You are an entrepreneur or have overall responsibility within a business or organisation that works hard every day to grow. But how do you ensure your IT infrastructure is protected as well as possible? Setting up a SOC is a smart move to better protect your business against cyber threats. With a well-configured Security Operations Centre (SOC), you detect threats in real time and can act quickly before damage occurs. But how exactly does a SOC work, and what does it deliver? At SECWATCH, we have an advanced solution for this: SuperSOC, an efficient and cost-effective alternative to a traditional SOC
You increasingly hear worrying reports of cyberattacks on businesses and organisations. That is frightening, especially because this is not your area of expertise. You are concerned and wonder what practical steps need to be taken now.
How do you protect your organisation against something you cannot see or understand? And how do you ensure compliance with increasingly strict legislation?
Many entrepreneurs we speak to recognise this challenge. Where do you start, and whom can you trust?
You may already have heard of setting up or implementing a Security Operations Centre (SOC). But what exactly is it, and what can you do with it?
At SECWATCH, we help medium-sized and larger SMEs protect themselves against costly cyber threats and meet the required compliance standards.
We map where your business is at risk so the organisation can take measures to limit the damage and then prevent it. One solution is to set up a SOC or our unique SuperSOC. It is important to know that these are two different things, which we discuss later.
What makes our team unique is that we work with ethical hackers. They look at threats and cyber risks from a hacker's perspective. For this article, we asked our experts to provide technical input.
With this article, we want to provide clarity so you know exactly where you stand.
Specifically, we cover:
- What exactly is a SOC, and how does it differ from the SuperSOC we offer?
- Why do we recommend a SOC, and in which situations?
- What does a SuperSOC cost?
What is a Security Operations Centre (SOC)?
SOC stands for Security Operations Centre. This is a central place where SOC analysts actively monitor an IT environment.
A SOC is equipped with tools that collect data and information. As soon as a deviation is detected in that data, an alert follows because it may indicate a possible cyberattack.
As you can see, a SOC has two basic components: a technical component and a human component. The technical component concerns setting up the SOC with tools that collect security information and data.
The human component consists of the security experts responsible for interpreting that data and taking action.
You can compare a SOC to a guard dog. Imagine you have a beautiful house containing valuable possessions that would interest burglars. Naturally, you want to protect those possessions properly.
A good guard dog responds to every deviation or strange noise by barking or growling. If the dog sounds the alarm in the middle of the night, you investigate what is happening yourself, or call the police or a security company to take action.
A SOC functions as a security monitoring centre, a guard dog for your digital business data and the continuity of your operations. To hackers, this data is worth its weight in gold. They can use it to blackmail and pressure you, or trade the data.
Cybercriminals use very subtle ways to enter your systems, methods you do not know yourself. That is why setting up a Security Operations Centre is essential for proactive security. A good Security Operations Centre addresses this by raising alerts when suspicious activities occur.
That is the simple explanation of what a SOC is. But as you will understand, it sounds simpler than it is: quite a lot is involved.
How does a SOC work, and why is setting one up important?
Imagine a hacker trying to gain access to the company network by sending malware in an email to an employee.
With a properly configured Security Operations Centre (SOC), this attempt is detected and you receive an alert that allows you to take immediate action.
Without a SOC, it might go unnoticed, and the consequences could be disastrous.
Your business is therefore vulnerable and constantly a possible victim of potential attacks. Without proactive monitoring, many of these attacks remain under the radar until they have already spread. By then, it is too late.
A SOC ensures you are always one step ahead of cybercriminals by detecting threats early, allowing you to take immediate action. This means not only that your business is safer, but also that you have greater peace of mind and confidence because you know someone is always watching.
Increasingly strict regulation
Setting up a SOC helps your business comply with increasingly strict regulations on data protection, continuity of critical business operations and privacy, such as the GDPR (General Data Protection Regulation), NIS2 and DORA.
Real-time monitoring and reporting mean you always have control over your security and can demonstrate that you have taken the right measures to protect your customers and business operations.
EU legislation is becoming increasingly strict, for example with the introduction of NIS2.
NIS2 legislation (Network and Information Security Directive 2) aims to increase digital resilience and sets strict cybersecurity requirements, particularly in sectors such as energy, transport, healthcare and digital infrastructure. Businesses must comply with strict rules, including monitoring and reporting cyber incidents, often within 24 hours
How does a SOC work, and why is setting one up essential?
A SOC is the centre of all digital signals within your business. Every piece of data entering or leaving the network, every login attempt, every action, all network traffic and user behaviour are closely monitored. The National Cyber Security Centre (NCSC) provides practical guidelines on how to set up a SOC effectively to increase your digital resilience.
