Safeguards
SOC
What is a SOC?
A SOC (security operations centre) is the team that receives incoming security alerts around the clock, assesses them and responds. It is the people behind the technology. We do not run one.
Up front, so you do not have to read on: vetosec does not run a SOC and does not offer a round the clock standby service. We build the monitoring a SOC needs, and for smaller businesses we help evaluate it during our business hours. If you need a guaranteed response at three in the morning, the route leads to a provider that specialises in it.
Tools such as a SIEM or protective software on the workstations produce alerts. An alert on its own achieves nothing. Someone has to read it, judge whether it is real and act when it counts, for example by taking a device off the network or locking an account. That is what a SOC does.
Attacks do not keep office hours. Encryption often happens at the weekend or at night, because nobody is looking then. The value of a SOC therefore lies in availability and in an agreed response time. Clarify in advance who is reachable and when, how quickly they respond, and which actions they may take without asking.
Running your own SOC pays off for very few businesses. Outsourcing to a provider that specialises in it is common. Make sure the alerts are assessed there. Forwarding without assessment simply moves the work back to you.
All terms in the knowledge base
Note: This entry reflects the state of knowledge to the best of our understanding and serves as general orientation. It is not legal advice. What counts is always the version currently in force at the responsible body, for example dsb.gv.at, nis.gv.at or enisa.europa.eu.
From the term to practice
Where does your business actually stand?
The IT Check reviews your IT across 8 audit areas with more than 100 individual checks and delivers documented findings with a prioritised action plan. From 1,299 € excl. VAT. The first call takes 20 minutes and carries no charge.