Security Operations Centre (SOC)
A team, with supporting processes and technology, that continuously monitors an organisation's systems for security threats, investigates alerts and coordinates the response to incidents.
A SOC collects security telemetry from endpoints, networks, cloud services, identity systems and applications, typically into a SIEM platform, and analysts triage the resulting alerts. Work is often organised in tiers: first-line analysts review and escalate alerts, senior analysts investigate and contain incidents, and specialists hunt for threats, engineer detections and analyse malware. Playbooks and SOAR tools standardise and automate common steps.
Organisations run SOCs in-house, outsource them to managed security service providers or managed detection and response services, or combine both in a hybrid model. Round-the-clock coverage matters because attackers often act at night, at weekends or during holidays. Converged SOCs increasingly monitor operational technology as well as IT, which requires knowledge of industrial protocols and of the safety constraints on response actions.
SOC effectiveness is commonly measured by mean time to detect and mean time to respond, alert volumes and false-positive rates, and coverage of attacker techniques mapped to MITRE ATT&CK. Alert fatigue, staff shortages and gaps in log coverage are persistent challenges, so tuning, automation and clear escalation paths to incident response teams are essential.
Key points
- Provides continuous monitoring, triage and investigation of security events.
- Can be run in-house, outsourced or as a hybrid.
- Commonly measured by mean time to detect and mean time to respond.
- Relies on SIEM, EDR and SOAR tooling as well as skilled analysts.
Where AiVibe comes in
AiVibe's security services include 24/7 monitoring with AI-powered anomaly detection, supported by threat intelligence.
Related terms
- Security Information and Event Management (SIEM)Cybersecurity & Compliance
- Security Orchestration, Automation and Response (SOAR)Cybersecurity & Compliance
- Endpoint Detection and Response (EDR)Cybersecurity & Compliance
- Incident ResponseCybersecurity & Compliance
- Threat IntelligenceCybersecurity & Compliance
- Anomaly DetectionAI & Machine Learning