{"id":8291,"date":"2026-04-23T13:43:44","date_gmt":"2026-04-23T11:43:44","guid":{"rendered":"https:\/\/www.islanetworks.com\/?p=8291"},"modified":"2026-07-07T11:35:15","modified_gmt":"2026-07-07T09:35:15","slug":"soc-cybersecurity-for-smes","status":"publish","type":"post","link":"https:\/\/www.islanetworks.com\/en\/blog\/soc-cybersecurity-for-smes\/","title":{"rendered":"SOC in Cybersecurity: What It Is, How It Works and When It Makes Sense for a Spanish SME"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"8291\" class=\"elementor elementor-8291 elementor-8290\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-54f08f4 e-flex e-con-boxed e-con e-parent\" data-id=\"54f08f4\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e24791f elementor-widget elementor-widget-html\" data-id=\"e24791f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<!-- ============================================================ -->\r\n<!-- NARRATIVE INTRO (IslaNet blog style: direct and human)       -->\r\n<!-- ============================================================ -->\r\n\r\n<p>Monday morning. You arrive at the office and your IT person says, with that look on their face: <em>\"Listen, they are\r\n        asking us for a SOC in a tender\"<\/em>. Or worse: you have already had a scare, looked into NIS2 and been told that\r\n    <strong>without 24\/7 monitoring you will not meet the requirements<\/strong>. And now you have to decide whether to build a SOC,\r\n    outsource it or choose something in between.\r\n<\/p>\r\n\r\n<p>Let\u2019s make it clear without the smoke. What a SOC is, what it actually does, how it differs from <strong>MDR, MSSP and\r\n        SIEM<\/strong> \u2014terms that people often mix on purpose\u2014 and when it makes sense for a Spanish SME. With the\r\n    specific information you need to make a decision.<\/p>\r\n\r\n<!-- ============================================================ -->\r\n<!-- H2 \u00b7 WHAT IS A SOC                                          -->\r\n<!-- ============================================================ -->\r\n\r\n<h2>What is a SOC <span class=\"isla-red-color\">in cybersecurity?<\/span><\/h2>\r\n\r\n<p>A <strong>SOC<\/strong> (<em>Security Operations Center<\/em>) is a unit \u2014physical, virtual or hybrid\u2014 that combines\r\n    <strong>people, processes and technology<\/strong> to continuously monitor, detect and respond to cybersecurity\r\n    threats. Usually 24\/7.<\/p>\r\n\r\n<p>A useful analogy is the <strong>control tower at an airport<\/strong>: it does not fly the planes, but it makes sure\r\n    they do not collide, coordinates the right people when there is an emergency and keeps everything under control. A\r\n    SOC does not manage your infrastructure either. It monitors what happens inside it and activates protocols when\r\n    something smells wrong.<\/p>\r\n\r\n<p>In Spanish institutions it is also referred to as <strong>COS<\/strong> (<em>Centro de Operaciones de Seguridad<\/em>) or\r\n    <strong>CSOC<\/strong>. It means the same thing. CCN-CERT defines it this way in its CCN-STIC 896 guide.\r\n<\/p>\r\n\r\n<!-- ============================================================ -->\r\n<!-- CENTERED EDITORIAL QUOTE (IslaNet landing pattern)           -->\r\n<!-- ============================================================ -->\r\n\r\n<blockquote class=\"cita-editorial\">\r\n    \"A SOC IS NOT A TECHNOLOGY.<br>\r\n    IT IS A TEAM THAT SUSTAINS A PROCESS.\"\r\n<\/blockquote>\r\n\r\n<!-- ============================================================ -->\r\n<!-- H2 \u00b7 WHAT A SOC DOES                                        -->\r\n<!-- ============================================================ -->\r\n\r\n<h2>What a SOC actually does, <span class=\"isla-red-color\">step by step<\/span><\/h2>\r\n\r\n<p>When a provider sells you a SOC, they are selling you <strong>a continuous five-stage process<\/strong>. Not a piece of\r\n    software.<\/p>\r\n\r\n<!-- Numbered blocks IslaNet style -->\r\n<div class=\"isla-numbered-grid\">\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">01<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Continuous prevention<\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">The SOC keeps critical assets inventoried, manages vulnerabilities,\r\n            applies patches and updates policies. It does not wait for something to happen: <strong>it reduces the attack\r\n                surface in advance<\/strong>, using <em>threat intelligence<\/em> on the campaigns currently active against\r\n            your sector.