What a Security Operations Centre Actually Is
A Security Operations Centre or SOC, is the combination of people, process and technology that an organisation uses to watch its systems for cyber threats around the clock. It detects suspicious activity, works out which alerts are real incidents and coordinates the response so an attack is contained before it does serious harm.
A SOC is a function, not a room. It can be a physical operations room, a distributed virtual team or a service you buy and it is sometimes written security operations center. What defines it is the monitoring and response behind it, wherever the analysts sit.
This matters now because attackers move faster and hide longer than most in-house teams can track. New flaws in internet-facing kit are exploited within days of disclosure and stealthy intruders can sit inside a network for months. The law has caught up too and Swedish organisations are now expected to detect and report incidents on a tight clock.
How a SOC Works
A SOC runs a continuous loop. It collects signals from across the estate, spots the ones that look like an attack, confirms them, contains the damage and then feeds what it learns back into better detection.

- Collect: A SIEM pulls logs and telemetry from endpoints, identities, cloud services and the network into one place
- Detect: Correlation rules, behavioural analytics and threat intelligence turn raw events into alerts worth a human’s attention
- Triage and Investigate: Analysts confirm which alerts are real, then scope how far an incident has spread
- Respond: The team contains and remediates often using SOAR automation and EDR or XDR to isolate a device or account fast
- Improve: Analysts tune the rules, retire noisy ones and hunt for intrusions that never raised an alert
The people usually sit in tiers. Tier 1 triages incoming alerts, Tier 2 investigates confirmed incidents and Tier 3 handles threat hunting and complex response. A SOC manager, detection engineers and incident responders round out the team.
Two numbers describe the reality. Roughly four in five SOCs run around the clock yet the most common SOC is still only 2 to 10 people, according to the SANS Institute’s 2024 SOC Survey.
A small team covering nights and weekends is why so many organisations share the load rather than staff it all themselves. The metrics that matter are mean time to detect (MTTD) and mean time to respond (MTTR).
Types of SOC
A SOC can be built, shared or bought. The right shape depends on your size, budget and how much you can staff around the clock.
- In-house SOC: You build, staff and run it yourself. Suits large organisations with the budget and headcount for 24/7 cover
- Virtual SOC: A distributed team often part-time or on-call with no dedicated operations room
- Co-managed or hybrid SOC: You keep some functions in-house and share the rest with a provider, a common fit when a small team needs round-the-clock cover
- SOC as a service (SOCaaS): Monitoring, detection and response delivered by an external provider sold in a form such as managed detection and response
- Command SOC or fusion centre: Coordinates several SOCs or blends security with fraud and physical-security teams used mainly by large or multinational organisations
With the most common SOC only 2 to 10 people (SANS Institute, 2024), mid-sized and public-sector organisations often reach for a co-managed model or SOC as a service. It buys the one thing a small team cannot easily create on its own which is genuine 24-hour coverage by trained analysts.
Why a SOC Matters to the Business
The value of a SOC is time. The faster an attack is spotted and contained, the smaller the loss and the easier it is to meet a reporting deadline. Four pressures make that speed hard to reach without one.
- Attacks are fast: For new critical flaws in perimeter and VPN devices, the median time from disclosure to mass exploitation was effectively zero days and ransomware appeared in 44% of breaches per the Verizon 2025 Data Breach Investigations Report
- Attacks are patient: Cyberespionage intrusions are often documented only 6 months to more than 4 years after they begin per ENISA’s 2025 Threat Landscape so periodic scans miss them
- People are scarce: The most recent published global workforce gap is about 4.8 million roles (ISC2, 2024) and 88% of organisations had a significant incident tied to a skills gap in the past year (ISC2, 2025)
- Alerts drown teams: About 62% of security teams say they are overwhelmed by data and alert volume (SANS 2024 Detection and Response Survey) and likewise cite the Detection and Response Survey for the MTTD and MTTR point so real threats get lost in the noise
Ransomware is the most impactful threat across the EU, according to ENISA’s 2025 report. A SOC exists to turn a flood of alerts into a short list of confirmed incidents that are handled quickly. That is what shortens dwell time and shorter dwell time is what limits the financial and operational damage.
Real-World Cases
Three incidents show what continuous monitoring is for. Each points to a control that a watching SOC provides.
Miljödata, 2025

