Monday morning. You arrive at the office and your IT person says, with that look on their face: "Listen, they are asking us for a SOC in a tender". Or worse: you have already had a scare, looked into NIS2 and been told that without 24/7 monitoring you will not meet the requirements. And now you have to decide whether to build a SOC, outsource it or choose something in between.
Let’s make it clear without the smoke. What a SOC is, what it actually does, how it differs from MDR, MSSP and SIEM —terms that people often mix on purpose— and when it makes sense for a Spanish SME. With the specific information you need to make a decision.
What is a SOC in cybersecurity?
A SOC (Security Operations Center) is a unit —physical, virtual or hybrid— that combines people, processes and technology to continuously monitor, detect and respond to cybersecurity threats. Usually 24/7.
A useful analogy is the control tower at an airport: it does not fly the planes, but it makes sure they do not collide, coordinates the right people when there is an emergency and keeps everything under control. A SOC does not manage your infrastructure either. It monitors what happens inside it and activates protocols when something smells wrong.
In Spanish institutions it is also referred to as COS (Centro de Operaciones de Seguridad) or CSOC. It means the same thing. CCN-CERT defines it this way in its CCN-STIC 896 guide.
"A SOC IS NOT A TECHNOLOGY.
IT IS A TEAM THAT SUSTAINS A PROCESS."
What a SOC actually does, step by step
When a provider sells you a SOC, they are selling you a continuous five-stage process. Not a piece of software.
Continuous prevention
The SOC keeps critical assets inventoried, manages vulnerabilities, applies patches and updates policies. It does not wait for something to happen: it reduces the attack surface in advance, using threat intelligence on the campaigns currently active against your sector.
Detection and monitoring
This is where SIEM platforms come in —correlating events from multiple sources— and EDR/XDR tools monitor endpoints. Any anomaly triggers an alert: a login at 03:00 from an unusual IP, an unknown binary running, large outbound transfers. The SOC watches all of this non-stop.
Investigation and triage
Not every alert is an attack. The L1 analyst filters out noise. If it looks serious, it escalates to L2, who investigates the context. If the incident is complex, an L3 analyst takes over for proactive threat hunting and forensics.
Response and containment
When an incident is confirmed, the SOC activates the corresponding playbook: isolating compromised devices, cutting suspicious connections, invalidating credentials and preserving evidence. Speed is everything: ransomware contained in minutes costs a thousand times less than ransomware contained in hours.
Recovery and learning
After containment, systems have to be restored, persistence has to be ruled out and everything must be documented. The least visible but most valuable part: each incident updates the playbooks, detection rules and controls. So the same thing does not happen again.
The three pillars: people,
processes, technology
A SOC that does not balance all three is not a SOC. It is an expensive dashboard.
People
L1 analysts (triage, 24/7), L2 analysts (deep investigation), L3 analysts (incident response and threat hunting), plus a SOC manager and often detection engineers who fine-tune the rules. In SMEs using an outsourced SOC, this team sits with the provider, not on your payroll.
Processes
Playbooks by incident type, response SLAs (guaranteed times to acknowledge, contain and report), escalation matrices, communication protocols with the Spanish Data Protection Agency, CCN-CERT and INCIBE, and regulatory notification procedures —especially critical under NIS2, which requires significant incidents to be reported within 24 hours.
Technology
SIEM as the core (Splunk, Microsoft Sentinel, Elastic, Wazuh), SOAR to automate repetitive responses, EDR/XDR on endpoints (SentinelOne, Microsoft Defender for Business, Sophos), threat intelligence feeds and ticketing for traceability. Without technology there is no SOC. With technology alone, there is not one either.
SOC vs MDR vs MSSP vs SIEM: they are not the same
Almost every provider mixes these terms on purpose. They sound similar and they help sell. Knowing the difference saves you from overpaying or buying less than you think.
| Concept | What it is | What it includes | Who buys it |
|---|---|---|---|
| SOC | Function / organisational unit | People + processes + technology (everything) | Companies that want full operational cybersecurity capability |
| MDR Managed Detection & Response |
Outsourced commercial service | Detection + active response, focused on endpoints and network | SMEs and mid-sized companies that need 24/7 capability without building their own SOC |
| MSSP Managed Security Service Provider |
Managed security service provider | May offer SOC, MDR, managed firewall, pentesting, audits… | Companies that outsource security layers under contract |
| SIEM Security Information & Event Management |
Technology platform (software) | Log collection and correlation + alerts | Internal SOCs or providers that build detection on top of it |
Practical summary: a SIEM is a tool; a SOC is the team that operates it; MDR is a commercial product that outsources detection and response; an MSSP is the type of company that can sell you any of the above. When a salesperson says "we offer SOC", ask what is included. If it is only alerts, it is managed SIEM. If they respond technically, it is MDR. If they also govern risk and compliance, then yes: it is a SOC.
SOC models: internal, outsourced
or hybrid
Internal SOC (dedicated)
Your own team, your own infrastructure, your own tools. It makes sense for large accounts (+1,000 employees), highly regulated critical sectors (banking, energy, public healthcare) or companies with extreme confidentiality requirements. For a standard SME, it is extremely expensive: a minimally viable 24/7 SOC requires 6-8 analysts working in shifts.
Outsourced SOC (SOCaaS)
You contract the service from an MSSP. They provide analysts, technology and processes. You pay a monthly fee based on monitored devices or event volume. It is the dominant model for SMEs and mid-sized companies in Europe because it converts CAPEX into OPEX and gives you access to capabilities that would not be viable at your own scale.
