A SOC (Security Operations Center) is a specialized unit responsible for monitoring, analyzing, and responding to cyber threats. This guide outlines the fundamentals of security operations, including core responsibilities, Tier 1–3 structures, common tools, the challenges of 24/7/365 operations, and the emerging alternative of AI SOC.

You have deployed EDR and SIEM, but it remains undecided who should review daily alerts and to what extent. When critical alerts trigger during nights or weekends, they go unnoticed until the next business day. It is common to hear these concerns from IT departments. While "SOC (Security Operations Center)" is often raised as the solution, the term itself can refer to a dedicated team, an external service, or a suite of tools, making the actual concept difficult to grasp.
This article defines the purpose and core tasks of a SOC, explains the Tier 1–Tier 3 operational structure, covers the tools used, and compares in-house, outsourced, and hybrid models. We will then analyze the structural limitations of traditional SOCs and introduce the alternative option of an AI SOC.
What is a SOC (Security Operations Center)? Definition and Purpose
A SOC is a dedicated unit (or function) that continuously monitors an organization's IT systems and networks, detects and analyzes signs of cyberattacks, and responds to incidents. Although the word "Center" often brings to mind a physical monitoring room, the essence is not the location. It is the continuous framework that combines people (analysts), processes (monitoring and response workflows), and technology (tools like SIEM and EDR). Basic terminology is also summarized in the glossary under "SOC (Security Operations Center)".
To understand this role, it is critical to distinguish between "events" and "incidents." The NIST (National Institute of Standards and Technology) Incident Response Recommendations and Considerations SP 800-61 Rev. 3 (published April 2025) defines an event as "any observable occurrence in a computing asset" and an incident as "an occurrence that actually or imminently jeopardizes the integrity, confidentiality, or availability of information or an information system" (NIST SP 800-61 Rev. 3, 2025). Countless events—including log-ins and software updates—occur daily within an organization. The core role of a SOC is to identify actual incidents requiring action from this vast pool of events and neutralize them before damage spreads.
The guideline aligns incident response with the six functions of the NIST Cybersecurity Framework (CSF) 2.0, explaining that Govern, Identify, and Protect primarily handle incident prevention, while Detect, Respond, and Recover manage the discovery, management, containment, eradication, and recovery of incidents (NIST SP 800-61 Rev. 3, 2025). Within this framework, the SOC is positioned as a continuous detection and response function that feeds lessons learned back to improve identification and protection.
The Difference Between SOC and CSIRT
Generally, a CSIRT (Computer Security Incident Response Team) acts as the decision-making and coordination command center when an incident occurs, whereas a SOC serves as the active operational force handling daily monitoring, detection, and initial response. In many organizations, the SOC escalates detected incidents to the CSIRT, which then coordinates with executive management, relevant departments, and regulatory authorities. Some organizations combine these roles, but both "monitoring and detection" and "response decision-making" functions remain essential.
Why is a SOC Crucial Now?
The driving force is the escalation of threats. In the organizational ranking of the "10 Major Information Security Threats 2026" published by IPA in January 2026, "Damage from Ransomware Attacks" ranked first for the 11th consecutive year, followed by "Attacks Targeting Supply Chains and Outsourcing Partners" in second place, and "Cyber Risks Surrounding AI Utilization" appearing for the first time in third place (IPA, 2026). Reports from the National Police Agency also show that ransomware incidents in 2025 remained high at 226 cases, with VPN devices accounting for over 60% of intrusion routes, and approximately 60% of victim organizations being SMEs. Over 50% of these organizations spent over 10 million yen on recovery, and only about half managed to recover in less than a month (National Police Agency, 2026).
Attacks are also accelerating. Mandiant's "M-Trends 2026," based on over 500,000 hours of incident investigations in 2025, notes that handoffs between ransomware criminal partners have shrunk to just seconds (Mandiant M-Trends, 2026). As the window between initial intrusion and actual damage shortens, waiting until "the next business day" is no longer an option. Because preventing all intrusions is nearly impossible, a continuous detection and response capability—a SOC—is essential for organizations of all sizes.
Core SOC Operations: 6 Essential Functions
SOC operations are divided into six main areas. This structured workflow begins with monitoring, triages alerts, analyzes key events, initiates incident response, and leverages the results for reporting and continuous improvement.
