SOC

Security Operations Center

Sicherheits-Leitstand / Security Operations Center

A SOC is the combination of people, processes and technology that continuously monitors security events, detects and assesses incidents and steers the response. It is the organisational place where Security Information and Event Management (SIEM) alerts turn into actual decisions and countermeasures. Its key metrics are mean time to detect (MTTD) and mean time to respond (MTTR).

History. The SOC evolved conceptually from the Network Operations Center (NOC) of the 1990s, which initially monitored availability. As attackers professionalised, availability monitoring turned into security monitoring. A tiered analyst model has become established — triage at Tier 1, investigation at Tier 2, threat hunting and forensics at Tier 3.

Facts. An effective SOC needs more than a dashboard: defined playbooks, a maintained source and use-case base, threat intelligence and a clear escalation chain. Round-the-clock operation is demanding and expensive in staffing terms, which is why SOC-as-a-Service has become an established operating model. The often months-long dwell time of attackers reported in industry studies shows what a SOC is meant to address: not the individual tool, but the gap between compromise and discovery.

Outlook & recommendation. Artificial Intelligence (AI)-assisted anomaly detection increasingly shifts Tier-1 work into automation but does not replace human judgement in a real incident. For most mid-sized organisations, running an in-house 24/7 SOC is neither economical nor feasible in staffing terms — operation via a specialised partner is the norm. At NEOSEC this tier corresponds to the highest Extended Security Incident and Event Management (XIEM) expansion stage, Command.

SOC — Security Operations Center