\r\n        <\/p>\r\n    <\/div>\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">02<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Detection and monitoring<\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">This is where <strong>SIEM<\/strong> platforms come in \u2014correlating events\r\n            from multiple sources\u2014 and\r\n            <strong>EDR\/XDR<\/strong> tools monitor endpoints. Any anomaly triggers an alert: a login at 03:00 from an\r\n            unusual IP, an unknown binary running, large outbound transfers. The SOC watches all of this\r\n            <strong>non-stop.<\/strong>\r\n        <\/p>\r\n    <\/div>\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">03<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Investigation and triage<\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">Not every alert is an attack. The <strong>L1<\/strong> analyst filters out\r\n            noise. If it looks serious, it escalates to\r\n            <strong>L2<\/strong>, who investigates the context. If the incident is complex, an <strong>L3<\/strong>\r\n            analyst takes over for proactive <em>threat hunting<\/em> and forensics.\r\n        <\/p>\r\n    <\/div>\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">04<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Response and containment<\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">When an incident is confirmed, the SOC activates the corresponding\r\n            <strong>playbook<\/strong>: isolating compromised devices, cutting suspicious connections, invalidating\r\n            credentials and preserving evidence. Speed is everything: ransomware contained in minutes costs a thousand\r\n            times less than ransomware contained in hours.<\/p>\r\n    <\/div>\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">05<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Recovery and learning<\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">After containment, systems have to be restored, persistence has to be\r\n            ruled out and everything must be documented. The least visible but most valuable part: <strong>each incident\r\n                updates the playbooks<\/strong>, detection rules and controls. So the same thing does not happen again.<\/p>\r\n    <\/div>\r\n\r\n<\/div>\r\n\r\n<!-- ============================================================ -->\r\n<!-- H2 \u00b7 THREE PILLARS                                          -->\r\n<!-- ============================================================ -->\r\n\r\n<h2>The three pillars: <span class=\"isla-red-color\">people,<br>processes, technology<\/span><\/h2>\r\n\r\n<p>A SOC that does not balance all three <strong>is not a SOC<\/strong>. It is an expensive dashboard.<\/p>\r\n\r\n<h3>People<\/h3>\r\n<p><strong>L1<\/strong> analysts (triage, 24\/7), <strong>L2<\/strong> analysts (deep investigation), <strong>L3<\/strong>\r\n    analysts (incident response and <em>threat hunting<\/em>), plus a <strong>SOC manager<\/strong> and often detection\r\n    engineers who fine-tune the rules. In SMEs using an outsourced SOC, this team sits with the provider, not on your\r\n    payroll.\r\n<\/p>\r\n\r\n<h3>Processes<\/h3>\r\n<p><strong>Playbooks<\/strong> by incident type, response <strong>SLAs<\/strong> (guaranteed times to acknowledge,\r\n    contain and report), escalation matrices, communication protocols with the Spanish Data Protection Agency, CCN-CERT\r\n    and INCIBE, and regulatory notification procedures \u2014especially critical under NIS2, which requires <strong>significant\r\n        incidents to be reported within 24 hours.<\/strong><\/p>\r\n\r\n<h3>Technology<\/h3>\r\n<p><strong>SIEM<\/strong> as the core (Splunk, Microsoft Sentinel, Elastic, Wazuh), <strong>SOAR<\/strong> to automate\r\n    repetitive responses, <strong>EDR\/XDR<\/strong> on endpoints (SentinelOne, Microsoft Defender for Business, Sophos),\r\n    threat intelligence feeds and <em>ticketing<\/em> for traceability. Without technology there is no SOC. With technology\r\n    alone, there is not one either.<\/p>\r\n\r\n<!-- ============================================================ -->\r\n<!