Security operations

What is a SOC (Security Operations Centre)?

The business guide to what a SOC is, how it works and how it keeps you inside NIS2 detection and reporting deadlines.

Key takeaways
  • A SOC is the people, process and technology that monitor your systems for threats around the clock, then detect, investigate and contain them.
  • A SOC is a function rather than a location, so it can be in-house, co-managed or delivered as a service.
  • The core stack is a SIEM for logs, SOAR for automation and EDR or XDR for endpoints, run by analysts in tiers.
  • Roughly four in five SOCs run 24/7, yet the most common SOC is still only 2 to 10 people (SANS Institute, 2024).
  • The global cybersecurity workforce gap is about 4.8 million roles (ISC2, 2024), and 88% of organisations had an incident tied to a skills gap in the past year (ISC2, 2025).
  • Ransomware is the most impactful threat in the EU and appeared in 44% of breaches (ENISA 2025, Verizon 2025).
  • Attackers can stay hidden for months to years, so point-in-time scans miss them and continuous monitoring is what catches them (ENISA, 2025).
  • NIS2, in Swedish law as Cybersäkerhetslagen since 15 January 2026, expects active detection and reporting to MCF within 24 hours of detection.
  • Buying a SIEM or an EDR is not the same as running a SOC, which needs people and a process to act on what the tools find.
  • For a small team, a co-managed SOC or SOC as a service usually beats trying to staff 24/7 alone.

What a Security Operations Centre Actually Is

A Security Operations Centre or SOC, is the combination of people, process and technology that an organisation uses to watch its systems for cyber threats around the clock. It detects suspicious activity, works out which alerts are real incidents and coordinates the response so an attack is contained before it does serious harm.

A SOC is a function, not a room. It can be a physical operations room, a distributed virtual team or a service you buy and it is sometimes written security operations center. What defines it is the monitoring and response behind it, wherever the analysts sit.

This matters now because attackers move faster and hide longer than most in-house teams can track. New flaws in internet-facing kit are exploited within days of disclosure and stealthy intruders can sit inside a network for months. The law has caught up too and Swedish organisations are now expected to detect and report incidents on a tight clock.

How a SOC Works

A SOC runs a continuous loop. It collects signals from across the estate, spots the ones that look like an attack, confirms them, contains the damage and then feeds what it learns back into better detection.

How a SOC Works
  • Collect: A SIEM pulls logs and telemetry from endpoints, identities, cloud services and the network into one place
  • Detect: Correlation rules, behavioural analytics and threat intelligence turn raw events into alerts worth a human’s attention
  • Triage and Investigate: Analysts confirm which alerts are real, then scope how far an incident has spread
  • Respond: The team contains and remediates often using SOAR automation and EDR or XDR to isolate a device or account fast
  • Improve: Analysts tune the rules, retire noisy ones and hunt for intrusions that never raised an alert

The people usually sit in tiers. Tier 1 triages incoming alerts, Tier 2 investigates confirmed incidents and Tier 3 handles threat hunting and complex response. A SOC manager, detection engineers and incident responders round out the team.

Two numbers describe the reality. Roughly four in five SOCs run around the clock yet the most common SOC is still only 2 to 10 people, according to the SANS Institute’s 2024 SOC Survey.

A small team covering nights and weekends is why so many organisations share the load rather than staff it all themselves. The metrics that matter are mean time to detect (MTTD) and mean time to respond (MTTR).

Types of SOC

A SOC can be built, shared or bought. The right shape depends on your size, budget and how much you can staff around the clock.

  • In-house SOC: You build, staff and run it yourself. Suits large organisations with the budget and headcount for 24/7 cover
  • Virtual SOC: A distributed team often part-time or on-call with no dedicated operations room
  • Co-managed or hybrid SOC: You keep some functions in-house and share the rest with a provider, a common fit when a small team needs round-the-clock cover
  • SOC as a service (SOCaaS): Monitoring, detection and response delivered by an external provider sold in a form such as managed detection and response
  • Command SOC or fusion centre: Coordinates several SOCs or blends security with fraud and physical-security teams used mainly by large or multinational organisations

With the most common SOC only 2 to 10 people (SANS Institute, 2024), mid-sized and public-sector organisations often reach for a co-managed model or SOC as a service. It buys the one thing a small team cannot easily create on its own which is genuine 24-hour coverage by trained analysts.

Why a SOC Matters to the Business

The value of a SOC is time. The faster an attack is spotted and contained, the smaller the loss and the easier it is to meet a reporting deadline. Four pressures make that speed hard to reach without one.

  • Attacks are fast: For new critical flaws in perimeter and VPN devices, the median time from disclosure to mass exploitation was effectively zero days and ransomware appeared in 44% of breaches per the Verizon 2025 Data Breach Investigations Report
  • Attacks are patient: Cyberespionage intrusions are often documented only 6 months to more than 4 years after they begin per ENISA’s 2025 Threat Landscape so periodic scans miss them
  • People are scarce: The most recent published global workforce gap is about 4.8 million roles (ISC2, 2024) and 88% of organisations had a significant incident tied to a skills gap in the past year (ISC2, 2025)
  • Alerts drown teams: About 62% of security teams say they are overwhelmed by data and alert volume (SANS 2024 Detection and Response Survey) and likewise cite the Detection and Response Survey for the MTTD and MTTR point so real threats get lost in the noise

Ransomware is the most impactful threat across the EU, according to ENISA’s 2025 report. A SOC exists to turn a flood of alerts into a short list of confirmed incidents that are handled quickly. That is what shortens dwell time and shorter dwell time is what limits the financial and operational damage.

Real-World Cases

Three incidents show what continuous monitoring is for. Each points to a control that a watching SOC provides.

Miljödata, 2025

Real-World Cases

In August 2025 ransomware hit Miljödata, a Swedish supplier of HR and sick-leave software used by roughly 80% of the country’s municipalities. Swedish authorities confirmed that 164 municipalities and four regions were directly affected with around 250 clients touched in total once universities and private firms were counted.

The attackers demanded about 1.5 bitcoin, roughly 1.5 million kronor. On 14 September 2025 data on more than a million Swedes was published on the dark web. CERT-SE coordinated the national response.

The lesson is that your monitoring has to reach the suppliers you depend on. A breach at a single vendor became a breach at hundreds of public bodies and only fast detection with a rehearsed response keeps that blast radius small.

Coop and the Kaseya Attack, 2021

On 2 July 2021 the REvil group exploited an unknown flaw in Kaseya VSA, a remote monitoring and management tool. The Swedish supermarket chain Coop was hit not directly but through its payment-systems supplier Visma Esscom which used the tool.

Coop closed nearly all of its roughly 800 stores for almost a week, keeping open only its online shop and stores in a handful of regions . It refused to pay and rebuilt its systems. Swedish State Railways, the pharmacy chain Apoteket Hjartat and the petrol-station chain St1 were caught up in the same wave.

Here the attack rode in through trusted, legitimate software. A SOC watches for odd behaviour even from tools you trust and network segmentation stops one compromise from reaching everything. That combination is what contains a supply-chain hit like this.

SolarWinds, 2020

Attackers compromised the build system behind SolarWinds Orion and slipped trojanised updates to customers between March and June 2020. The intrusion was not discovered until December 2020 roughly nine months of poisoned updates in the wild.

CISA issued Emergency Directive 21-01 on 13 December 2020, ordering federal agencies to disconnect the affected products. About 18,000 organisations installed the update and around a hundred private companies and nine federal agencies were actively breached.

The intruders used valid credentials and blended into normal activity so signature tools and point-in-time scans never flagged them. Continuous monitoring, behavioural detection and active threat hunting are what surface an attacker who already looks like a legitimate user.

SOC and Compliance

For Swedish organisations, monitoring is now a legal expectation. Cybersäkerhetslagen (SFS 2025:1506) brought the EU NIS2 Directive into Swedish law and came into force on 15 January 2026.

NIS2 Article 21 requires risk-management measures that include incident handling, business continuity and supply-chain security. Article 20 makes the management body approve and oversee those measures and lets supervisors hold board members personally accountable.

Article 23 sets the clock. A significant incident must reach MCF (formerly MSB) and the sector authority as an early warning within 24 hours, a full notification within 72 hours and a final report within one month.

That 24-hour clock starts at detection rather than at Monday-morning discovery. You cannot report what you have not detected which is why continuous monitoring underpins the whole duty. Fines run up to 10 million euros or 2% of global turnover for essential entities.

Two neighbouring regimes add to this. DORA Article 17 sets ICT incident-management rules for financial entities supervised by Finansinspektionen. GDPR Article 33 gives you 72 hours to notify the data protection authority IMY when personal data is exposed.

The targets are not hypothetical. ENISA found that 53.7% of analysed EU incidents hit essential entities as defined by NIS2 so the sectors the law covers are the ones already under fire.

Signs Your Monitoring Has Gaps

You rarely see a missing SOC directly. You see the symptoms. Any of these is a sign that your detection is not keeping up.

  • Your last incident came to light through a customer, a partner or plain luck rather than your own monitoring
  • Alerts pile up unreviewed overnight, at weekends and over holidays
  • No one can tell you your mean time to detect or respond, a blind spot for more than half of teams (SANS Institute, 2024)
  • You own plenty of security tools but nobody is correlating what they report
  • You collect logs but no one is watching them in real time

A SIEM or an EDR is not a SOC. Collecting logs is not the same as having someone read them and tools without the people and process to act on them just add noise. If any of the signs above sound familiar, the gap is not usually more technology. It is the monitoring and response wrapped around it.

How to Build or Choose a SOC

Whether you build a SOC, buy it or share it, the same choices decide whether it works. Start with coverage, then staffing, then tooling.

How to Build or Choose a SOC
  • Match your coverage to your deadlines. If you must warn MCF within 24 hours of detection, you need monitoring that does not sleep
  • Be honest about staffing. A 2-to-10-person team rarely covers nights and weekends so a co-managed SOC or SOC as a service often fits a smaller organisation better than hiring alone
  • Consolidate before you buy more. Correlate the logs and telemetry you already collect rather than adding another disconnected tool
  • Measure MTTD and MTTR from day one and work to bring both down
  • Extend monitoring beyond your own endpoints to your suppliers and cloud services
  • Rehearse the response so a detection turns into containment instead of a scramble

If building and staffing a 24-hour capability is out of reach, a Swedish-based provider can run the monitoring for you. eBuilder Security offers managed detection and response from a SOC in Sweden and pairs it with penetration testing to find the gaps before an attacker does. For a closer look at a neighbouring discipline, see the guide to vulnerability management.

The single most useful step is to decide, today, who is watching your systems tonight. If the answer is nobody, that is the gap to close first.

Myths & Facts

Myth

A SOC is a room full of screens.

We have a firewall and antivirus, so we do not need a SOC.

A SIEM or an EDR is a SOC.

Only large enterprises need a SOC.

A SOC guarantees you will not be breached.

We only need monitoring during office hours.

Fact

A SOC is defined by what it does, which is continuous monitoring and response. It can be an in-house team, a virtual team or an outsourced service, and the wall of screens is optional.

Preventive tools stop known attacks but do not watch for the ones that get through. A SOC exists to detect, investigate and respond to what your defences miss.

A SIEM collects and correlates data but does not investigate or respond. Without analysts and a defined process, it produces alerts that no one acts on.

Attackers target smaller organisations too. Ransomware featured in 88% of breaches at small and mid-sized firms in 2025 (Verizon), and a co-managed SOC or SOCaaS makes cover affordable.

No control is perfect. A SOC does not promise zero incidents. It shortens the time to detect and contain them, and that is what limits the damage.

Attackers prefer nights, weekends and holidays. The Coop and Miljödata incidents both unfolded over a weekend, and NIS2 counts the 24-hour reporting clock from detection, whenever that is.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. It is Saturday night. Your monitoring flags unusual access to an HR system run by an external supplier.

    What is the right first move?

    • Wait until Monday to investigate
    • Trigger incident response now and investigate, including the supplier link
    • Assume the supplier will deal with it
  2. A routine update from a trusted software vendor starts behaving oddly, making network connections it never made before.

    What should your SOC do?

    • Ignore it because the software is trusted
    • Investigate the anomalous behaviour and isolate the affected systems
    • Whitelist the tool to stop the alerts
  3. Your team has a SIEM collecting logs from everything, but no one reviews alerts overnight.

    What does this tell you?

    • You have a working SOC
    • You have a monitoring gap, because collection without real-time review misses attacks
    • You should buy another tool
  4. An attacker has quietly used valid credentials inside your network for months without tripping antivirus.

    What is most likely to catch this?

