Introduction to the SOC
What a Security Operations Center is, why it exists, and how it delivers value
Learning Objectives
- ›Define a SOC and its mission
- ›Understand the threat landscape SOCs defend against
- ›Identify SOC business outcomes (MTTD, MTTR, risk reduction)
- ›Differentiate SOC vs NOC vs IT support
Module 1 — What is a SOC?
A Security Operations Center is a centralized function — people, process, technology — that continuously monitors, detects, analyzes, and responds to cyber threats across an organization.
SOCs operate 24/7/365 and are the operational arm of the security program. They turn raw logs into decisions and actions.
Models: in-house, MSSP (managed), MDR (managed detection & response), hybrid, virtual SOC.
Module 2 — Why Companies Build SOCs
Regulatory pressure: PCI-DSS, HIPAA, SOX, GDPR, NIS2, ISO 27001 all require monitoring & incident response.
Risk reduction: average breach cost is USD 4.88M (IBM 2024); a mature SOC reduces dwell time from months to hours.
Brand & customer trust: a fast, transparent breach response preserves reputation.
Module 3 — SOC vs NOC vs IT Support
NOC watches availability and performance (uptime, latency, capacity).
IT Support fixes user-reported issues (password resets, hardware).
SOC watches security signals — adversary activity, policy violations, indicators of compromise.
All three sit in operations; only the SOC has an adversary on the other side.
Module 4 — Threat Landscape 2025
Top categories: ransomware-as-a-service, identity-driven attacks, supply chain, cloud misconfigurations, AI-augmented phishing.
Adversaries: nation-state APTs, financially motivated crime groups, hacktivists, insiders.
Identity-driven breaches take 292 days to identify and contain on average.
Lab 1 — Tour the SOC Platform
- Open the LMS dashboard and skim the 30-day curriculum.
- Open the Splunk ES lab and click each top-level tab (Posture, Incident Review, Search…).
- Write a 4-line definition of a SOC in your own words.
- List 5 outcomes a SOC delivers to the business.
Key Takeaways
- ✓A SOC is people + process + technology operating 24/7 against an active adversary
- ✓MTTD and MTTR are the universal SOC scoreboards
- ✓Splunk Enterprise Security is today's industry-standard SIEM