What is a Security Operations Center (SOC)?

9 minute read
Intermediate

A Security Operations Center is the team that monitors, detects, and responds to cybersecurity threats.

What a SOC Actually Does

A SOC performs four core functions: continuous monitoring of security telemetry from across the organization's environment, detection of suspicious activity through correlation of signals from multiple sources, investigation of detected activity to determine whether it represents a genuine threat, and response to confirmed threats through containment, eradication, and recovery actions. These functions operate around the clock — threats do not respect business hours, and a SOC that does not operate 24x7 has detection gaps that adversaries can exploit.

Mature SOCs also perform proactive functions beyond reactive monitoring: threat hunting that searches for adversary activity not detected by automated tools, threat intelligence consumption that informs detection priorities, detection engineering that improves the SOC's ability to identify specific threats, and continuous tuning of detection rules to reduce false positives and improve signal-to-noise ratio. These proactive capabilities distinguish operational SOCs that meaningfully reduce risk from compliance SOCs that exist primarily to satisfy regulatory requirements.

Build vs. Buy: Internal SOC vs. MSSP/MDR

Building an internal SOC requires substantial investment in personnel, tooling, and operational processes. A 24/7 SOC requires at minimum 8-12 analysts to cover all shifts with redundancy, senior threat hunters and detection engineers, a SOC manager, and the supporting tooling (SIEM, EDR, SOAR, threat intelligence, case management) that can easily exceed $1M annually in licensing alone. For most mid-market organizations, the build option is not financially viable; the buy option — engaging an MSSP or MDR provider — delivers SOC capabilities at a fraction of the cost.

Security Operations Center Metrics

Mean Time to Detect (MTTD) measures how long between an attacker gaining access and the SOC generating an alert. Mean Time to Respond (MTTR) measures how long between an alert and a containment action. Mean Time to Remediate measures how long until affected systems are fully restored. These three metrics provide the most operationally meaningful picture of SOC capability.

Alert volume and false positive rate are operational health metrics. A SOC overwhelmed with alerts has an effective MTTD that is measured in days rather than minutes, because genuine alerts are buried in false positive noise. Mature SOCs track false positive rates by detection rule and systematically tune rules to maintain signal quality as the environment and threat landscape evolve.

SOC as a Service for PE Portfolio Companies

For PE-backed companies, the SOC question is almost always a build-versus-buy decision in favor of managed services. The math is straightforward: an MDR provider delivers 24/7 security operations with a team of experienced analysts for $100,000-$500,000 annually, depending on organization size and scope. Building equivalent capability internally costs $2-4 million annually. The economics favor MDR for all but the largest portfolio companies.

The critical question is not whether to use an MDR provider but which MDR provider, and whether their coverage actually addresses the threats facing the organization. MDR providers vary significantly in analyst quality, detection content depth, response capability, and scope. Validating MDR provider capability — not just reviewing their marketing materials — is the work that most organizations skip.

Frequently Asked Questions

What does a SOC actually do?

A SOC performs four core functions: continuous monitoring of security telemetry from across the organization's environment, detection of suspicious activity through correlation of signals from multiple sources, investigation of detected activity to determine whether it represents a genuine threat, and response to confirmed threats through containment, eradication, and recovery actions. Mature SOCs also conduct proactive threat hunting, threat intelligence consumption, detection engineering, and continuous tuning of detection rules.

Should we build a SOC or use MSSP/MDR?

For most mid-market organizations between 50 and 500 employees, building an internal SOC is not economically rational. Building a genuine 24/7 SOC requires 8-12 analysts plus senior threat hunters, a SOC manager, and supporting tooling totaling $1.5M-$3M annually. Mature MDR providers deliver equivalent capability for $100K-$500K through shared service economics. Internal SOCs make sense for larger organizations (1,000+ employees), highly regulated industries with data sovereignty requirements, or organizations with unique threat profiles that justify dedicated analyst attention.

How many analysts does a 24/7 SOC need?

A genuine 24/7/365 SOC requires roughly 8 analysts at minimum to cover three shifts daily with vacation, sick time, and training accounted for. Mature SOCs add tier 2 and tier 3 analysts for complex investigations and senior incident response, plus a SOC manager for coordination. Total staffing for a small enterprise SOC is typically 10-15 people. The math of three shifts plus coverage redundancy is what makes internal SOC builds expensive even before considering technology costs.

What is the difference between SOC and NOC?

A Network Operations Center (NOC) focuses on network availability, performance, and infrastructure health — monitoring for outages, performance degradation, and capacity issues. A Security Operations Center focuses on security events, threats, and incidents. The skill sets differ: NOC analysts focus on network and infrastructure operations; SOC analysts focus on security threat detection and response. Some organizations combine the functions into a single SOC+NOC team; most maintain them as separate functions with different reporting lines and skill profiles.

What is a tier 1, 2, and 3 SOC analyst?

Tier 1 analysts perform initial alert triage and basic investigation — they review automated alerts, determine whether they represent genuine threats, and escalate confirmed incidents. Tier 2 analysts conduct detailed investigation of escalated incidents, perform forensic analysis, and coordinate initial containment actions. Tier 3 analysts handle the most complex cases including advanced threat actor investigation, custom detection engineering, threat hunting, and incident response leadership. The tier model reflects increasing technical depth and incident complexity rather than strict separation of duties.

What metrics measure SOC effectiveness?

Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), and Mean Time to Remediate are the operational metrics that determine breach cost. Industry MTTD averages around 200 days; mature SOCs achieve MTTD measured in hours to days for high-severity threats. Alert volume and false positive rate measure operational health — a SOC overwhelmed with false positives has effective MTTD measured in days because genuine alerts are buried in noise. Coverage metrics (percentage of environment under monitoring, percentage of high-priority detection rules deployed) measure scope rather than effectiveness.

What is the difference between SOC-as-a-Service and MDR?SOC-as-a-Service and MDR overlap significantly in delivery model. SOC-as-a-Service typically emphasizes broader monitoring and compliance reporting; MDR typically emphasizes active response and threat hunting. The capability differential between specific providers is often more meaningful than the marketing terminology. Both deliver outsourced 24/7 security operations through shared service economics. Selection should focus on actual capabilities — detection content, response authority, integration depth, analyst quality — rather than service category labels.

Real-World Example: Target 2013 — SOC That Didn't Act

The Target breach in 2013 is as much a story about SOC failure as about technical compromise. Target had deployed FireEye malware detection tooling that correctly identified the malware used in the attack and generated alerts. The alerts were reviewed by Target's security operations team in Bangalore, who escalated to the US security team. The US team did not act on the alerts. The malware continued to operate for weeks, exfiltrating 40 million payment card records. The lesson is critical: security monitoring without effective response processes produces no security outcome. The SOC's value is not in detecting threats — it is in detecting and responding to threats.

24/7

Monitoring is required for a SOC to be effective — because attackers time their most damaging actions for nights, weekends, and holidays when they expect reduced monitoring attention. A SOC that is only staffed during business hours provides 33% of the coverage a threat actor accounts for.

How Cloudskope Can Help

Cloudskope's Managed Detection and Response service provides 24/7 SOC capability for mid-market organizations, operated by practitioners with backgrounds in military intelligence, law enforcement, and enterprise security engineering. Our MDR service wraps existing security tooling rather than requiring replacement, delivering immediate coverage uplift without migration disruption.