Mycelium 365 — Managed IT, Microsoft 365 and Azure across Australia, New Zealand and the United States
    Security operations

    Security Operations Centre (SOC)

    A security operations centre is the team and tooling responsible for monitoring, detecting, investigating and responding to security events. It combines analysts, a SIEM or XDR platform, and documented response procedures, and for most mid-sized organisations it is delivered as a managed service rather than built in-house.

    What Security Operations Centre (SOC) means in practice

    A SOC exists because detection technology produces signals, not decisions. Somebody has to judge whether an impossible-travel sign-in was an attacker or an executive using a VPN, isolate a device at 3am, and know when an incident crosses the threshold that triggers notification obligations. That judgement, available continuously, is what a SOC provides.

    The functions are consistent regardless of size. Monitoring ingests telemetry from identity, endpoint, email, network and cloud platforms. Triage separates noise from signal and assigns severity. Investigation reconstructs what happened, which accounts and devices were involved, and whether data was accessed or exfiltrated. Response contains the incident — disabling accounts, isolating endpoints, blocking senders — and then recovers. Threat hunting looks proactively for activity no alert fired on. Reporting closes the loop with root cause and control improvements.

    Building this internally requires around the clock rostering, which in practice means six to eight analysts before you have covered leave and turnover. For most Australian mid-market organisations that is not economic, which is why the capability is usually bought as a managed detection and response or managed SOC service.

    When comparing providers, the questions that separate them are operational rather than technical. What is the contracted time to acknowledge and to contain, and are those measured or aspirational? Does the service have delegated authority to isolate a device without waiting for approval at 3am, and if not, who does? Does it cover identity and email or only endpoints? Is threat intelligence tuned to Australian targeting? Who writes the incident report, and will it satisfy an insurer or a regulator?

    A SOC does not replace preventative controls. Detection is the layer that assumes prevention failed, which is exactly what a Zero Trust posture expects. Organisations that buy monitoring before fixing multi-factor authentication and privileged access are usually paying to watch a problem they could have removed.

    How we help with this

    Related terms

    Back to the full glossary

    Ready to simplify and secure your technology?

    Book a free, no-obligation Discovery Call to talk through your Microsoft 365, Azure, security, or support needs — no sales pitch, just a straight conversation.

    We respond to every enquiry within 4 business hours. Monday to Friday, 7am–7pm AEST.