Insights · 24 July 2026

What is a SOC? Inside a security operations centre

Learn what a Security Operations Centre is, with key roles, costs and how it protects UK organisations in 2026. Discover how a SOC detects and responds to incidents today.

What is SOC? A Security Operations Centre (SOC) is a team, processes and tools that detect, investigate, respond to and report security incidents for an organisation.

A SOC centralises telemetry from endpoints, cloud and identity systems, triages alerts and coordinates containment and regulator‑ready reporting under UK rules such as the Information Commissioner’s Office breach duties. In the UK, 43% of businesses reported a cyber security incident in 2025 (GOV.UK, 2025), analysts estimated the average cost of a significant cyber incident to a UK business in 2025 (IBM, 2025), and the National Cyber Security Centre summarised incident trends and defensive priorities in its 2025 annual review (NCSC, 2025).

  • Definition: A SOC is a team plus tools that find and manage security incidents, from detection through to reporting.
  • Main functions: Collection, alerting, triage, investigation, response coordination and regulator‑ready reporting under UK duties such as the Information Commissioner’s Office.
  • Why it matters: 43% of UK businesses reported a cyber security incident in 2025 (GOV.UK, 2025), so detection and response reduce impact.
  • Build or buy: Decide by telemetry coverage, response playbooks and regulator duties such as the Information Commissioner’s Office and National Cyber Security Centre guidance (NCSC, 2025).
  • Cost signals: Analysts published UK breach cost estimates in 2025 (IBM, 2025); ask providers for priced scenarios with clear Service Level Agreements (SLA) and escalation paths.

What is a SOC? (what is soc)

A Security Operations Centre (SOC) is a team, processes and technology that detect, investigate, respond to and report security incidents for an organisation.

What is SOC in practice: a SOC centralises alerts from logs, endpoint agents, cloud services and identity systems, triages those alerts, escalates confirmed incidents and co-ordinates remediation and reporting. The SOC’s primary goals are threat detection, incident investigation, containment and restoration.

Key Takeaway

A SOC turns noisy security signals into clear actions: detect what matters, investigate fast, and coordinate response and reporting under UK regulatory expectations.

Core functions

The SOC performs six core functions: collection of telemetry, alerting, triage, investigation, response co-ordination and reporting. Collection uses SIEM (Security Information and Event Management) or XDR (Extended Detection and Response) platforms plus endpoint detection. Triage removes false positives, investigation builds a timeline, response contains the incident and reporting documents impact for boards and regulators.

In the UK, SOC outputs are often required by regulators and standards such as the National Cyber Security Centre (NCSC), the Information Commissioner’s Office (ICO), the Financial Conduct Authority (FCA) and ISO 27001. The SOC helps meet breach notification duties under UK GDPR and evidences controls cited in NIS2 and DORA when applicable.

Why a SOC matters now: 43% of UK businesses reported a cyber incident in 2025, showing how common breaches are in the market (GOV.UK, 2025). Organisations that invest in a SOC reduce detection times and improve coordinated response, which limits business impact; IBM’s UK study shows measurable cost differences where detection and response are faster (IBM, 2025).

In our experience, deciding what is SOC for your organisation starts with telemetry coverage and response playbooks: define which logs and endpoints feed the SOC, who owns escalations, and what regulatory reports the SOC must produce. If you want a hands-on guide to outsourcing or building a SOC, see our managed SOC page for practical options and pricing.

How does a SOC work in practice, including shift patterns and escalation paths?

A Security Operations Centre (SOC) collects telemetry, detects suspicious activity, triages alerts, investigates incidents and escalates to containment or incident response teams within agreed on-call paths.

A what is soc answer in one line: telemetry intake, detection rules, analyst triage, investigation and escalation form the SOC lifecycle. The SOC ingests logs from endpoints, cloud services, network devices and identity systems into a Security Information and Event Management (SIEM) or XDR platform, then uses detection engineering and threat hunting to find real incidents. Practical SOCs rely on what is soc tooling such as SIEM, Endpoint Detection and Response (EDR), and Security Orchestration Automation and Response (SOAR) to automate repetitive tasks and surface high‑priority alerts.

