IT glossary
SOC (Security Operations Centre)
A SOC, or security operations centre, is the team that watches an organization's systems for signs of attack and decides what to do when an alert fires.
Confusingly, the same three letters are also used for SOC 2, an unrelated auditing standard about how a company handles data. If someone asks whether you are “SOC compliant”, they almost certainly mean that one.
Why it matters to you
Security monitoring only works if someone is looking. A SOC is what “someone is looking” actually consists of: analysts on a rota, a defined severity scale, a documented set of actions for each kind of alert, and a way to reach you at an inconvenient hour.
Very few organizations under 200 people can staff this themselves, it takes enough people to cover nights and weekends without burning them out. So it is normally bought as a service.
The questions worth asking
- Where are the analysts? Time zone, country, and whether your data leaves Canada.
- Are they employees of the provider, or a subcontracted platform? This is the single biggest quality difference in the market, and the one least often volunteered.
- What are the staffed hours? “24/7 monitoring” sometimes means software runs continuously and a human looks in the morning.
- What do they do, not just report? Detection without the authority to contain something is a slower version of an email.
happier IT runs its own security operations centre in Canada, staffed by our own people. That is a deliberate choice and it is the main thing that distinguishes us in this part of the market.