-- H2 \u00b7 COMPARISON TABLE (ADDED VALUE #1)                      -->\r\n<!-- Visual diagram goes here                                    -->\r\n<!-- ============================================================ -->\r\n\r\n<h2>SOC vs MDR vs MSSP vs SIEM: <span class=\"isla-red-color\">they are not the same<\/span><\/h2>\r\n\r\n<p>Almost every provider mixes these terms on purpose. They sound similar and they help sell. Knowing the difference\r\n    <strong>saves you from overpaying or buying less than you think<\/strong>.\r\n<\/p>\r\n\r\n<!-- VISUAL DIAGRAM OF THE COMPARISON TABLE -->\r\n<!-- The same information in an accessible table (for SEO and screen readers) -->\r\n<div class=\"isla-table-wrapper\">\r\n    <table class=\"isla-table\">\r\n        <thead>\r\n            <tr>\r\n                <th scope=\"col\">Concept<\/th>\r\n                <th scope=\"col\">What it is<\/th>\r\n                <th scope=\"col\">What it includes<\/th>\r\n                <th scope=\"col\">Who buys it<\/th>\r\n            <\/tr>\r\n        <\/thead>\r\n        <tbody>\r\n            <tr>\r\n                <td data-label=\"Concept\"><strong>SOC<\/strong><\/td>\r\n                <td data-label=\"What it is\">Function \/ organisational unit<\/td>\r\n                <td data-label=\"What it includes\">People + processes + technology (everything)<\/td>\r\n                <td data-label=\"Who buys it\">Companies that want full operational cybersecurity capability<\/td>\r\n            <\/tr>\r\n            <tr>\r\n                <td data-label=\"Concept\"><strong>MDR<\/strong><br><small>Managed Detection & Response<\/small><\/td>\r\n                <td data-label=\"What it is\">Outsourced commercial service<\/td>\r\n                <td data-label=\"What it includes\">Detection + active response, focused on endpoints and network<\/td>\r\n                <td data-label=\"Who buys it\">SMEs and mid-sized companies that need 24\/7 capability without building their own SOC<\/td>\r\n            <\/tr>\r\n            <tr>\r\n                <td data-label=\"Concept\"><strong>MSSP<\/strong><br><small>Managed Security Service Provider<\/small><\/td>\r\n                <td data-label=\"What it is\">Managed security service provider<\/td>\r\n                <td data-label=\"What it includes\">May offer SOC, MDR, managed firewall, pentesting, audits\u2026<\/td>\r\n                <td data-label=\"Who buys it\">Companies that outsource security layers under contract<\/td>\r\n            <\/tr>\r\n            <tr>\r\n                <td data-label=\"Concept\"><strong>SIEM<\/strong><br><small>Security Information & Event Management<\/small><\/td>\r\n                <td data-label=\"What it is\">Technology platform (software)<\/td>\r\n                <td data-label=\"What it includes\">Log collection and correlation + alerts<\/td>\r\n                <td data-label=\"Who buys it\">Internal SOCs or providers that build detection on top of it<\/td>\r\n            <\/tr>\r\n        <\/tbody>\r\n    <\/table>\r\n<\/div>\r\n\r\n<p><strong>Practical summary:<\/strong> a SIEM is a tool; a SOC is the team that operates it; MDR is a commercial product\r\n    that outsources detection and response; an MSSP is the type of company that can sell you any of the above. When a\r\n    salesperson says <em>\"we offer SOC\"<\/em>, ask what is included. If it is only alerts, it is managed SIEM. If they\r\n    respond technically, it is MDR. If they also govern risk and compliance, then yes: it is a SOC.\r\n<\/p>\r\n\r\n<!-- ============================================================ -->\r\n<!-- H2 \u00b7 MODELS                                                 -->\r\n<!-- ============================================================ -->\r\n\r\n<h2>SOC models: <span class=\"isla-red-color\">internal, outsourced<br>or hybrid<\/span><\/h2>\r\n\r\n<h3>Internal SOC (dedicated)<\/h3>\r\n<p>Your own team, your own infrastructure, your own tools. It makes sense for large accounts (+1,000 employees), highly\r\n    regulated critical sectors (banking, energy, public healthcare) or companies with extreme confidentiality\r\n    requirements. For a standard SME, <strong>it is extremely expensive<\/strong>: a minimally viable 24\/7 SOC requires\r\n    <strong>6-8 analysts working in shifts.