Security Operation Centre - What is it actually?

Security Operation Centre - What is it actually?

Security Operation Centre - What is it actually?

In a survey, we asked you what you would like to know more about in connection with a SOC (Security Operation Centre). Here are the answers from our experts:  

What is a SOC and how does it work?

A SOC (Security Operation Centre) can be understood as the central control centre for all security-relevant information on IT resources. It is made up of a team of IT security experts and a tool that processes all information digitally - the so-called SIEM (Security Information and Event Management). In this tool, all data from the connected system areas is recorded in real time and simultaneously monitored by the experts. This enables the SOC to work in parallel around the clock, allowing vulnerabilities and potential threats to be recognised and eliminated proactively. As soon as an anomaly (unusual behaviour, e.g. triggered by an attack or vulnerability) is detected by the SIEM, it is checked by the SOC team and, in an emergency, an alert is triggered and specific measures are initiated immediately.

To summarise, the main task of a SOC is the central security management of system-relevant company areas in the form of monitoring, analysing and dealing with possible security gaps in order to protect the company's entire IT infrastructure as effectively and preventively as possible.

Which areas should be connected?

Technically speaking, almost all areas of a company can be monitored by a SOC. Which specific areas should be connected depends heavily on the respective industry and the individual priorities of the company or its existentially important areas. In principle, however: 

A SOC is only as good as the data that is available to it

Director Managed Services

The more areas that are connected, the better and more reliably the SOC can monitor and protect IT security.

Depending on the industry and area of activity, we recommend the direct connection of particularly critical systems and personal data. These include, for example, AD, firewall, VPN, endpoints, DNS and DHCP. Building on this, various access points such as routers, switches and email gateways should also be monitored in order to quickly identify and stop intruders.  

How does it react to anomalies?

A Security Operation Centre is a combination of technical sophistication and human expertise. The response to an anomaly depends on both factors. By using a SIEM system, certain anomalies or attack scenarios can be recognised and suitable countermeasures can be initiated at short notice together with the customer.  

Why is that?  

Anomalies are incidents that happen outside the norm or the known. An example to illustrate this: Bernd Bärendienst has been logging on to his client at 08.00 on Mondays to Fridays for 10 months and logging off again at 17.00. Bernd Bärendienst now has a critical project and is suddenly working at the weekend. This case clearly deviates from the norm and would at least be worth registering in a SOC.

This anomaly is probably harmless, but the system has to report it first. For this purpose, the configuration is continuously adapted to reduce false positives, among other things.

How are you notified?

Notifications are largely automated from within the system. Here too, the configuration determines when and to what extent information is output. As a rule, this still happens quite frequently at the beginning and becomes more targeted and optimised with increasing runtime.

Increasing optimisation in the area of response will therefore mean that not every message will require consultation with the customer, but communication will be much more targeted. This will enormously reduce the effort on all sides. Communication is sent to all defined stakeholders using different communication media depending on the criticality. These can be adapted at any time.  

What is the response time?

Basically, the response time varies from SOC to SOC due to various factors. On the one hand, it depends on the skill level of the team and, above all, on the degree of automation of the tools used. The lower the level of automation, the more messages have to be checked and processed manually by the team, even harmless messages such as Bernd Bärendienst's working time, which takes up a lot of time. In addition, different incidents may require different amounts of effort, which can also have an impact on the average response time. To minimise the response time, it is essential to consider specific measures, such as orchestration and automation, and implement them as far as possible.  

How is the quality of the analysis?

With the use of a SOC, every company takes its own customised ideal path in the area of IT security. However, the royal road can only be travelled royally and carefree if the basics are right. In other words, all important and relevant log sources must be connected and it takes time to put the SOC into optimum detection and processing mode.

Our SOC already comes with a comprehensive standard configuration, but of course this cannot be the optimal solution for all companies. IT infrastructures are too heterogeneous for this and there are too many special features.

However, if these factors are taken into account, our SOC is probably one of the best IT security solutions on the market.

Screen Shot 2025-05-14 at 19-a9cb.png

Michael Döhmen

Chief Marketing Officer

Published on 14.05.2025