← All terms

Security Operations Center (SOC)

A security operations center (SOC) is the team that monitors, detects and responds to security events — including the ones people report.

A security operations center (SOC) is the centralized function — a team, its processes, and its tooling — responsible for continuously monitoring an organization's environment, detecting security incidents, and coordinating the response. Whether it's an in-house room of analysts, a fully outsourced managed service (MSSP/MDR), or a hybrid, the SOC is where alerts from across the company converge and become decisions: real or false positive, contain now or watch, escalate or close.

How it works

The core loop is telemetry in, verdicts out. Logs and alerts from endpoints, identity providers, email gateways, and network sensors flow into a SIEM or detection platform; analysts triage what the tooling flags, investigate what looks real, and hand confirmed incidents to responders. Work is typically tiered — front-line triage, deeper investigation, threat hunting — and runs against playbooks so that a 3 a.m. phishing report gets the same handling as a 3 p.m. one.

What's easy to miss is how much of a SOC's best signal comes from people rather than sensors. A user-reported phishing email is often the earliest indicator of a campaign in progress; an employee who calls about an unexpected MFA prompt may be the only "sensor" that catches a push-bombing attack using valid credentials. Social engineering rarely trips a technical alarm — the human report is the detection.

How to strengthen it

Treat the workforce as the SOC's outermost sensor grid. Make reporting effortless (one button in the mail client), answer every report — a thank-you within minutes is what keeps the next report coming — and track report rates from phishing simulations as a detection metric, not just a training statistic. Close the loop in both directions: SOC findings about real lures should feed the awareness program, and repeated risky behavior visible in SOC data belongs in the organization's human risk measurement. A SOC that ignores the human layer is monitoring only half the attack surface.

Related terms

Blue TeamA blue team is the defensive side of security — the people who detect, respond to and harden against attacks, including social engineering.Insider ThreatAn insider threat is the risk that employees, contractors, or partners with legitimate access cause harm — maliciously, negligently, or after being compromised.Human FirewallA human firewall is a workforce trained and measured to recognize, resist and report social engineering — the defensive layer technology cannot replace.MFA Fatigue AttackAn MFA fatigue attack bombards a user with repeated multi-factor authentication push notifications until they approve one out of frustration or confusion.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo