What is a managed SOC, and does your organisation need one?
What a security operations centre actually does, what changes when you outsource it, and the honest test for whether your organisation needs one yet.
A security operations centre is a function, not a room
The phrase conjures a darkened room of screens. In practice a security operations centre is a function: the continuous work of collecting security telemetry, identifying activity that matters, investigating it, and doing something about it before it becomes an incident.
That function has four requirements. Somewhere for security data to land and be searched. Detection logic that identifies suspicious activity within it. People with the skill to judge whether an alert represents genuine risk. And an agreed process for what happens when it does.
Organisations frequently have the first, sometimes the second, and rarely the third and fourth. This is why so many have security tooling that produces alerts nobody reads, which provides the cost of a control without its benefit.
What "managed" changes
A managed SOC means a provider supplies the platform, the detection engineering and the analysts, as a service. You keep ownership of your systems and your decisions; they operate the monitoring function.
The economic argument is straightforward. Staffing a SOC around the clock requires several analysts, because coverage across nights, weekends, leave and turnover cannot be done with one or two people. In a market where security analysts are scarce, recruiting and retaining them is a substantial and continuing commitment. A managed provider spreads that cost across many organisations.
The trade is dependency and disclosure. Your provider sees a great deal about your environment, and your detection quality becomes their responsibility. That is why how the provider secures its own platform, and how it isolates one customer from another, deserves scrutiny before you sign anything.
What a SOC does on an ordinary day
Most days contain no incident. The work is still substantial, and the quality of that routine work determines whether the platform catches anything on the day that matters.
- Triage: reviewing the events the detection layer raised and separating genuine risk from routine noise.
- Investigation: for events that survive triage, establishing what actually happened - which account, which process, which host, and whether it appears elsewhere.
- Tuning: adjusting detections that fire too often or not often enough. An untuned ruleset is the most common reason a SOC deployment fails.
- Coverage checking: confirming log sources are still reporting. A source that has silently stopped is indistinguishable from one with nothing to say.
- Detection engineering: writing new rules for techniques observed in the wild or found during hunting.
- Reporting: recording outcomes so the monthly report reflects what actually happened.
The honest test for whether you need one
Not every organisation needs a managed SOC, and a provider that tells you otherwise is selling rather than advising. A useful test is to ask four questions and answer them truthfully.
- If an attacker had valid credentials on your network right now, what would tell you? If the honest answer is "nothing", that is the gap.
- How long would a compromise persist before someone noticed? If the answer is measured in months, monitoring changes your risk materially.
- Who looks at security alerts at 22:00 on a Friday? If nobody does, your coverage matches when attackers are least active, not most.
- What would a week of downtime cost? If that number is significant, compare it with the annual cost of monitoring.
What a managed SOC will not do
Monitoring is detection and response, not prevention. It does not stop attacks from starting. It shortens the interval between something going wrong and somebody competent knowing - which in most incidents is the difference between a contained event and a disclosed breach.
It also does not compensate for absent fundamentals. If privileged accounts have no multi-factor authentication, backups have never been restored, and critical systems have gone unpatched for years, monitoring will detect the resulting incidents rather than prevent them. A good provider will tell you to fix those first, and will say so before taking your money rather than after.