Hybrid SOC (co-managed)
Your internal IT team handles day-to-day operations. The provider adds 24/7 monitoring, threat hunting and out-of-hours response. It is usually the most efficient model for companies with competent internal IT but no shift capacity. At IslaNet, it is the model we most often recommend for SMEs with 50-250 employees in the Balearic Islands.
Does your SME need a SOC? Four clear scenarios
Not every company needs a SOC. But if you are in one of these four scenarios, the question stops being "if" and becomes "how".
Your sector is covered by NIS2
If your company is an essential or important entity under NIS2 (energy, healthcare, transport, water, digital services, food, critical manufacturing), the regulation requires continuous detection and notification of significant incidents within 24 hours. Meeting that requirement without SOC capability, internal or outsourced, is technically impossible.
Your clients or suppliers are asking for it
More and more contracts with large accounts, public-sector tenders and supply-chain audits ask the same question: "how does your company monitor security incidents 24/7?". Being able to answer with a SOC —your own or outsourced— is the difference between winning the contract and being left out.
You have suffered an incident and do not want another one
After ransomware, a data breach or a serious CEO fraud attempt, most companies discover that they had no real visibility until it was too late. A SOC ensures that the next incident is detected before it causes damage.
You operate in a high-risk sector
Hospitality (PMS, POS, guest data), healthcare (special-category GDPR data), logistics, finance, law firms with professional secrecy. These are sectors where a successful attack is not a question of if, but of when. Early detection is survival.
How to choose a SOC provider: a practical checklist
If you have already decided to outsource, these are the seven criteria that separate a real SOC from one that only sells the badge.
Response SLAs written into the contract
Maximum time to acknowledge, analyse and contain by severity level. If the SLA is not in writing, it does not exist.
Real 24/7 coverage you can verify
Ask how many analysts are on each shift, where they work from and how they prove night-time coverage. A "24/7" SOC with two analysts in total is not 24/7.
Provider and team certifications
For the provider: ISO 27001, ENS, SOC 2. For the team: CISSP, GCIA, GCIH, OSCP, ISO 27001 Auditor.
Transparency around the technology stack
Which SIEM they use, which EDR they deploy, which intelligence feeds they consume. If they will not tell you, be suspicious: it is probably a wrapper on top of another provider.
Integration with your current stack
Microsoft 365, Google Workspace, ERP, CRM, firewalls, cloud. A SOC that cannot ingest logs from your core stack creates blind spots. And that is exactly where attackers will get in.
Executive reporting, not only technical reporting
Monthly reports that management can actually read: incidents detected, mean time to containment, maturity. If reporting is just a sheet full of alerts, management loses context and the SOC loses internal sponsorship.
Real response exercises
Regular tabletop exercises with management and at least one annual purple team. A SOC that never tests you leaves you not knowing whether it works until the worst has already happened.
FAQs
about SOCs
"We are small, no one is going to attack us"
Classic mistake. 43% of cyberattacks target SMEs precisely because they are usually less protected. For an attacker, a 50-person company with customer data can be worth as much as a small corporation. Being small does not protect you: it exposes you.
"We already have an IT person, why would we need a SOC?"
They are different things. Your IT person manages systems: making sure they work, stay up to date and allow people to do their jobs. A SOC monitors security 24/7 with specific tools and processes. They do not replace each other; they complement each other. A SOC usually works on top of the infrastructure your IT team already maintains.
What is the difference between a SOC and a NOC?
A NOC (Network Operations Center) monitors network availability: making sure everything works. A SOC monitors security: making sure no one is attacking. They often coexist and coordinate, but they are different teams, tools and objectives. Confusing them leads to thinking your IT provider already handles cybersecurity. That is not true.
Can I build an internal SOC with 2-3 people?
No, not with 24/7 coverage. A minimally functional internal SOC needs 6-8 analysts working in shifts just to guarantee continuous coverage, plus a SOC manager. For SMEs, the realistic path is an outsourced or hybrid SOC, where the provider supplies the shift team and you keep an internal owner.
What are SOC L1, L2 and L3 analysts?
L1 performs the initial triage of alerts and filters false positives. L2 investigates anything that looks suspicious, correlates events and escalates if it is a real incident. L3 handles complex incident response, digital forensics and proactive threat hunting. The career path starts at L1 and evolves with experience and certifications.
Does a SOC replace antivirus or firewall protection?
No, it uses them. The SOC is the layer that orchestrates and monitors the whole environment: it receives alerts from the EDR, firewall, email, identity, cloud and correlates them. Without antivirus and firewall, the SOC has nothing to monitor. With antivirus and firewall but no SOC, you generate alerts that nobody reviews.
Do you subcontract the SOC to another country?
At IslaNet, no. We manage the SOC from Palma with our own technicians. When a critical alert fires at 3 a.m., one of our technicians in Mallorca picks up —not an operator in another time zone and not a generic call centre.
Does NIS2 require every SME to have a SOC?
Not directly. NIS2 applies to essential and important entities with more than 50 employees or €10M in turnover in covered sectors, and to their critical suppliers. What it requires is continuous detection and notification within 24 hours, and in practice that almost always requires a SOC —internal or outsourced. If you are unsure whether it applies to you, we can validate it in a cybersecurity audit.
IF YOU NEED A SOC, LET’S TALK
If your company is considering hiring a SOC —internal, outsourced or hybrid— we can help you decide. No pressure sales. A short call is enough for us to understand your case, see which model fits your size and sector, and give you a realistic investment range.
