What is a SOC (Security Operations Center)?
A SOC (Security Operations Center) is the function that monitors an organisation's systems for security incidents and responds to them when they occur. Where many security measures are preventive, a SOC is the active part of cybersecurity: the eyes on the screen that spot the attack while it is happening. The function consists of analysts, documented processes and tools that together ensure an alarm at three in the morning does not simply vanish into an inbox.
What does a SOC do around the clock?
The work in a SOC follows a fixed rhythm, whether the team sits in-house or with a partner:
- Monitoring: analysts follow alerts from SIEM, EDR and other sources across servers, clients, networks and cloud.
- Triage: every alert is assessed and prioritised. Is it a false positive, a minor issue or an attack in progress?
- Response: for genuine incidents, affected machines are isolated, accounts are locked, and the attack is investigated and documented, so you know what happened and how to stop it in future.
Because attackers do not keep office hours, 24/7 coverage is the whole point. The Danish Centre for Cyber Security highlights precisely the ability to detect and handle incidents as a core element of a robust cyber defence.
SOC vs. SIEM vs. MDR
The three terms are often mixed up, but they describe different things:
- SOC is people and processes: the team that monitors and responds.
- SIEM is the tool: the platform that collects log data and generates the alerts the SOC works from, for example Microsoft Sentinel.
- MDR (Managed Detection and Response) is the SOC function bought as a service, often marketed as SOC as a Service: an external provider monitors your environment and responds on your behalf.
In short: SIEM without a SOC is alarms nobody hears. A SOC without SIEM is analysts without data. MDR is the packaged solution where both come included.
Does an SMB need a SOC?
The honest answer: very few Danish SMBs need their own SOC. An in-house setup requires at least five to eight specialists to cover all shifts, and that investment rarely matches the risk for a company with 20 to 200 employees.
But the need for the function does not go away. Ransomware hits SMBs in particular, and requirements from customers and regulation such as NIS2 presuppose that you can detect and handle incidents. The solution is therefore typically access to the SOC function through a partner: monitoring and response as a service, sized for your organisation.
How MI Support IT can help
We give you the SOC function's core tasks without you having to build an in-house team: setting up monitoring and alerting as part of your IT security, combined with our 24/7 service desk that responds when something requires action. Contact us for a conversation about what monitoring and response could look like in your environment.