What Is a Security Operations Center (SOC)?
A Security Operations Center (SOC) is the team, process, and tooling that continuously monitors for, detects, and responds to security threats. It is the operational front line — the people watching the SIEM, triaging alerts, investigating the suspicious, and coordinating response when something is real. A SOC is where security stops being a plan and becomes a shift.
What does a SOC do day to day?#
The core loop is monitor → triage → investigate → respond:
- Monitor — watch alerts and logs from across the environment.
- Triage — separate the meaningful from the noise (most alerts are noise).
- Investigate — dig into genuine leads to understand scope and impact.
- Respond — contain, eradicate, and recover, per the incident response plan.
How is a SOC structured?#
Commonly in tiers, though the model varies:
| Tier | Role |
|---|---|
| Tier 1 | Alert triage and escalation |
| Tier 2 | Deeper investigation and response |
| Tier 3 | Threat hunting, detection engineering, advanced threats |
Organizations may run their own SOC, outsource to a managed provider, or combine both. Whatever the shape, the hardest problems are the same: alert fatigue, staffing and burnout, and turning a flood of data into timely action.
The SOC is where detection and response happen operationally. More at the Defense & Hardening hub.
Frequently asked questions#
What does a SOC do?
A Security Operations Center (SOC) is the team, processes, and technology responsible for continuously monitoring an organization’s security, detecting threats, and responding to incidents. It watches logs and alerts, triages what matters, investigates suspicious activity, and coordinates response — the operational front line of defense, often running around the clock.
How is a SOC typically structured?
Many SOCs use tiers: Tier 1 analysts triage and escalate alerts, Tier 2 investigate deeper, and Tier 3 handle advanced threats, threat hunting, and detection engineering. Some organizations run their own SOC, others outsource to a managed provider (MSSP), and many use a hybrid of both.