# SOC

**What is a SOC?**

A SOC (security operations centre) is the team that receives incoming security alerts around the clock, assesses them and responds. It is the people behind the technology. We do not run one.

Up front, so you do not have to read on: vetosec does not run a SOC and does not offer a round the clock standby service. We build the monitoring a SOC needs, and for smaller businesses we help evaluate it during our business hours. If you need a guaranteed response at three in the morning, the route leads to a provider that specialises in it.

Tools such as a SIEM or protective software on the workstations produce alerts. An alert on its own achieves nothing. Someone has to read it, judge whether it is real and act when it counts, for example by taking a device off the network or locking an account. That is what a SOC does.

Attacks do not keep office hours. Encryption often happens at the weekend or at night, because nobody is looking then. The value of a SOC therefore lies in availability and in an agreed response time. Clarify in advance who is reachable and when, how quickly they respond, and which actions they may take without asking.

Running your own SOC pays off for very few businesses. Outsourcing to a provider that specialises in it is common. Make sure the alerts are assessed there. Forwarding without assessment simply moves the work back to you.

## Related terms
- [SIEM](https://vetosec.at/en/it-security/siem/)
- [Monitoring and logging](https://vetosec.at/en/it-security/monitoring-logging/)
- [IT emergency plan](https://vetosec.at/en/it-security/notfallplan/)
- [Antivirus and EDR](https://vetosec.at/en/it-security/edr-virenschutz/)

## Source
https://vetosec.at/en/it-security/soc/ (vetosec, schutz)