One of the most important functions of a SOC is that it is always active, even while you are asleep or away from the office. Cybercriminals do not rest, so systems are continuously monitored through the SOC.
You can compare it to a fire alarm: the alarm sounds at even a small sign of smoke. But not every cloud of smoke means a fire. The SOC filters out false alarms and assesses the severity of the threat, so you intervene only when it is genuinely necessary to prevent a major fire.
Sounds good, but how do you interpret a SOC's signals?
Setting up a SOC is the first step in the process. This is done using various tools. Once it is set up, the foundation is ready. When something threatens to go wrong or something alarming happens, you receive an alert. But that is not enough: those alerts must actually be acted on.
This is where the human component of a SOC comes in. It is good that signals are generated, of course, but how do you interpret them?
Compare it to an alarm monitoring centre watching your home. When the alarm sounds, you need people to take action and interpret it correctly. It is not the monitoring centre that comes to your home when something happens, but the police you call after the alert.
This is exactly what happens in a SOC. An incident occurs, and experts are then needed to interpret the signals, advise and, where necessary, take action.
A SOC therefore involves security experts and specialists who continuously monitor these signals and intervene when needed.
It is crucial that signals are assessed correctly. A small signal can be the start of a snowball effect with major consequences.
This means you cannot simply label a “low risk” alert unimportant. The impact can be very significant if it is not interpreted correctly.
Correct interpretation of information matters greatly. The impact of an error or misinterpretation can be enormous. You do not want people without the right knowledge and experience in your organisation to be responsible for essential security tasks.
How do you set up a Security Operations Centre?
A SOC uses various tools and systems to locate incidents. All these tools collect data from different sources within your network, such as firewall logs, Microsoft 365, Entra ID, LDAP, antivirus systems and email servers.
When you look into a SOC and its associated tools, you encounter terms such as XDR, MDR, SIEM, threat intelligence and endpoints.
You do not immediately need to know every detail, but we can briefly explain what they mean.
SIEM: Security Information & Event Management
SIEM stands for Security Information & Event Management. SOC and SIEM are often inseparably linked. SIEM is the system that collects information and data from different sources within the IT infrastructure.
This is essential because it gives immediate insight into what is happening at that moment. The data collected through SIEM is then analysed and interpreted by specialists in the Security Operations Centre.
Building layers of security
Think of building different security layers as lines of defence. This starts with protecting devices such as computers, laptops and smartphones. There is also network security, which protects the internal network, and it is possible to combine the information from these two layers.
Looking at the first line of defence, it is important to realise that every device connected to the network and/or the internet is a potential entry point for attackers. Implementing endpoint security solutions such as antivirus software, endpoint detection and response (EDR) and firewalls prevents hackers from gaining access, while also allowing the right information to be collected.
Network security
Network security focuses on protecting the internal network itself. This goes beyond firewalls and also includes Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), VPNs (Virtual Private Networks) and network segmentation. In short, you want to prevent unauthorised parties from gaining access to your network.
MDR and XDR
You can also combine different security layers with XDR and MDR. XDR stands for Extended Detection and Response. This is a security solution that can collect and analyse data from many security layers, such as endpoint detection and response solutions, firewalls, IDS and IPS, as well as network traffic (NDR).
This combined information makes rapid intervention possible because you can make the right connections. XDR can monitor email, network login attempts and activity on an employee's computer, provided these sources are integrated into the XDR platform. This could allow you to address the problem at its source.
Unlike a SOC with a SIEM, which collects and correlates a wide range of log sources, XDR focuses mainly on endpoints, networks and cloud integrations. A SOC offers more flexibility and customisation.
MDR: Management Detection Response
MDR stands for Managed Detection and Response. This is a service in which an external team of security experts monitors your business 24/7 and helps respond to threats. These experts watch your systems, analyse suspicious activities and respond quickly when something goes wrong.
As you can see, the Security Operations Centre combines the right experts with the right tools to prevent you from becoming the victim of a cyberattack.
But which tools should you use?
This is not a question we can answer offhand. It is exactly why SECWATCH always provides a tailored service. We always give tailored advice, as every organisation has its own threat landscape and a different starting point. What matters to us is helping customers make the right choice.
There are often overlaps or blind spots in security. You may think an XDR solution gives you complete coverage, only to find that a SIEM/SOC solution would still be a very valuable addition.
A SOC with a SIEM can collect and analyse more log sources than an MDR or XDR solution, which is often limited to endpoints and a few network sources.
Some organisations are looking for MDR, XDR or SIEM/SOC without realising that they are missing certain elements. This is an important point we watch for: even if you think you are well protected, something may still be missing. For organisations that want to deploy an effective security solution quickly, an alternative such as Rapid7's InsightIDR can be a smart choice.