<\/strong>\r\n<\/p>\r\n\r\n<h3>Outsourced SOC (SOCaaS)<\/h3>\r\n<p>You contract the service from an MSSP. They provide analysts, technology and processes. You pay a monthly fee based on\r\n    monitored devices or event volume. It is the <strong>dominant model for SMEs and mid-sized companies<\/strong> in\r\n    Europe because it converts CAPEX into OPEX and gives you access to capabilities that would not be viable at your own\r\n    scale.<\/p>\r\n\r\n<h3>Hybrid SOC (co-managed)<\/h3>\r\n<p>Your internal IT team handles day-to-day operations. The provider adds 24\/7 monitoring, <em>threat hunting<\/em> and\r\n    out-of-hours response. It is usually the <strong>most efficient model for companies with competent internal IT but no\r\n        shift capacity.<\/strong> At IslaNet, it is the model we most often recommend for SMEs with 50-250 employees in\r\n    the Balearic Islands.<\/p>\r\n\r\n<!-- ============================================================ -->\r\n<!-- H2 \u00b7 WHEN AN SME NEEDS IT \u2014 FAQ-style objections             -->\r\n<!-- ============================================================ -->\r\n\r\n<h2>Does your SME need a SOC? <span class=\"isla-red-color\">Four clear scenarios<\/span><\/h2>\r\n\r\n<p>Not every company needs a SOC. But if you are in one of these four scenarios, the question stops being\r\n    <em>\"if\"<\/em> and becomes <em>\"how\"<\/em>.\r\n<\/p>\r\n\r\n<div class=\"isla-numbered-grid\">\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">01<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Your sector is covered by <span class=\"isla-red-color\">NIS2<\/span><\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">If your company is an <strong>essential or important entity<\/strong> under\r\n            NIS2 (energy, healthcare, transport, water, digital services, food, critical manufacturing), the regulation\r\n            requires <strong>continuous detection and notification of significant incidents within 24 hours<\/strong>.\r\n            Meeting that requirement without SOC capability, internal or outsourced, is technically impossible.<\/p>\r\n    <\/div>\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">02<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Your clients or suppliers <span class=\"isla-red-color\">are asking for it<\/span>\r\n        <\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">More and more contracts with large accounts, public-sector tenders and\r\n            supply-chain audits ask the same question: <em>\"how does your company monitor security incidents 24\/7?\"<\/em>.\r\n            Being able to answer with a SOC \u2014your own or outsourced\u2014 is <strong>the difference between winning the\r\n                contract and being left out.<\/strong>\r\n        <\/p>\r\n    <\/div>\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">03<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">You have suffered an incident <span class=\"isla-red-color\">and do not want\r\n                another one<\/span><\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">After ransomware, a data breach or a serious CEO fraud attempt, most\r\n            companies discover that they had no real visibility until it was too late. A SOC ensures that the next\r\n            incident <strong>is detected before it causes damage.<\/strong><\/p>\r\n    <\/div>\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">04<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">You operate in a <span class=\"isla-red-color\">high-risk sector<\/span><\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">Hospitality (PMS, POS, guest data), healthcare (special-category GDPR\r\n            data), logistics, finance, law firms with professional secrecy. These are sectors where a successful attack\r\n            is not a question of if, but of <strong>when<\/strong>. Early detection is survival.<\/p>\r\n    <\/div>\r\n\r\n<\/div>\r\n\r\n<!-- ============================================================ -->\r\n<!-- H2 \u00b7 CHECKLIST \u2014 numbered IslaNet style                     -->\r\n<!-- ============================================================ -->\r\n\r\n<h2>How to choose a SOC provider: <span class=\"isla-red-color\">a practical checklist<\/span><\/h2>\r\n\r\n<p>If you have already decided to outsource, these are the seven criteria that separate a <strong>real SOC<\/strong> from\r\n    one that only sells the badge.