In August 2025 ransomware hit Miljödata, a Swedish supplier of HR and sick-leave software used by roughly 80% of the country’s municipalities. Swedish authorities confirmed that 164 municipalities and four regions were directly affected with around 250 clients touched in total once universities and private firms were counted.
The attackers demanded about 1.5 bitcoin, roughly 1.5 million kronor. On 14 September 2025 data on more than a million Swedes was published on the dark web. CERT-SE coordinated the national response.
The lesson is that your monitoring has to reach the suppliers you depend on. A breach at a single vendor became a breach at hundreds of public bodies and only fast detection with a rehearsed response keeps that blast radius small.
Coop and the Kaseya Attack, 2021
On 2 July 2021 the REvil group exploited an unknown flaw in Kaseya VSA, a remote monitoring and management tool. The Swedish supermarket chain Coop was hit not directly but through its payment-systems supplier Visma Esscom which used the tool.
Coop closed nearly all of its roughly 800 stores for almost a week, keeping open only its online shop and stores in a handful of regions . It refused to pay and rebuilt its systems. Swedish State Railways, the pharmacy chain Apoteket Hjartat and the petrol-station chain St1 were caught up in the same wave.
Here the attack rode in through trusted, legitimate software. A SOC watches for odd behaviour even from tools you trust and network segmentation stops one compromise from reaching everything. That combination is what contains a supply-chain hit like this.
SolarWinds, 2020
Attackers compromised the build system behind SolarWinds Orion and slipped trojanised updates to customers between March and June 2020. The intrusion was not discovered until December 2020 roughly nine months of poisoned updates in the wild.
CISA issued Emergency Directive 21-01 on 13 December 2020, ordering federal agencies to disconnect the affected products. About 18,000 organisations installed the update and around a hundred private companies and nine federal agencies were actively breached.
The intruders used valid credentials and blended into normal activity so signature tools and point-in-time scans never flagged them. Continuous monitoring, behavioural detection and active threat hunting are what surface an attacker who already looks like a legitimate user.
SOC and Compliance
For Swedish organisations, monitoring is now a legal expectation. Cybersäkerhetslagen (SFS 2025:1506) brought the EU NIS2 Directive into Swedish law and came into force on 15 January 2026.
NIS2 Article 21 requires risk-management measures that include incident handling, business continuity and supply-chain security. Article 20 makes the management body approve and oversee those measures and lets supervisors hold board members personally accountable.
Article 23 sets the clock. A significant incident must reach MCF (formerly MSB) and the sector authority as an early warning within 24 hours, a full notification within 72 hours and a final report within one month.
That 24-hour clock starts at detection rather than at Monday-morning discovery. You cannot report what you have not detected which is why continuous monitoring underpins the whole duty. Fines run up to 10 million euros or 2% of global turnover for essential entities.
Two neighbouring regimes add to this. DORA Article 17 sets ICT incident-management rules for financial entities supervised by Finansinspektionen. GDPR Article 33 gives you 72 hours to notify the data protection authority IMY when personal data is exposed.
The targets are not hypothetical. ENISA found that 53.7% of analysed EU incidents hit essential entities as defined by NIS2 so the sectors the law covers are the ones already under fire.
Signs Your Monitoring Has Gaps
You rarely see a missing SOC directly. You see the symptoms. Any of these is a sign that your detection is not keeping up.
- Your last incident came to light through a customer, a partner or plain luck rather than your own monitoring
- Alerts pile up unreviewed overnight, at weekends and over holidays
- No one can tell you your mean time to detect or respond, a blind spot for more than half of teams (SANS Institute, 2024)
- You own plenty of security tools but nobody is correlating what they report
- You collect logs but no one is watching them in real time
A SIEM or an EDR is not a SOC. Collecting logs is not the same as having someone read them and tools without the people and process to act on them just add noise. If any of the signs above sound familiar, the gap is not usually more technology. It is the monitoring and response wrapped around it.
How to Build or Choose a SOC
Whether you build a SOC, buy it or share it, the same choices decide whether it works. Start with coverage, then staffing, then tooling.

- Match your coverage to your deadlines. If you must warn MCF within 24 hours of detection, you need monitoring that does not sleep
- Be honest about staffing. A 2-to-10-person team rarely covers nights and weekends so a co-managed SOC or SOC as a service often fits a smaller organisation better than hiring alone
- Consolidate before you buy more. Correlate the logs and telemetry you already collect rather than adding another disconnected tool
- Measure MTTD and MTTR from day one and work to bring both down
- Extend monitoring beyond your own endpoints to your suppliers and cloud services
- Rehearse the response so a detection turns into containment instead of a scramble
If building and staffing a 24-hour capability is out of reach, a Swedish-based provider can run the monitoring for you. eBuilder Security offers managed detection and response from a SOC in Sweden and pairs it with penetration testing to find the gaps before an attacker does. For a closer look at a neighbouring discipline, see the guide to vulnerability management.
The single most useful step is to decide, today, who is watching your systems tonight. If the answer is nobody, that is the gap to close first.