    • A weekly vulnerability scan
    • Continuous monitoring with behavioural detection and threat hunting
    • A stronger firewall

Knowledge Test

  1. What best describes a SOC?

    • A physical room required by law
    • The people, process and technology that monitor and respond to threats
    • A type of firewall
    • A compliance certificate

    A SOC is a function combining people, process and technology, rather than a room, a product or a certificate.

  2. Roughly what share of SOCs run around the clock, per the SANS Institute 2024 SOC Survey?

    • About one in five
    • About four in five
    • All of them
    • About half

    Only about 20% of SOCs do not run 24/7, so roughly four in five operate around the clock (SANS Institute, 2024).

  3. What is the most recent published global cybersecurity workforce gap?

    • About 480,000 roles
    • About 4.8 million roles
    • About 48 million roles
    • There is no shortage

    The ISC2 2024 Cybersecurity Workforce Study put the gap at about 4.8 million unfilled roles.

  4. Under Cybersäkerhetslagen, how quickly must a significant incident reach MCF?

    • Within 24 hours of detection
    • Within 30 days
    • Only if data is stolen
    • There is no deadline

    Cybersäkerhetslagen requires an early warning to MCF within 24 hours of detection, then 72 hours and one month.

  5. Why do point-in-time scans miss attacks like SolarWinds?

    • Scans are too expensive
    • Attackers use valid credentials and blend in between scans
    • Scans only run at night
    • SolarWinds was not a real attack

    The SolarWinds intruders used legitimate credentials and stayed hidden for months, which periodic scans do not catch.

  6. For a small team that cannot staff 24/7, what usually fits best?

    • Turning off monitoring at night
    • A co-managed SOC or SOC as a service
    • Buying more security tools
    • Doing nothing until an incident

    With the most common SOC only 2 to 10 people, co-managed or SOC-as-a-service models give smaller teams round-the-clock cover.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

A SOC is only as strong as the people around it. Analysts catch what tools miss, but the staff outside the SOC are its first sensors. They are the ones who notice the odd invoice, the login that was not them or the supplier email that feels wrong, and who report it in time to matter.

Training turns employees into early warning rather than the way in. eBuilder Security’s Cyber 101 guides are written by the analysts who run its SOC, so the advice reflects what actually reaches the queue.

Frequently Asked Questions

What is a SOC (Security Operations Centre)?

A SOC is the combination of people, process and technology that monitors an organisation's systems for cyber threats around the clock. It detects suspicious activity, investigates which alerts are real incidents and coordinates the response, so attacks are contained before they cause serious harm.

What does a SOC do?

A SOC continuously watches endpoints, identities, cloud and network for signs of attack. It collects and correlates logs, triages alerts, investigates confirmed threats and drives containment and recovery. It also tunes detection rules, hunts for hidden intrusions and produces the evidence needed for incident reporting.

What is the difference between a SOC and a NOC?

A SOC (Security Operations Centre) defends against cyber threats, while a NOC (Network Operations Centre) keeps systems available and performing. The SOC investigates attacks and security incidents. The NOC handles outages, capacity and uptime. Larger organisations often run both and sometimes share tooling between them.

What is the difference between a SOC and MDR?

A SOC is the monitoring and response function itself, whether you run it in-house or buy it. MDR, or managed detection and response, is one way to buy that function as a service. It gives smaller teams 24/7 detection and response without building and staffing their own centre.

What does a SOC analyst do?

A SOC analyst reviews security alerts and decides which are real threats. The work is usually tiered. Tier 1 triages incoming alerts, Tier 2 investigates confirmed incidents and Tier 3 hunts for hidden threats and handles complex response. Detection engineers and a SOC manager support the team.

What is a SOC as a service (SOCaaS)?

SOC as a service delivers monitoring, detection and response from an external provider instead of an in-house team. It suits organisations that cannot staff a 24/7 centre, since the most common in-house SOC is still only 2 to 10 people (SANS Institute, 2024). Co-managed models share the work.

Does NIS2 or Cybersäkerhetslagen require a SOC?

Neither names a SOC directly, but both expect active detection and fast reporting. Under Cybersäkerhetslagen, in force since 15 January 2026, significant incidents must reach MCF within 24 hours of detection. Meeting that deadline is practically impossible without continuous monitoring, which is what a SOC provides.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.