<\/p>\r\n\r\n<div class=\"isla-numbered-grid checklist-proveedor\">\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">01<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Response SLAs <span class=\"isla-red-color\">written into the contract<\/span>\r\n        <\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">Maximum time to acknowledge, analyse and contain by severity level.\r\n            <strong>If the SLA is not in writing, it does not exist.<\/strong><\/p>\r\n    <\/div>\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">02<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Real 24\/7 coverage <span class=\"isla-red-color\">you can verify<\/span><\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">Ask how many analysts are on each shift, where they work from and how they\r\n            prove night-time coverage. A \"24\/7\" SOC with two analysts in total <em>is not 24\/7.<\/em><\/p>\r\n    <\/div>\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">03<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Provider and team <span class=\"isla-red-color\">certifications<\/span><\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">For the provider: <strong>ISO 27001, ENS, SOC 2<\/strong>. For the team:\r\n            CISSP, GCIA, GCIH, OSCP, ISO 27001 Auditor.<\/p>\r\n    <\/div>\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">04<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Transparency around the <span class=\"isla-red-color\">technology stack<\/span>\r\n        <\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">Which SIEM they use, which EDR they deploy, which intelligence feeds they\r\n            consume. <strong>If they will not tell you,\r\n                be suspicious<\/strong>: it is probably a <em>wrapper<\/em> on top of another provider.<\/p>\r\n    <\/div>\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">05<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Integration with <span class=\"isla-red-color\">your current stack<\/span><\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">Microsoft 365, Google Workspace, ERP, CRM, firewalls, cloud. A SOC that\r\n            cannot ingest logs from your core stack <strong>creates blind spots<\/strong>. And that is exactly where\r\n            attackers will get in.<\/p>\r\n    <\/div>\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">06<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Executive reporting, <span class=\"isla-red-color\">not only technical reporting<\/span>\r\n        <\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">Monthly reports that management can actually read: incidents detected,\r\n            mean time to containment, maturity. If reporting is just a sheet full of alerts, <strong>management loses\r\n                context and the SOC loses internal sponsorship.<\/strong><\/p>\r\n    <\/div>\r\n\r\n    <div class=\"isla-numbered-grid__item\">\r\n        <span class=\"isla-numbered-grid__number\">07<\/span>\r\n        <h3 class=\"isla-numbered-grid__title\">Real response <span class=\"isla-red-color\">exercises<\/span><\/h3>\r\n        <p class=\"isla-numbered-grid__desc\">Regular <em>tabletop exercises<\/em> with management and at least one annual\r\n            <em>purple team<\/em>. A SOC that never tests you leaves you not knowing whether it works until the worst has\r\n            already happened.<\/p>\r\n    <\/div>\r\n\r\n<\/div>\r\n\r\n<!-- ============================================================ -->\r\n<!-- TWO-COLUMN FAQ MODULE                                       -->\r\n<!-- ============================================================ -->\r\n\r\n<div class=\"isla-faq\">\r\n\r\n    <div class=\"isla-faq__header\">\r\n        <h2>FAQs<br>about <span class=\"isla-red-color\">SOCs<\/span><\/h2>\r\n    <\/div>\r\n\r\n    <div class=\"isla-faq__accordion\">\r\n\r\n        <details class=\"isla-faq__item\" name=\"faq-soc\">\r\n            <summary class=\"isla-faq__summary\">\r\n                <span class=\"isla-faq__icon\"><\/span>\r\n                \"We are small, no one is going to attack us\"\r\n            <\/summary>\r\n            <div class=\"isla-faq__content\">\r\n                <p>Classic mistake. <strong>43% of cyberattacks target SMEs<\/strong> precisely because they are usually\r\n                    less protected. For an attacker, a 50-person company with customer data can be worth as much as a\r\n                    small corporation. Being small does not protect you: it exposes you.