SOC
A Security Operations Center (SOC) is the team that constantly monitors an organisation's IT for attacks and intervenes during incidents.
A Security Operations Center (SOC) is the team that continuously monitors an organisation's IT for attacks and intervenes during incidents. It combines analysts, processes, and tools like SIEM and EDR into a continuous operation.
How it works
The SOC collects logs and telemetry from endpoints, identities, the cloud, and the network. Detection rules generate Alerts that analysts evaluate, investigate, and contain if necessary. Triage is important here. From thousands of daily signals, only a few Cases remain that require attention.
For example, an account logs in from an unknown country at 3 a.m. It then starts PowerShell on a server. The SOC correlates both signals, blocks the account, and isolates the server. By morning, IT receives a documented Case with all supporting artefacts.
What to look out for
- Coverage: Which log sources are connected, and which are still missing?
- Operating hours: Is the same quality of work maintained at night, on weekends, and on holidays?
- Metrics: MTTD and MTTR should be measured and reported regularly.
- Noise: A high false-positive rate occupies analysts and can obscure real attacks.
- Mandate: It must be clearly defined which actions the SOC can take without consultation.
Switzerland and regulation
FINMA Circular 2023/1 requires banks and securities firms to effectively detect and handle cyberattacks. Since 1 April 2025, the ISG has obliged operators of critical infrastructure to report cyberattacks that meet the criteria to the National Cyber Security Centre (NCSC) within 24 hours of discovery. A SOC provides the foundation for meeting both of these requirements.
Typical mistakes
Many organisations build a SOC around a tool and forget about the operational aspects. A SIEM without maintained rules detects little, and without night-time coverage, alerts sit until the morning. Another mistake is having a scope that is too narrow. Monitoring only endpoints means attacks via cloud accounts and suppliers may be missed. Therefore, check annually which attack paths the SOC can and cannot see. A purple team test provides a good basis for this assessment.
How we implement it
We operate our SOC 24/7 from Switzerland, combining automation, Agentic AI, and analysts in a single, non-tiered team. For Critical Alerts, we respond contractually within 60 minutes, typically in under 15 minutes.