We help build the complete picture: what do you have now, and what is still missing?
SECWATCH's SuperSOC
When faced with the decision to set up a SOC, it can be quite overwhelming. Which tools do you choose, how do you configure them and which providers do you obtain them from?
Is it already becoming too much? That is perfectly understandable.
Too often, we see organisations choose complicated arrangements involving tools they have no idea how to use or what they actually do.
Remember: you can buy a machine for a million, but if nobody knows how it works, it is of no use.
Or put another way: if you build a factory to make Teslas but only have experience with BMWs, you have a beautiful factory without the right knowledge in-house.
There is no direct relationship between the size of your investment and cybersecurity. Nor is there a direct relationship between the number of tools and security.
In other words, you can deploy an enormous number of tools, but if they make no direct contribution, they undermine the process rather than increase security.
So how should you do it?
By working with experts who understand what is happening. That is why we work with a SuperSOC at SECWATCH: a Security Operations Centre (SOC) without sky-high costs, always tailored to your needs.
With a traditional SOC, you often receive a warning only when something is already going wrong. There is nothing inherently wrong with that, but you must then act immediately to resolve the problem. This alert often comes just before a critical incident occurs. That is just in time, but also just before things threaten to go seriously wrong.
With the SuperSOC we offer, we work much earlier in the process. You receive preventive signals that allow you to intervene in time.
That is not all: a standard SOC is often configured and delivered without additional services.
The big question then is:
- Who analyses the incidents and reports? Would you like us to handle this entirely, or should we train your team to carry out analyses independently? Which would you prefer?
- How do we ensure we can analyse and respond effectively together? We take the lead as cybersecurity experts, while you and/or your IT provider contribute knowledge of business processes and network structure. How can we shape this cooperation most effectively?
- Are the tools you use configured correctly? (We sort that out for you.)
- Who monitors everything that happens across the board? (We are happy to do that for you.)
Is your security really in order?
Many business decision-makers think their security is in order when they do not really understand how the system works.
They are sometimes required to meet certain standards without knowing exactly what that means.
We make sure you know exactly where you stand and guide you through the entire process. This gives you a sense of certainty and control.
Outsourcing the SOC
In our view, it is sensible to outsource setting up your SOC to a party that does this every day. For example, we can help by handling alerts promptly, assigning actions and suggesting improvements.
We train and coach your employees rather than acting only as the last safety net when things are about to go wrong. Of course, it is good to receive a warning then, but so much happens before that which we can address together.
Always tailored
When an organisation decides to work with us, we always start with a thorough analysis of the current situation. For example, we examine which systems are running, the greatest risks and the changes needed to keep everything running smoothly.
We also incorporate the threat landscape into our approach. This helps us configure and fine-tune monitoring so we can target relevant risks.
This is a crucial step, because without these insights it is difficult to take the right actions. With this approach, we ensure you not only solve problems but also raise your security to a higher level.
This process is entirely tailored. We work alongside you to examine what is already running, what needs monitoring and which threats matter.
Which smart choices do you make? It is not a matter of setting it up and leaving it, but of continuous coordination and fine-tuning. You want the right information to appear when a trigger fires, so you know what needs to happen.
Analysing an alert
In practice, we analyse alerts to determine whether they require action. This process is called triage. We investigate whether alerts relate to a threat and whether there is a clear pattern.
When something is genuinely wrong, we gather relevant context, for example from endpoints and logs, to establish whether the activity is or could become malicious.
You are informed of suspicious or malicious activity through our Signal group or by telephone, depending on the incident's severity. Where necessary, we request additional information (Request For Information, RFI) to complete the investigation.
This is followed by a deeper analysis. We establish exactly what happened, what caused it and what followed.
It is an ongoing process of monitoring, interpretation and assigning actions together with the organisation to get ahead of problems or address them immediately when needed.
The use of ethical hackers
An important difference between a standard SOC and the SuperSOC we offer is that we work with certified ethical hackers who are also responsible for the SOC services.
This means they can think like real hackers, allowing them to see things others do not.
This contrasts with a standard SOC, which usually employs analysts at different experience levels, junior, mid-level and senior, without the same practical experience.
Setting up a Security Operations Centre: key insights
As you have read, the possibilities are endless. Making the right choices may seem complicated, but with the right explanation from an expert, it is manageable.
In essence, you should not have to worry about the technical configuration of systems, but you do need to understand what is happening.
That is exactly what matters to us at SECWATCH. We work through things with you and make all the information practically usable. We cooperate at the highest level with the Dutch government and cybersecurity specialists.
We are happy to put that knowledge to work for your organisation.
Would you like to know how setting up a SOC makes your business safer? Contact our experts and discover how we can help you establish an effective Security Operations Centre.