<\/p>\r\n            <\/div>\r\n        <\/details>\r\n\r\n        <details class=\"isla-faq__item\" name=\"faq-soc\">\r\n            <summary class=\"isla-faq__summary\">\r\n                <span class=\"isla-faq__icon\"><\/span>\r\n                \"We already have an IT person, why would we need a SOC?\"\r\n            <\/summary>\r\n            <div class=\"isla-faq__content\">\r\n                <p>They are different things. Your IT person manages systems: making sure they work, stay up to date and\r\n                    allow people to do their jobs. A SOC <strong>monitors security<\/strong> 24\/7 with specific tools and\r\n                    processes. They do not replace each other; they complement each other. A SOC usually works\r\n                    <em>on top of<\/em> the infrastructure your IT team already maintains.<\/p>\r\n            <\/div>\r\n        <\/details>\r\n\r\n        <details class=\"isla-faq__item\" name=\"faq-soc\">\r\n            <summary class=\"isla-faq__summary\">\r\n                <span class=\"isla-faq__icon\"><\/span>\r\n                What is the difference between a SOC and a NOC?\r\n            <\/summary>\r\n            <div class=\"isla-faq__content\">\r\n                <p>A <strong>NOC<\/strong> (Network Operations Center) monitors network <strong>availability<\/strong>:\r\n                    making sure everything works. A <strong>SOC<\/strong> monitors <strong>security<\/strong>: making sure\r\n                    no one is attacking. They often coexist and coordinate, but they are different teams, tools and\r\n                    objectives. Confusing them leads to thinking your IT provider already handles cybersecurity. That is\r\n                    not true.<\/p>\r\n            <\/div>\r\n        <\/details>\r\n\r\n        <details class=\"isla-faq__item\" name=\"faq-soc\">\r\n            <summary class=\"isla-faq__summary\">\r\n                <span class=\"isla-faq__icon\"><\/span>\r\n                Can I build an internal SOC with 2-3 people?\r\n            <\/summary>\r\n            <div class=\"isla-faq__content\">\r\n                <p>No, not with 24\/7 coverage. A minimally functional internal SOC needs <strong>6-8 analysts working in\r\n                        shifts<\/strong> just to guarantee continuous coverage, plus a SOC manager. For SMEs, the\r\n                    realistic path is an <strong>outsourced or hybrid SOC<\/strong>, where the provider supplies the\r\n                    shift team and you keep an internal owner.<\/p>\r\n            <\/div>\r\n        <\/details>\r\n\r\n        <details class=\"isla-faq__item\" name=\"faq-soc\">\r\n            <summary class=\"isla-faq__summary\">\r\n                <span class=\"isla-faq__icon\"><\/span>\r\n                What are SOC L1, L2 and L3 analysts?\r\n            <\/summary>\r\n            <div class=\"isla-faq__content\">\r\n                <p><strong>L1<\/strong> performs the initial triage of alerts and filters false positives. <strong>L2<\/strong>\r\n                    investigates anything that looks suspicious, correlates events and escalates if it is a real\r\n                    incident. <strong>L3<\/strong> handles complex incident response, digital forensics and proactive\r\n                    <em>threat hunting<\/em>. The career path starts at L1 and evolves with experience and certifications.<\/p>\r\n            <\/div>\r\n        <\/details>\r\n\r\n        <details class=\"isla-faq__item\" name=\"faq-soc\">\r\n            <summary class=\"isla-faq__summary\">\r\n                <span class=\"isla-faq__icon\"><\/span>\r\n                Does a SOC replace antivirus or firewall protection?\r\n            <\/summary>\r\n            <div class=\"isla-faq__content\">\r\n                <p>No, it <em>uses<\/em> them. The SOC is the layer that orchestrates and monitors the whole environment:\r\n                    it receives alerts from the EDR, firewall, email, identity, cloud and correlates them. Without\r\n                    antivirus and firewall, the SOC has nothing to monitor. With antivirus and firewall but no SOC, you\r\n                    generate alerts that nobody reviews.