IronSights

Detection & response

Security Operations CentreSOC

A centralised function — either internal or outsourced — responsible for continuously monitoring an organisation's security posture, detecting threats, and coordinating incident response.

Also known asSOCsecurity operations center

In plain English

A SOC is the team (and the tools they use) that watches for cyber attacks around the clock. They monitor alerts from security systems, investigate suspicious activity, and respond when something looks wrong. Most SMEs don't run their own SOC — they rely on a managed security provider to perform this function on their behalf.

Keep learning

More terms in the IronSights Glossary.