **ExtraHop**, **Corelight** (open Zeek), (5) **TIP (Threat Intelligence Platform)** — IOC and TTP aggregation; **MISP** (open-source industry standard), **ThreatConnect**, **Anomali**, **Recorded Future**, (6) **UEBA (User and Entity Behavior Analytics)** — behavioral anomaly detection; **Exabeam**, **Securonix**, **Microsoft Sentinel UEBA**, (7) **Case management** — incident tracking; **TheHive + Cortex** (open-source), **ServiceNow SIR**, **Jira Service Management**, (8) **Vulnerability management** — Tenable Nessus, Qualys VMDR, Rapid7 InsightVM, (9) **Deception** — honeypots and decoys; Thinkst Canary, Attivo (TrellixDeception), (10) **AI-augmented SOC tools (2025-2026)** — Microsoft Security Copilot, Google Gemini for Security, IBM watsonx for cybersecurity, CrowdStrike Charlotte AI; these reduce triage time by 40-60% and help L1 analysts investigate without escalating to L3.

+ Does my company need a SOC?

You need a SOC (in-house, MSSP, or co-managed) if you meet at least one of these criteria: (1) **Regulatory** — you are an essential or important entity under the EU **NIS2 Directive** (energy, transport, banking, healthcare, digital infrastructure, public administration, managed ICT providers), a financial-sector entity under **DORA Art. 17** (banks, insurers, payment institutions), a subject under your national cybersecurity framework, or you process sensitive data under **GDPR Art. 32** at a scale that requires continuous monitoring, (2) **Risk-based** — you process customer financial data (PCI DSS), health records (HIPAA, GDPR special categories), high-value intellectual property, or classified data, (3) **Scale-based** — you have >200 endpoints, >50 business applications, a hybrid on-prem + multi-cloud environment, OT/ICS, distributed offices, (4) **Geopolitical** — you are an APT target (strategic significance for the state, defense, energy, telco), you have already had an incident or near-miss, leadership demands security visibility, (5) **Client-driven** — your enterprise clients require a 24/7 SOC as part of due diligence (typical in B2B procurement, SIG questionnaires, ISO 27001 Annex A.5.25 Information Security Incident Management audits). **You do not need a full SOC** if you are very small (<50 employees, <50 endpoints, no critical data) — then a managed EDR (MDR) plus an email security gateway plus a good IT outsourcer with on-demand incident response is sufficient. The threshold at which MDR stops being enough and you need a real SOC is typically 100-200 endpoints OR any regulatory requirement.

Tags:

SOC security-operations-center siem soar edr xdr mssp incident-response nis2 dora

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist