Insights

What is a Security Operations Centre (SOC)?

Last updated: June 2026 | Article orginally published in 2019.

TL;DR: What is a SOC?

A Security Operations Centre (SOC) is a team of security analysts who monitor your IT environment around the clock, detect threats, and respond before damage is done. For most UK businesses, the choice is between outsourcing to a managed SOC service or building one in-house. However, the cost difference is substantial, making it unrealistic for most SMBs to build their own. This article covers what a SOC does, how managed SOC services work, and what to look for when choosing a provider.

What is a Security Operations Centre (SOC)?

A Security Operations Centre (SOC) is a dedicated team, with security tooling and a set of processes that focus on monitoring IT environments for threats and responding when something is detected. Sometimes, this is also referred to as a Cyber Security Operations Centre (CSOC).

The team monitors activity across various IT environments, usually on a 24/7 basis, with the goal of catching threats and attacks early, and remediating them before they become incidents that could harm the business.

A SOC can either be an in-house function or outsourced to a Managed Security Services Provider (MSSP). An MSSP that offers SOC-as-a-service, provides security monitoring, detection and response on behalf of your business. This is commonly known as a managed SOC service, which includes managed cyber security services such as MDR (Managed Detection & Response) and MXDR (Managed Extended Detection & Response).

What does a SOC do?

A SOC collects data from across your environment e.g. logs, alerts, and signals from endpoints, email, identity systems, and applications, and uses that data to spot unusual or suspicious activity.

When something is flagged, analysts investigate. They work out whether it’s a genuine threat or a false positive, assess the scope and potential impact, and either take action directly or advise your team on next steps.

That response can include actions such as isolating an affected device, blocking a compromised account, or containing a threat before it spreads.

The core functions of a SOC are:

  • Continuous monitoring: Monitoring your environments 24/7 for suspicious activity
  • Alert triage: Filtering genuine threats from noise
  • Investigation: Building a clear picture of what happened, how, and why
  • Response and containment: Remediating vulnerabilities or acting to stop a threat or attack from gaining access to systems or spreading
  • Reporting: Giving you visibility of incidents, trends, and your overall security posture

Why security is central to modern IT

IT and security used to be treated as distinct disciplines, which simply isn’t logical or workable. Every device, application, and user account in your business is a potential entry point for an attacker; The way your team works across cloud applications, remote access, Microsoft 365 etc. all creates an attack surface that has to be actively managed, not periodically reviewed.

Security is the first and last consideration in everything.

David Howell, Head of Infrastructure, Chorus

For most businesses, keeping that level of vigilance in-house around the clock isn’t feasible with the everyday demands of IT. That would require your IT team upskilling in complex areas of cyber security, while you’d need to hire more people to work overnight to ensure 24/7 coverage.

A managed SOC service is how many UK organisations are filling this gap, bringing continuous, expert-led monitoring, detection and response to their environments without the unrealistic overhead of building it themselves.

Why is 24/7 monitoring so important for SOC services?

Cyber attacks exploit vulnerabilities, and you’re always going to be more vulnerable when there’s no one keeping watch overnight. According to research by Semperis (2025), 52% of ransomware attacks take place on weekends or public holidays, when staffing is thinner and response times are slower.

A gap of even a few hours in monitoring can be enough for an attacker to move through a network undetected. The average cost of a significant cyber attack on a UK business is almost £195,000, according to KPMG research published by the UK Government in 2025. For many SMBs, that figure alone is usually enough to make the decision easier.

The UK is one of the most frequently targeted countries globally for cyberattacks, according to Microsoft’s Digital Defense Report 2025. The same report found that most attacks are financially motivated, e.g. ransomware, extortion, and data theft, rather than targeted espionage.

For SMBs, that is why the “we’re too small to be targeted” argument is a false one. Financially motivated attackers look for accessible targets, not high-profile ones, and that’s often the UK’s small and medium sized businesses, who often don’t invest enough in their security.

Outsourced SOC vs in-house SOC

Building your own SOC in-house is an option, but it’s one few SMBs could afford. You’d need a team of experienced security analysts available around the clock, the tooling to ingest and process security data at scale, and the processes to act on it quickly.
The recruitment issue alone is enough to put most companies off, because cyber security remains one of the hardest technical disciplines to hire for.

According to the ISC2 2024 Cybersecurity Workforce Study, the global shortfall is around 4.8 million professionals, while in the UK, the government’s own research (DSIT, 2025) estimates a net annual shortfall of approximately 3,800 people in cyber security, with a minimum of 12,900 individuals needed each year but only 9,100 entering the workforce.

Outsourcing to a managed SOC provider gives you access to that capability without carrying the full cost internally. According to Kaspersky (2026), 64% of companies plan to outsource part of their SOC, and 26% plan to fully adopt a SOC-as-a-Service model. Only 9% plan to build entirely in-house.

For most SMBs, deciding which provider to trust as your SOC provider will be the key security decision to make, not whether to outsource or not.

What technologies does a SOC use?

The tooling varies between providers, but most enterprise-grade SOCs are built around two core platforms: a Security Information and Event Management (SIEM) system, which aggregates and analyses log data from across the environment, and an Extended Detection and Response (XDR) platform, which correlates signals across endpoints, identities, and applications to detect and respond to threats.

At Chorus, our Cyber Security Operations Centre (CSOC) is built on Microsoft Sentinel (as the SIEM and Security Orchestration, Automation and Response (SOAR) platform) and Microsoft Defender XDR. All data stays within your Microsoft tenant. There are no third-party agents to deploy, and no data leaves your environment for processing elsewhere.

We have built our SOC on Microsoft technologies as Microsoft Security is a world leader in cyber security, with unparalleled threat intelligence, processing 100 trillion security signals every day and screening around 5 billion emails daily for malware and phishing.

When a new threat pattern emerges anywhere across that global footprint or Microsoft customers, Microsoft’s cloud protection adapts and your environment benefits.

Our service uses these tools and advanced capabilities to help our customers benefit and stay protected.

What should a managed SOC service include?

Alerting and response are different. Some providers surface alerts and leave your internal team to act on them. A well-structured managed SOC service should include full response capability beyond alerting.

Ask any prospective provider you engage with what they do when a threat is confirmed.
Can they isolate a device, block compromised accounts, contain threats without requiring your team to act first? Do they have automated remediation in place to instantly take action without or before human review and intervention?

Beyond the detection and response capabilities themselves, also look for:

  • Defined SLAs: Response times should be contractual with clear SLAs.
  • Fast response times: Beyond SLAs, look for metrics that provide evidence of speed, which is critical to effective security. Our SOC at Chorus has a mean time to acknowledge (MTTA) of under 5 minutes and a mean time to close (MTTC) of under 20 minutes, some of the fastest times in the industry.
  • Human analysts alongside automation and AI: While automation improves speed and efficiency, human judgement is key for complex or novel threats. Around 50% of incidents in our CSOC are closed through automation; the rest involve analyst review. Both are needed for a comprehensive SOC service.
  • Structured reporting: You should receive regular reports on incident activity, SLA performance, and recommendations, rather than a list of alerts in a dashboard. Ask how reporting and touch points with your provider will work, and whether it can be tailored to a cadence that suits you and your team.
  • A named service contact: A Service Delivery Manager who knows your environment and can discuss risks and improvements with you regularly is key to a high quality SOC service. Ask how this will work and how they are there to support you.

What’s the difference between MDR and MXDR?

You’ll often see managed SOC services described as either Managed Detection and Response (MDR) or Managed Extended Detection and Response (MXDR). The difference is coverage.

Managed Detection and Response (MDR):

MDR covers less than MXDR e.g. endpoints and identities. The scope of coverage will vary between providers. But it’s usually going to be focused on the most common entry points for attacks. At Chorus, our MDR offering is typically a good fit for organisations that just want to protect endpoints and identities, which we can do with Microsoft 365 Business Premium or Defender for Endpoint P2.

Managed Extended Detection & Response (MXDR):

The “extended” phrasing in MXDR reflects how it extends that protection across a wider range of environments, including identities, devices, email, cloud apps, infrastructure, data and networks. MXDR has many benefits, giving you comprehensive detection and response coverage throughout your IT estate. At Chorus, we use the Microsoft Defender Suite to[LT3.1] give analysts a wider view of your environment.

If you’re still not clear, we’ve covered this in more detail in our article the differences between EDR vs XDR vs MDR vs MXDR.

If you’re not sure which applies to your situation, that’s a good question to discuss with your MSSP. Your Microsoft licensing may already give you a lot of the tools you need for such a service, meaning you just need to pay for the service on top.

How does the Chorus SOC work?

The Chorus SOC delivers 24/7 MDR and MXDR services built entirely on Microsoft Sentinel and Defender XDR. There are no proprietary platforms or additional agents and everything runs within your Microsoft environment.

When a threat is detected, our analysts investigate and respond directly. That can include isolating affected devices, blocking compromised accounts, and containing threats before they spread. We also carry out proactive threat hunting, looking for threats that haven’t yet triggered an alert. Custom detection rules and automated playbooks are built for each customer, so the service is tuned to your environment.

We also advise you on your cyber security strategy, and can support security hardening and consulting projects to implement best practice security architectures aligned to zero trust security principles.

Chorus holds membership of the Microsoft Intelligent Security Association (MISA) and Microsoft Verified MXDR Solution status — both require direct validation of architecture, automation, reporting, and response capability by Microsoft.

By working with Chorus as our strategic security partner, we feel confident that we are making best use of Microsoft technologies with a Zero Trust security model.

Jason Kane, Global IT Director, Buro Happold

Talk to Chorus about managed SOC services

Chorus is a Microsoft-focused MSP and MSSP, delivering 24/7 managed cyber security services through our own Security Operations Centre (SOC), as well as managed IT services and a range of professional services including cyber security.

We’re a member of the Microsoft Intelligent Security Association (MISA), hold Microsoft Verified Managed XDR Solution status, and carry Microsoft Solutions Partner designations in Security and more, with advanced specialisations in Cloud Security and Threat Protection.

Our mean time to acknowledge threats is under five minutes, and our service is built entirely on Microsoft Sentinel and Defender XDR — so your data stays in your environment.

Frequently asked questions (FAQs)

What is the difference between a SOC and a CSOC?

A CSOC (Cyber Security Operations Centre) is simply a named variation of a Security Operations Centre (SOC).

What does a Security Operations Centre monitor?

The exact scope depends on the provider and service tier. Good SOCs will monitor activity across your endpoints (laptops, desktops, servers), identities, email, applications, and network traffic. More basic SOCs or lower service tiers might just monitor endpoints, leaving gaps in coverage elsewhere.

What is SOC as a service (SOCaaS)?

SOC-as-a-service (referred to as SOCaaS) is a managed security model where an external provider delivers the SOC function behalf of your business. Rather than building and staffing your own SOC, you pay an ongoing fee as part of a contract, which gets you continuous monitoring, detection, and response from a dedicated team. It gives SMBs access to enterprise-grade security and expertise without the overhead of running it in-house.

How much does a SOC cost for a UK business?

Managed SOC pricing varies by provider, service tier, and the size of your environment. Most managed SOC services are priced per user per month, which keeps costs predictable and scales with your business. Enquire with an MSSP and you may find reductions in the per user cost if you commit to longer contract terms, which typically range from one to three years.

Do I need a SOC if we’ve already achieved Cyber Essentials or invested in security tools?

Cyber Essentials and advanced security tooling will cover many of the core foundations such as patching, access controls, malware protection, but they’re largely preventative. They reduce your attack surface, but they don’t necessarily provide continuous monitoring or active response if something gets through (which is always a possibility and why Zero Trust guidance recommends an “assume breach” mindset). A SOC watches your environment around the clock, investigates alerts as they happen, and responds before a threat can spread. For organisations that have already done the groundwork on Cyber Essentials or security software deployment, a managed SOC service is often the next logical step and can build on your initial groundwork.