Toolchain and detection methods

SOCs use a toolchain: SIEM for aggregation, EDR for endpoint telemetry, XDR for cross-product correlation, and SOAR for scripted response. Detection content maps to frameworks such as MITRE ATT&CK for consistent coverage, and threat hunting looks for anomalies that rules miss. The 2025 Verizon Data Breach Investigations Report shows system intrusions remain a dominant pattern, which justifies investment in detection engineering and hunting. The National Cyber Security Centre (NCSC) guidance on operational monitoring explains how to balance alerting thresholds and retention so teams can investigate without drowning in noise, and practical UK SOCs follow that guidance for telemetry and escalation design (NCSC, 2025).

Shifts, rotas and escalation paths

Typical UK SOC rosters combine 24/7 cover with handovers and on-call escalation to senior analysts and the incident response function. A common pattern is a three-shift model: daytime core analysts, overlap shifts for handover, and night watch covering alerts and escalation. Analysts triage by severity, creating tickets with context, evidence and recommended containment steps; high-severity incidents escalate to an incident responder or the IT Director on a defined on-call rota. Clear playbooks and runbooks reduce mean time to detect and mean time to respond, which in turn limits business impact. If you need help deciding whether to run an in-house SOC or buy a managed service, our comparison on managed detection vs SOC explains the trade-offs and practical onboarding steps (MDR or a SOC).

What is a SOC? Inside a security operations centre - supporting illustration

What does SOC stand for and who is on a SOC team?

A SOC is a Security Operations Centre, and a SOC team combines analysts, threat hunters, incident responders, a SOC manager and supporting roles to detect, triage and respond to cyber incidents.

In the UK, a SOC team typically includes tiered analysts who triage alerts, senior analysts or threat hunters who investigate complex activity, incident responders who contain breaches, a SOC manager who runs day-to-day operations, and threat intelligence and engineering support that tune detection rules and tooling.

Common SOC roles

SOC Analyst Level 1 monitors alerts and gathers context for higher tiers, SOC Analyst Level 2 investigates and escalates confirmed incidents, and SOC Analyst Level 3 or threat hunters conduct deep investigations and proactive hunting. SOC managers coordinate shifts, reporting and escalation to executive teams and to the Data Protection Officer (DPO) where personal data incidents implicate UK GDPR.

Shift patterns and escalation

UK teams often run a three-shift model with handovers and an on-call senior analyst or incident responder for high-severity incidents, plus formal escalation routes to the IT Director and to the board for material incidents. Organisations under the Network and Information Systems 2 (NIS2) rules or the Financial Conduct Authority (FCA) expectations should document these escalation lines and include the DPO and compliance owners in incident playbooks.

Skills, certifications and coordination

Valued certifications in the UK include CREST, Certified Information Systems Security Professional (CISSP) and SANS courses for detection and response skills. SOC teams coordinate with the Data Protection Officer and the board on reporting and regulatory notifications, following guidance from the Information Commissioner's Office (ICO) and with threat intelligence inputs from the European Union Agency for Cybersecurity (ENISA).

For a compact overview of who runs our SOC and accreditations, see our About 24/7 SOC page.

Understanding what is soc means knowing who will act during an incident, how they hand over, and who signs off notifications under UK GDPR and NIS2.

Who needs a SOC, and when can you outsource it?

At CyPro, we see that organisations holding sensitive data, subject to UK GDPR or NIS2 reporting, or without 24/7 analyst cover need SOC capabilities, and outsourcing is the pragmatic choice when you cannot sustain continuous staffing or tooling investment.

Regulatory and risk triggers

Under UK GDPR and the NIS2 Directive, organisations that must detect and report incidents promptly should be able to demonstrate monitoring and response arrangements, so a SOC or equivalent service often forms part of that evidence. Evidence of widespread cyber harm supports this: the UK government found many firms report recurring attacks and financial impact (GOV.UK), and industry analysts position Managed Detection and Response alongside SOC capabilities for organisations that cannot accept long dwell times (Forrester, 2025).

