What is a SOC? Definition, tasks and structure

A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.

All

What a SOC does

  • Continuous monitoring of logs, endpoints, network and cloud
  • Triage and investigation of every alert
  • Threat hunting beyond existing rules
  • Incident response, including containment and recovery coordination
  • Reporting to management and regulator

Tools: SIEM, EDR, SOAR

SIEM collects and correlates logs. EDR delivers endpoint telemetry and response. SOAR automates repeatable playbooks. None of these technologies alone is a SOC. A SOC is the team that orchestrates them.

The classic tier model and why it is outdated

Historically a SOC was split into Tier 1 (triage), Tier 2 (investigation) and Tier 3 (hunting/engineering). Modern SOCs drop the rigid split: automation and agentic AI handle triage, and every analyst works with contextualised alerts.

SOC vs. NOC

A NOC (Network Operations Center) manages availability and performance. A SOC manages security. Both run 24/7. A NOC asks whether systems are running; a SOC asks whether they are compromised.

Frequently asked questions

What does a SOC analyst do?

SOC analysts review alerts, weigh context, decide on response and coordinate with IT and management. Modern analysts focus on decisions and avoid spending time copying and pasting between consoles.

What is the difference between SOC and NOC?

A NOC monitors availability and performance; a SOC monitors security events and attacks.

Does an SME need a SOC?

Yes, as soon as an incident would seriously affect operations. For SMEs, an outsourced managed SOC is usually the only economical option.

What is the difference between SOC and MDR?

A SOC is the operating unit; MDR is a service model with a contractual commitment to respond. Read more on [SOC vs. MDR](/en/soc/soc-siem-edr-xdr-mdr-terms).

How long does it take to set up a SOC?

An in-house SOC build takes several weeks to months for onboarding, plus several quarters to mature. A managed SOC delivers operations within the [onboarding phase](/en/soc/soc-onboarding-switzerland).