A security operations centre (SOC) combines people, processes and technology to improve your organization's resilience against cyber threats. A SOC is run from a central location by a team of information security professionals. This includes security engineers who may work closely with your development team, security analysts and threat hunters.
As cyber threats evolve and become more sophisticated, many organizations are establishing SOC capabilities to better detect, investigate and respond to cyber incidents. The threat landscape has expanded due to increasing reliance on operational technology (OT) systems with information technology (IT) environments, as well as growing reliance on cloud services and artificial intelligence (AI)-enabled systems. This means that there is a greater need for continuous security monitoring and response.
This publication provides guidance for organizations of all sizes on best practices for establishing, operating and continuously improving a SOC. It also provides guidance to organizations interested in subscribing to a SOC as a service (SOCaaS) from a third-party provider.
On this page
How SOCs operate
SOCs are primarily responsible for detecting and responding to cyber incidents and threats. SOCs can also conduct vulnerability assessments, penetration testing, threat hunting and auditing for regulatory compliance. Specifically, SOCs perform the following key activities:
Monitoring and detection
SOCs collect and analyze security and event data from across the organization’s environment, including specialized environments that may require dedicated monitoring tools and expertise. This includes:
- on-premises devices
- cloud services
- industrial control systems (ICS) and OT systems
- remote systems
- mobile devices
This data is used to identify abnormal activity, indicators of compromise (IoCs) and potential threats. Threats are assessed and assigned severity ratings, and alerts are generated based on defined policies and priorities.
Response and recovery
When a threat or incident is identified, SOCs quickly investigate and take immediate action to contain and mitigate the threat. This is especially important for organizations that may not have 24/7 in-house monitoring or response capabilities. During this process, SOCs analyze the incident to identify the root cause and determine what was affected. They also support recovery efforts by restoring affected systems and data and helping return operations to a normal state.
Analysis and improvement
SOCs analyze incidents to understand their cause and impact. They review audit logs, user activity logs and system logs to determine how an incident occurred and what was affected. Lessons learned can be used to improve detection capabilities, response procedures and overall security operations.
Supporting IT and OT environments
SOCs may support IT environments, OT environments, or both. While the core functions of a SOC remain the same, the technologies being protected, operational priorities, and response requirements can differ.
IT environments typically include business systems, networks, cloud services, endpoints and data. SOC activities focus on detecting and responding to threats that could affect business operations and information assets.
OT environments include ICS and technologies that support physical processes and operations. In these environments, maintaining safe and reliable operations may be a primary consideration during incident response activities.
Organizations that operate both IT and OT environments should ensure their SOC processes, tools and personnel account for the unique requirements of each environment.
SOC as a service
If your organization has limited resources, it may be challenging to set up and operate a SOC. As an alternative, your organization could consider a SOCaaS subscription model. Some organizations adopt a hybrid approach, where core functions like monitoring and incident response are performed in-house, while specialized activities such as penetration testing or malware analysis are outsourced.
When evaluating a SOC provider:
- ensure the services offered align with your organization’s operational, security, legal, privacy and data protection requirements
- confirm that services can be tailored and scaled to support your organization’s environment and changing operational needs
- understand how tools and technologies are used to collect, use, store and protect your data
- assess what level of access the provider requires to your systems, networks and security information
- review how the service integrates with your existing security tools, processes and incident response procedures
- evaluate the provider’s security practices, including service level agreements and the use of AI-enabled tools
- assess how the provider manages supply chain risks, including third-party dependencies, and safeguards against vulnerabilities
Benefits of SOCs
SOCs combine efforts to support incident response, including threat identification, containment, eradication, recovery and reporting. Together, these efforts help strengthen your organization’s overall security posture and provide the following key benefits.
Proactive threat hunting
By combining historical data and threat intelligence, SOCs can detect early signs of attacks that might otherwise go unnoticed. They establish a baseline of normal system and network activity and investigate when behaviour deviates from expected patterns.
Improved incident detection and response times
Depending on their size and level of expertise, SOCs can quickly detect signs of an attack, conduct an initial investigation and start to contain the threat. This heightened response can limit the damage to your organization and help to prevent threat actors from accessing your valuable assets and sensitive information.
Increased security visibility and centralized incident management
SOCs use tools and dashboards to provide real-time situational awareness of your organization’s security posture. This can help you better coordinate resources needed to fix and contain threats.
Support for informed decision-making
SOCs help prioritize risks and response activities, giving your organization the information needed to make timely and effective decisions during an incident.
Regular auditing of systems
By ensuring industry and government regulations are followed, SOCs can help to protect your organization from reputational damage, administrative or material privacy violations and legal liability in case of a breach.
Reduced business impact
SOCs help limit disruption by containing threats early and supporting the restoration of systems and data, helping your organization return to normal operations more quickly.
Considerations when establishing your SOC
A SOC can help increase your organization’s resilience against cyber threats and minimize the impact in the event of a compromise. The following are some best practices to consider when setting up and operating a SOC.
Develop a SOC strategy
- Identify high-value assets, including systems, services and data, that require monitoring and protection
- Conduct a cyber security risk assessment to understand likely threats and their potential impact
- Assess the capability and intent of threat actors targeting your organization
- Identify legal, regulatory and compliance requirements that affect SOC operations
- Define clear objectives, scope and success criteria for your SOC
Design a SOC that meets your organization's needs
- Select a SOC model that aligns with your risk profile, business needs and available resources
- Design your SOC to scale and adapt as threats, technologies and requirements evolve
- Use threat-informed defence by incorporating frameworks such as MITRE ATT&CK and OWASP top ten
- Plan integration with existing IT, cloud and OT environments
- Ensure the SOC has the expertise needed to monitor and support specialized technologies, such as industrial systems and telecommunications networks
- For large enterprises, consider consolidating or sharing SOC capabilities across regions or organizations to improve efficiency and visibility
Implement and operate your SOC
- Collect and centralize relevant data from endpoints, networks, cloud services and OT systems
- Use automation and an event management solution to support alert triage, analysis and incident management
- a number of commercial and open-source security information and event management platforms are available to help your organization benefit from the volumes of event data collected daily
- Establish and regularly test an incident response plan to ensure timely recovery of critical services
- Apply and maintain controls to ensure SOC activities comply with legal and regulatory requirements and protect sensitive data
- Document and regularly update processes, procedures and playbooks to support consistent and effective detection and response
- Build, train and retain a skilled SOC team, and support employee well-being to reduce fatigue and burnout
Maintain and improve your SOC
- Promote communication and collaboration between the SOC and key stakeholders across your organization
- Collect and review performance metrics to assess effectiveness and guide improvements
- Regularly update detection rules, playbooks and processes based on new threats and lessons learned
- Conduct exercises such as simulations and assessments to validate SOC capabilities
- Expand capabilities over time to include advanced practices such as threat hunting and deception
Considerations for critical infrastructure
Organizations that support critical infrastructure or essential services should design their SOC to support continued operations during severe cyber disruptions and to protect services that are critical to public safety and economic security.
- Identify and prioritize systems, assets and services that are essential to safe and continuous operations
- Ensure SOC monitoring focuses on these critical areas
- Align SOC detection, response and recovery processes with incident response and business continuity plans that account for extended disruptions and degraded conditions
- Prepare the SOC to support isolation of affected systems or network segments to contain threats and maintain critical functions when required
- Ensure the SOC can operate effectively when external systems, services or connectivity are unavailable, including during isolated or degraded states
- Support recovery by enabling validation, rebuilding and restoration of systems from trusted and offline sources following severe cyber incidents
For more information, read our publication Critical infrastructure resilience and escalated threat navigation initiative.
Using AI in your SOC
AI-enabled tools can help SOC teams process large volumes of security data, identify patterns and support security operations. Organizations may use AI to assist with activities such as alert triage, log analysis, threat hunting and incident investigation.
While AI can improve efficiency, it should complement, not replace, human decision-making. AI-generated outputs may be incomplete, inaccurate or lack important context. SOC analysts should validate AI-generated findings and maintain oversight of security decisions and incident response activities.
Before implementing AI-enabled tools, your organization should:
- assess how AI will support existing SOC processes and operational requirements
- ensure AI-generated outputs can be reviewed and validated by SOC personnel
- understand what data the AI tool collects, processes and stores
- implement appropriate access controls to protect sensitive information
- monitor AI-enabled systems and services as part of regular security operations
- review incident response procedures to address risks associated with AI-enabled systems
As AI technologies continue to evolve, organizations should regularly review how AI is used within their SOC and update processes, controls and training as needed.