When to build, when to outsource

Build an internal Security Operations Centre when you have a sustained budget, senior security analysts, mature incident response practises and a business case for 24/7 shifts. Outsource your SOC when you lack shift rotas, cannot justify SIEM platform costs, or need faster time to capability. Outsourcing moves day to day monitoring and analyst shifts to the provider while governance, escalation and business decisions remain with you.

At CyPro, we publish clear options so teams can decide: an internal SOC, a managed SOC subscription, or a fully outsourced SOC run from the UK. See our managed offering and our outsourced SOC playbook for procurement and onboarding detail: Your 24/7 managed SOC, run from the UK, Outsource your SOC without losing control.

How much does a SOC cost in the UK?

Typical UK options in 2026 cost: building an in-house Security Operations Centre (SOC) from £500,000 to £1.5m in year one, a managed SOC from £3,000 to £60,000 per month, and SOC as a Service from £1,500 to £25,000 per month depending on scope and scale.

Costs vary primarily by staffing, tooling and hours of coverage, plus onboarding and integrations.

Key Takeaway

Plan SOC spend around people and tools: staff costs drive in-house builds, while vendor licence tiers drive managed SOC pricing. Match the model to whether you need 24/7 coverage and senior analysts.

Primary cost drivers

People and tooling are the two biggest drivers. Headcount for an in-house SOC commonly includes Tier 1 analysts, senior threat hunters, a SOC manager and on-call rotas, which push annual payroll above £350,000 for a small 24/7 team. Licences for a Security Information and Event Management (SIEM), endpoint detection tools and log storage add tens to hundreds of thousands of pounds per year. Additional costs include cloud ingestion, integrations, threat intelligence feeds and ongoing training.

How managed and outsourced models change the maths

Managed SOC or SOC as a Service packages turn fixed staff and licence costs into a monthly subscription, which helps predictability. Entry-level SOC as a Service often starts around £1,500 per month for basic coverage, while fully featured 24/7 managed SOCs aimed at mid-market UK firms commonly sit between £3,000 and £25,000 per month in 2026. Larger enterprise packages with bespoke threat hunting and retention can reach £60,000 per month.

ModelTypical UK price (2026)What is included
In-house build£500k to £1.5m first yearHiring, SIEM, EDR, training, premises, shift rotas
Managed SOC£3k to £60k per month24/7 analysts, detections, response, reporting
SOC as a Service£1.5k to £25k per monthSubscription monitoring, onboarding, standard integrations

Gartner notes that market offerings and pricing models for managed detection and response vary widely across providers, which affects comparability and procurement discussions Gartner. Live monitoring platforms such as Mandiant's ASM dashboards show how alert volumes and asset counts scale costs as you add more endpoints or cloud sources Mandiant.

For UK organisations, factor in regulatory needs: under NIS2 and UK GDPR you may need faster detection and longer log retention, which raises costs. If you are unsure which model fits your maturity and budget, review how many alerts you expect, whether you need 24/7 cover, and the seniority of analysts required.

What is a SOC? Inside a security operations centre - supporting illustration

What is a SOC report and what should it contain?

A SOC report summarises incidents, trends, key metrics and recommended actions for stakeholders, providing evidence for audits and governance. A good SOC report covers incidents, Mean Time To Detect (MTTD), Mean Time To Respond (MTTR), open investigations, risk actions and trend analysis.

In the UK, SOC reports are used as compliance evidence for the Information Commissioners Office (ICO), the Financial Conduct Authority (FCA) and ISO 27001 auditors, and they feed into board-level risk reporting.

Typical contents

Essential sections are: an executive summary, incident log with severity and status, detection and response metrics, trending for attack types and affected assets, root cause notes, and a clear remediation tracker with owners and deadlines. SOC reports should include a timeline for each incident and a record of communications for regulator or insurer requests. For background on wider incident trends, see NCSC Annual Review 2025 and the 2025 Data Breach Investigations Report.

Format and cadence

Daily alerts, weekly dashboards, monthly metric packs and quarterly board reports are the common cadence. The executive summary must answer two questions: what happened and what the business needs to approve. The monthly pack should include MTTR and MTTD, counts of confirmed incidents, and high-priority unmitigated risks.

