What is a SOC? Definition, tasks and structure
A Security Operations Center (SOC) is a team of people, processes and technology. It monitors an organisation's IT and OT environment around the clock, detects attacks and coordinates the response. A SOC is not a piece of software; it is an operating unit.
What a SOC does
- Continuous monitoring of logs, endpoints, network and cloud
- Triage and investigation of every alert
- Threat hunting beyond existing rules
- Incident response, including containment and recovery coordination
- Reporting to management and regulator
Tools: SIEM, EDR, SOAR
SIEM collects and correlates logs. EDR delivers endpoint telemetry and response. SOAR automates repeatable playbooks. None of these technologies alone is a SOC. A SOC is the team that orchestrates them.
The classic tier model and why it is outdated
Historically a SOC was split into Tier 1 (triage), Tier 2 (investigation) and Tier 3 (hunting/engineering). Modern SOCs drop the rigid split: automation and agentic AI handle triage, and every analyst works with contextualised alerts.
SOC vs. NOC
A NOC (Network Operations Center) manages availability and performance. A SOC manages security. Both run 24/7. A NOC asks whether systems are running; a SOC asks whether they are compromised.
Placement in SOC operations
The framework for building and operating a SOC for Swiss organisations is described on SOC as a Service Switzerland.
Frequently asked questions
What does a SOC analyst do?
SOC analysts review alerts, weigh context, decide on response and coordinate with IT and management. Modern analysts focus on decisions and avoid spending time copying and pasting between consoles.
What is the difference between SOC and NOC?
A NOC monitors availability and performance; a SOC monitors security events and attacks.
Does an SME need a SOC?
Yes, as soon as an incident would seriously affect operations. For SMEs, an outsourced managed SOC is usually the only economical option.
What is the difference between SOC and MDR?
A SOC is the operating unit; MDR is a service model with a contractual commitment to respond. Read more on [SOC vs. MDR](/en/soc/soc-siem-edr-xdr-mdr-terms).
How long does it take to set up a SOC?
An in-house SOC build takes several weeks to months for onboarding, plus several quarters to mature. A managed SOC delivers operations within the [onboarding phase](/en/soc/soc-onboarding-switzerland).
Related terms
- SOC A Security Operations Center (SOC) is the team that constantly monitors an organisation's IT for attacks and intervenes during incidents.
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- Tier-less SOC A Tier-less SOC is a model that operates without the traditional T1, T2, and T3 analyst hierarchy.
- T1 / T2 / T3 T1, T2, and T3 are the classic tiered roles for analysts within a Security Operations Center.
- MTTR Mean Time to Respond (MTTR) is the average time from when an incident is detected until it is contained.
- MTTD Mean Time to Detect (MTTD) is the average time from the start of an attack to its detection.