1. Monitoring
Logs and alerts are collected from firewalls, EDR, authentication platforms, cloud services, and servers for continuous 24/7 monitoring. NIST SP 800-61 Rev. 3 lists the continuous monitoring of unauthorized activities, unexpected behaviors, and changes in security posture to generate alerts for the SOC or incident responders as a key element of the detection function (NIST SP 800-61 Rev. 3, 2025). The scope and comprehensiveness of these logs dictate the quality of all subsequent stages.
2. Triage (Initial Assessment)
This step determines whether an alert is an actual threat (true positive) or a false alarm (false positive), prioritizing them by severity and impact. NIST SP 800-61 Rev. 3 notes that because the volume of potentially harmful events is generally extremely high, organizations must rely on technical mechanisms to filter massive event data (NIST SP 800-61 Rev. 3, 2025). This is the most volume-intensive, labor-depleting stage in a SOC and the primary driver of alert fatigue.
3. Analysis and Investigation
For suspicious alerts, analysts cross-reference logs to determine what happened, the scope of impact, and the phase of the attack. To grasp the complete picture of an attack that single alerts cannot reveal, log correlation analysis linking endpoints, authentication, and network logs is indispensable. Mapping results to MITRE ATT&CK helps clarify the attack's progress and the attacker's potential next steps.
4. Incident Response
Analysts execute or direct containment and eradication measures, such as network isolation of devices, account disablement, malicious file deletion, and IP blocking. Recovery is typically shared with IT departments or the CSIRT, requiring pre-established agreements on who has the authority to act and to what extent.
5. Threat Hunting
Instead of waiting for alerts, threat hunting is a proactive activity based on the hypothesis that attackers may already have breached the environment. Analysts query data stored in SIEM and EDR platforms to find traces of attackers that bypassed automated rules (Glossary: "Threat Hunting").
6. Reporting and Continuous Improvement
Daily and monthly reports visualize detection volume and response status to assist with executive briefings and compliance audits. Simultaneously, the SOC continuously tunes rules to reduce false positives, adds rules for new threats, and updates runbooks. NIST SP 800-61 Rev. 3 emphasizes that the need to feed lessons learned back into continuous improvement is more critical than ever (NIST SP 800-61 Rev. 3, 2025).
SOC Structures: Tier 1–Tier 3 Roles and Models
Roles of Tier 1, Tier 2, and Tier 3
Most SOCs divide tasks into tiers based on complexity and expertise. While not a formal standard, this structure serves as a common industry framework for staffing and outsourcing planning.
Tier 1 (Triage Analysts): Monitor alerts, perform initial triage, verify true/false positives using playbooks, and escalate verified threats to Tier 2. This tier contains the largest number of staff to support 24/7 shift coverage.
Tier 2 (Incident Responders): Conduct deep investigations into escalated events, determine the scope of impact, execute containment actions, and coordinate with the CSIRT and relevant departments.
Tier 3 (Advanced Analysts / Threat Hunters): Handle malware analysis, forensics, proactive threat hunting, detection rule engineering, and threat intelligence integration to elevate the overall capabilities of the SOC.
SOC Managers / SOC Engineers: Managers run operations and manage KPIs, while engineers build and maintain SIEM and EDR platforms to support the analysts.
The difficulty of maintaining this structure 24/7 in-house becomes clear even when looking at staffing a single Tier 1 seat. Accounting for shifts, time off, training, and turnover, one seat requires multiple employees. The total head count, including Tier 2, Tier 3, and management, easily exceeds the entire security budget of mid-sized organizations. Detailed costs and steps are discussed in "SOC Construction Costs and Steps." Trends and challenges in SOC staffing are also published annually in the SANS Institute SOC Survey (SANS, 2025).
In-House, Outsourced, and Hybrid Models
In-House SOC: The organization handles everything from monitoring to response with its own employees. This model allows decisions based on deep internal knowledge of workflows and infrastructure, keeping authority internal for faster speed and tighter control. However, the cost of 24/7 staffing, training, retention, and tool maintenance is a heavy burden.
Outsourced SOC (MSS/MDR): Monitoring, detection, and initial triage are delegated to a specialized provider. NIST SP 800-61 Rev. 3 notes outsourcing to Managed Security Service Providers as a viable operational model (NIST SP 800-61 Rev. 3, 2025). While this establishes night and weekend coverage quickly, external analysts lack business-specific context, often leading to a situation where "alerts are escalated, but internal staff must still handle the response overnight." Designing delegation scopes and response authority beforehand is critical.
Hybrid SOC: This model combines both approaches, such as running an in-house team during the day and outsourcing nights/weekends, or delegating Tier 1 monitoring to an external provider or AI while keeping Tier 2 and above in-house. For a detailed comparison of cost, talent, quality, and speed, see "In-House vs. Outsourced SOC (MSS/MDR)."
Primary Tools Used in a SOC: SIEM, EDR, SOAR, and Threat Intelligence
SIEM (Security Information and Event Management): A platform that aggregates logs across systems to detect and alert on threat indicators through correlation analysis. It is the core of SOC monitoring and analysis. For example, Microsoft Sentinel documentation organizes its core functions into four areas: collecting data across users, devices, applications, and infrastructure; detecting threats with analytics and threat intelligence; investigating threats with AI; and responding rapidly with built-in orchestration and automation (Microsoft Learn, 2026). For details, see "SIEM" in the glossary.
EDR (Endpoint Detection and Response): Software that monitors processes and network behaviors on PCs and servers, detecting anomalies and enabling actions like device isolation. Since most ransomware and targeted attacks execute on endpoints, EDR is a vital tool for detection and containment.
SOAR (Security Orchestration, Automation, and Response): A framework that automates repetitive workflows like gathering alert details, sending notifications, creating tickets, and isolating endpoints based on playbooks. It minimizes manual labor, freeing analyst time for complex investigations.
Threat Intelligence: Data regarding attacker infrastructure, malware signatures, and Tactics, Techniques, and Procedures (TTPs). It improves detection accuracy and assists analysts during triage. The common language for this is MITRE ATT&CK, a free, globally accessible knowledge base of real-world adversary behavior (MITRE ATT&CK, accessed 2026). Case management systems and internal knowledge bases also play critical roles in SOC operations.
Structural Limits of Traditional SOCs: Alert Volume, Talent Scarcity, Silos, and After-Hours Coverage
Traditional SOC models assume human analysts will review every alert. Today, this fundamental assumption has reached its practical limits.
Alert Volume and "Alert Fatigue"
As monitoring scopes expand, alerts increase. Because there is a physical limit to how many alerts Tier 1 analysts can investigate, many SOCs routinely leave lower-priority alerts unaddressed. In a Tines survey of 900 security professionals, 63% reported experiencing burnout, 81% stated their workload had increased over the past year, and 53% cited manual tasks as their biggest frustration. Crucially, over half indicated they might change jobs within the next year (Tines Voice of the SOC, 2023). For more, see "SOC Analyst Shortages and 'Alert Fatigue'."
Cybersecurity Talent Scarcity
According to the ISC2 "2024 Cybersecurity Workforce Study," while the global security workforce hovered around 5.47 million, the workforce gap reached approximately 4.76 million, a 19.1% year-over-year increase, with the largest shortfalls in Asia-Pacific and Europe. Additionally, 90% of respondents reported skills gaps within their teams, primarily due to budget constraints (ISC2, 2024). Recruiting experienced Tier 2 and Tier 3 analysts is incredibly difficult, and training takes time, leaving many security teams understaffed.
Silos and Knowledge Loss
Investigation quality often depends on a few senior analysts who possess deep context of the network environment. tribal knowledge, such as "this specific traffic on this server is normal," remains undocumented. When these individuals leave, detection accuracy and response speed suffer. Even when runbooks exist, keeping them updated is a constant struggle.
Nights and Weekends Coverage Gaps
Attackers do not operate on a 9-to-5 schedule. With faster attack execution, an intrusion starting on Friday night can easily lead to complete domain encryption by Monday morning. The reasons why human-centric coverage struggles during off-hours are analyzed in "Why Night and Weekend Security Operations Fail."
The cost of inaction is high. According to IBM's "Cost of a Data Breach Report 2026," the global average cost of a data breach rose to $4.99 million, a 12% increase year-over-year. The report also highlights that organizations leveraging AI and automation extensively in their security workflows reduced breach costs by $1.93 million compared to those that did not (IBM, 2026). Under the constraint of human limitations, security operations must be redesigned.
The AI SOC Alternative: Offloading Triage to AI Agents
AI SOC offers a new approach to these structural limits. While traditional SOAR executes pre-programmed playbooks, an AI SOC deploys AI agents that replicate the investigative workflows of senior analysts. These agents autonomously ingest alerts from EDR and SIEM, correlate logs, determine true/false positives, map scopes of impact, and recommend or execute containment actions. AI handles Tier 1 triage and most Tier 2 investigations 24/7 without interruption.
Yagura AI SOC aims to alleviate analyst burden and assist with response decisions through automated initial alert investigations. Organizations can validate the impact on investigation rates, manual analysis times, and resolution speeds using their own historical alerts and operational runbooks. Integrating with over 100 security tools (EDR, SIEM, IAM, etc.) and leveraging context memory to learn the unique nuances of an environment directly addresses the challenge of tribal knowledge and silos.
Critically, an AI SOC does not replace human analysts. By offloading initial and secondary triage to AI, humans can focus on high-value Tier 3 tasks: final containment approvals, cross-department coordination, proactive threat hunting, and detection engineering. In the Tines survey, 93% of respondents agreed that increased automation would improve their work-life balance (Tines Voice of the SOC, 2023). For architecture details, see "What is an AI SOC? Architecture, Traditional SOC Comparison, and Benefits."
Frequently Asked Questions
Q. How many analysts are needed to run a SOC?
This depends on the monitoring scope, coverage hours, and whether response action is taken in-house. Maintaining 24/7 human-only coverage requires multiple staff members per shift to account for rotations and leave, plus Tier 2/3 escalations and management. For mid-sized enterprises, outsourcing Tier 1 triage to external services or an AI SOC while keeping final decisions and response in a lean in-house team is the most practical model.
Q. Does deploying SIEM and EDR constitute a SOC?
No. SIEM and EDR are alerting tools. Without the staff (or AI) and processes to evaluate and act on those alerts, detections will sit unaddressed. Deciding who reviews alerts, when they review them, and how they respond is the baseline of a SOC.
Q. Do mid-sized enterprises need a SOC?
Yes, the need is growing. According to the National Police Agency, SMEs accounted for approximately 60% of ransomware victims in 2025 (National Police Agency, 2026). However, SMEs do not need to build enterprise-scale teams. Leveraging an AI SOC or external MSS for triage while keeping internal focus on final decisions and response is highly effective.
Summary
A SOC combines people, processes, and technology to continuously detect and respond to incidents within a vast volume of security events. Core tasks—monitoring, triage, analysis, response, hunting, and reporting—are executed across Tiers 1–3 using tools like SIEM, EDR, SOAR, and threat intelligence, operating under in-house, outsourced, or hybrid models.
However, human-centric traditional SOCs face severe limitations from alert volume, talent shortages, silos, and off-hours coverage gaps. Delegating initial investigations to AI agents allows human analysts to focus on decision-making and optimization. An AI SOC is a practical strategy to achieve the core goal of security operations—fast detection and containment—with limited headcount. Whether building a new SOC or optimizing an existing one, start by defining who responds, when they respond, and what actions they take.
Related Service: Learn more about "Yagura AI SOC," where AI agents autonomously investigate and respond to EDR and SIEM alerts 24/7/365.
References & Sources
NIST SP 800-61 Rev.3 "Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile" (2025): https://csrc.nist.gov/pubs/sp/800/61/r3/final (Full PDF: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf)
IPA "10 Major Information Security Threats 2026" (2026): https://www.ipa.go.jp/security/10threats/10threats2026.html
National Police Agency "Threat Trends in Cyberspace 2025" (2026): https://www.npa.go.jp/publications/statistics/cybersecurity/data/R7/R07_cyber_jousei.pdf
Mandiant (Google Cloud) "M-Trends 2026" (2026): https://cloud.google.com/security/resources/m-trends
IBM "Cost of a Data Breach Report 2026" (2026): https://www.ibm.com/reports/data-breach
ISC2 "2024 ISC2 Cybersecurity Workforce Study" (2024): https://www.isc2.org/Insights/2024/10/ISC2-2024-Cybersecurity-Workforce-Study
Tines "Voice of the SOC 2023" (2023): https://www.tines.com/reports/voice-of-the-soc-2023/
SANS Institute "SANS 2025 SOC Survey" (2025): https://www.sans.org/white-papers/sans-2025-soc-survey/
MITRE ATT&CK (Accessed 2026): https://attack.mitre.org/
Microsoft Learn "What is Microsoft Sentinel?" (Accessed 2026): https://learn.microsoft.com/en-us/azure/sentinel/overview