What to ask your provider

Ask for an items checklist: incident timestamps, root cause, impacted assets, containment steps, recovery status, remediation owner, and evidence copies. Request that reports map findings to ISO 27001 controls or your internal risk register. For an example of how SOC reporting supports certification, see our dual certification case study.

How to choose a SOC provider or delivery model

Match the delivery model to your use case, skills and budget, and prioritise detection, response and integration coverage. A simple checklist helps decide between an in-house Security Operations Centre (SOC), Managed SOC, SOC as a Service and Managed Detection and Response (MDR).

Start by mapping risk: which assets must be monitored, how fast you need response, and whether you require UK data residency or 24/7 coverage. Then score providers on tooling, analyst skill and onboarding transparency. Our experience shows that clarity on these points stops procurement from becoming a feature comparison exercise.

Decision checklist

Answer these five questions and you will narrow options quickly: 1) Do you need 24/7 coverage or business-hours only? 2) Do you have existing telemetry (EDR, logs, cloud monitoring)? 3) Do you need hands-on incident response or just alerting? 4) Is UK data residency required? 5) What budget and senior analyst time can you commit to run a SOC?

Use the answers to weight the trade-offs: in-house SOCs give control but cost staff and tooling; Managed SOCs provide continuous operations without hiring; SOC as a Service packages scope and pricing; MDR focuses on endpoint detection with bundled response. For market context, analyst reports frame MDR and SOC markets and vendor capabilities Forrester, 2025 and platform guidance is summarised in research on managed detection and response Gartner.

How we evaluate providers

We score providers on five criteria: detection coverage (logs, cloud, endpoints), analyst skill and threat hunting, response playbooks and integration with your IT, onboarding time and data residency, and pricing transparency including run-books and SLAs. Ask for a sample playbook, a list of required log sources, and a clear SLA for time to acknowledge and time to remediate.

At CyPro, we find teams choosing Managed SOC when they need continuous, UK-based analysts without the build cost, and choosing MDR when endpoint protection plus rapid containment is the priority. If you are still deciding, our MDR or SOC comparison explains the trade-offs in practical terms.

Frequently asked questions

What is a SOC report?

A SOC report summarises security incidents, trends and key performance indicators for stakeholders. Typical contents include incident summaries, mean time to detect (MTTD), open investigations, risk actions and recommendations. Boards, Data Protection Officers (DPOs), auditors and IT operations teams use these reports. Cadence varies: daily alerts, weekly dashboards, monthly metrics and quarterly board packs are common.

Do I need a SOC if I already have Endpoint Detection and Response (EDR)?

EDR helps detect threats on endpoints, but a SOC provides 24/7 monitoring, correlation across sources and incident response. EDR alone can suffice for small organisations with low risk and clear playbooks. You should consider a SOC when you have multiple telemetry sources, regulatory requirements or limited in-house security staff. Run a one-month EDR pilot to review detection coverage before deciding.

How long does it take to stand up a SOC?

Typical timelines range from three months for a Managed SOC or SOC as a Service to 12 months or more for an in-house build. Time depends on integrations, playbook readiness, staff hiring and tooling procurement. Interim options include Managed Detection and Response (MDR) while you build. We recommend a four to six week discovery to scope integrations and staffing needs.

Can a SOC be fully outsourced?

Yes, a SOC can be fully outsourced via Managed SOC or SOC as a Service, provided contracts cover SLAs, data residency and escalation routes. Outsourcing buys speed and expertise but you should keep control of playbooks and reporting. At CyPro, we help clients define contracts and test providers during onboarding, including exit plans and UK-based analyst requirements if needed.

What ROI can I expect from a SOC?

ROI varies by organisation but is often shown as reduced mean time to detect and avoided breach costs. Short-term wins include faster detection, fewer escalations to executives and clearer compliance evidence. Measure ROI by baseline MTTD, incident frequency and incident costs before and after the SOC. Use a 12 month plan with specific KPIs and quarterly reviews to track progress.

3D rocket illustration for booking a free MDR discovery call

Take the first step

Put a 24/7 SOC behind your business

See what 24/7 cover would cost your estate in about thirty seconds, then book a free 45 minute discovery call when you want the exact figure. No obligation, no hard sell.