• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » Security Operations Center (SOC)

Security Operations Center (SOC)

Definition

Security Operations Center (SOC)

A security operations center (SOC) is a dedicated team, tools, and playbooks that watch an organization’s networks, endpoints, and cloud assets in real time — detecting, triaging, and responding to cyber threats around the clock so a breach never has room to spread.

Most SOCs run as follow-the-sun operations, staffed 24/7 across three or more shifts. Tier-1 analysts triage alerts, Tier-2 analysts investigate incidents, and Tier-3 threat hunters chase advanced adversaries before they escalate.

Standing up an in-house SOC is expensive — 24/7 staffing, security information and event management (SIEM) licenses, and rare threat-hunting talent all bite.

That is why buyers increasingly outsource the function to managed security service providers (MSSPs), buying SOC-as-a-Service by the seat or by the alert.

The category has boomed since 2020. Managed detection and response (MDR), the premium outsourced tier that layers threat hunting on top of monitoring, has grown into a multi-billion-dollar market as ransomware losses climbed.

Key takeaways

  • A SOC is the always-on function that monitors, detects, and responds to cyber threats across a company’s networks, endpoints, and cloud assets.
  • SOC teams tier work into Tier-1 triage, Tier-2 investigation, and Tier-3 threat hunting, with a SOC manager and chief information security officer (CISO) sitting above them.
  • Core tooling combines log correlation, response automation, endpoint detection, and threat intelligence feeds, all glued together by documented incident response playbooks.
  • Outsourced SOC-as-a-Service gives mid-market firms 24/7 coverage without the need to hire 30 analysts in-house.
  • Key metrics are mean time to detect (MTTD), mean time to respond (MTTR), and dwell time.

How it works

A SOC works as a layered pipeline: sensors feed a SIEM, analysts triage the alerts against playbooks, and confirmed incidents escalate to response. The four-step workflow of monitor, detect, analyze, and respond is codified by NIST in its cybersecurity glossary.

TierRoleTypical output
Tier 1Alert triage and classificationClosed false positives, escalated incidents
Tier 2Incident investigation and containmentRoot-cause reports, containment actions
Tier 3Threat hunting and forensicsNovel indicators of compromise, hardened detections
SOC managerMetrics, staffing, escalationWeekly MTTD/MTTR reports

Behind the tiers sits the tool stack: a SIEM, a security orchestration, automation, and response (SOAR) platform, and endpoint detection and response (EDR) agents catch what network sensors miss. Threat intelligence feeds enrich every alert with adversary context.

Playbooks matter more than tools. A Tier-1 analyst chasing a phishing alert follows the same steps every time: check sender reputation, sandbox the attachment, pivot on any indicators of compromise, and close or escalate.

Repeatable playbooks are what let a lean team scale.

In 2024, IBM’s Cost of a Data Breach report pegged the global average breach at $4.88 million, and firms using extensive security AI and automation saved an average of $2.22 million per incident. That is the business case buyers use to justify the SOC spend.

Examples

Real SOCs range from Fortune 100 in-house command rooms to lean outsourced pods run out of Manila or Kraków. What they share is a 24/7 duty roster, a defined tier structure, and named playbooks for the top ten alert types.

JPMorgan Chase runs one of the largest private-sector SOCs on Earth, backed by a technology budget north of $17 billion in 2024. Its global security operations center processes billions of events per day across hubs in New York, London, and Singapore.

Global providers like Accenture and IBM run Manila-based security operations centers as regional delivery hubs, monitoring client networks across Asia-Pacific around the clock. The Philippines has become a major SOC outsourcing base for English-fluent cyber talent.

The US government runs a federated SOC model, with agency SOCs feeding CISA’s National Cybersecurity Protection System. That structure was hardened after the 2020 SolarWinds intrusion, when EINSTEIN sensors missed the supply-chain compromise.

Sophos and Arctic Wolf both operate multi-tenant SOCs serving thousands of small-and-medium business clients, the retail end of the market. Their SOC-as-a-Service model has grown fast because most mid-market firms cannot staff 24/7 monitoring alone.

Related terms

These glossary terms sit closest to the SOC in a buyer’s mental map. Each one names either a delivery model, a core tool, or a contract lever that determines how well the security operations center actually performs.

FAQ

Common questions buyers ask when comparing in-house SOC builds against outsourced SOC-as-a-Service contracts. Each answer sticks to the facts a procurement team needs before signing a monitoring deal.

What does a security operations center actually do?

A security operations center continuously monitors an organization’s networks, endpoints, and cloud assets, then detects and responds to cyber threats as they surface. Most SOCs also handle vulnerability tracking, compliance reporting, and post-incident forensics.

What is the difference between a SOC and an MSSP?

A SOC is the function — the people, tools, and playbooks. A managed security service provider is one delivery model for that function, running your SOC under contract instead of you staffing it in-house.

Why do companies outsource their SOC?

Cost, coverage, and talent. Running a true 24/7 in-house SOC needs 8-12 analysts minimum, plus SIEM licenses that start at six figures. Outsourced SOC-as-a-Service turns that fixed cost into a monthly subscription and shifts the hiring risk to the provider.

How many people work in a typical SOC?

A small mid-market SOC typically runs on 6-10 analysts across three shifts, while a Fortune 500 in-house SOC can carry 50-200 staff across regional hubs.

Compare vetted SOC-as-a-Service providers and BPO partners in the Outsource Accelerator directory.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image