Security operations centre
SOC · The team and processes that continuously monitor logs and alerts from your systems, investigate suspicious events and notify the right people.
- 01
Why it matters
Attacks often start quietly and outside working hours; they leave traces in logs and alerts, but nobody notices if nobody is watching. A security operations centre watches those traces continuously, separates real threats from false alarms and tells the right person what to do. An incident spotted early does far less damage.
- 02
Example
At 3 a.m. an administrator account signs in from another country and downloads many files within minutes. The analyst reviewing the alert confirms it is unusual, recommends disabling the account and leaves a detailed note for the team in the morning.
- 03
Common mistake
Sending every alert with the same priority, or forwarding them all to e-mail without triage. A team flooded with pointless alerts soon ignores all of them, and the real attack gets lost in the noise.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.