<\/p>\r\n            <\/div>\r\n        <\/details>\r\n\r\n        <details class=\"isla-faq__item\" name=\"faq-soc\">\r\n            <summary class=\"isla-faq__summary\">\r\n                <span class=\"isla-faq__icon\"><\/span>\r\n                Do you subcontract the SOC to another country?\r\n            <\/summary>\r\n            <div class=\"isla-faq__content\">\r\n                <p>At IslaNet, no. We manage the SOC <strong>from Palma with our own technicians<\/strong>. When a critical\r\n                    alert fires at 3 a.m., one of our technicians in Mallorca picks up \u2014not an operator in another time\r\n                    zone and not a generic call centre.<\/p>\r\n            <\/div>\r\n        <\/details>\r\n\r\n        <details class=\"isla-faq__item\" name=\"faq-soc\">\r\n            <summary class=\"isla-faq__summary\">\r\n                <span class=\"isla-faq__icon\"><\/span>\r\n                Does NIS2 require every SME to have a SOC?\r\n            <\/summary>\r\n            <div class=\"isla-faq__content\">\r\n                <p>Not directly. NIS2 applies to essential and important entities with more than 50 employees or \u20ac10M in\r\n                    turnover in covered sectors, and to their critical suppliers. What it requires is <strong>continuous\r\n                        detection and notification within 24 hours<\/strong>, and in practice that almost always requires a SOC\r\n                    \u2014internal or outsourced. If you are unsure whether it applies to you, we can validate it in a <a href=\"\/auditoria-ciberseguridad-empresas\/\">cybersecurity audit<\/a>.<\/p>\r\n            <\/div>\r\n        <\/details>\r\n\r\n    <\/div>\r\n<\/div>\r\n\r\n<!-- ============================================================ -->\r\n<!-- FINAL CTA \u2014 IslaNet landing pattern                          -->\r\n<!-- ============================================================ -->\r\n\r\n<section class=\"cta-final\">\r\n\r\n    <h2>IF YOU NEED A SOC, <span class=\"isla-red-color\">LET\u2019S TALK<\/span><\/h2>\r\n\r\n    <p>If your company is considering hiring a SOC \u2014internal, outsourced or hybrid\u2014 we can help you decide. No pressure\r\n        sales. A short call is enough for us to understand your case, see which model fits your size and sector, and\r\n        give you a realistic investment range.<\/p>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-faqschema8290 e-con-full e-flex e-con e-parent\" data-id=\"faqschema8290\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-faqsw8290 elementor-widget elementor-widget-html\" data-id=\"faqsw8290\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.islanetworks.com\/#organization\",\"name\":\"islaNet\",\"url\":\"https:\/\/www.islanetworks.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\/\/www.islanetworks.com\/wp-content\/uploads\/2024\/10\/islanet-consultoria-digital-248x72.webp\"},\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"Carrer de Can Mart\u00ed Feliu, 4, 1\u00ba C\",\"addressLocality\":\"Palma de Mallorca\",\"addressRegion\":\"Balearic Islands\",\"postalCode\":\"07002\",\"addressCountry\":\"ES\"},\"sameAs\":[\"https:\/\/www.linkedin.com\/company\/islanetworks\/\"]}]}<\/script>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Monday morning. You arrive at the office and your IT person says, with that look on their face: &#8220;Listen, they are asking us for a SOC in a tender&#8221;. Or worse: you have already had a scare, looked into NIS2 and been told that without 24\/7 monitoring you will not meet the requirements. And now [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":8396,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[64],"tags":[87,88],"class_list":["post-8291","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ai","tag-google-io-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.islanetworks.com\/en\/wp-json\/wp\/v2\/posts\/8291","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.islanetworks.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.islanetworks.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.islanetworks.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.islanetworks.com\/en\/wp-json\/wp\/v2\/comments?post=8291"}],"version-history":[{"count":0,"href":"https:\/\/www.islanetworks.com\/en\/wp-json\/wp\/v2\/posts\/8291\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.islanetworks.com\/en\/wp-json\/wp\/v2\/media\/8396"}],"wp:attachment":[{"href":"https:\/\/www.islanetworks.com\/en\/wp-json\/wp\/v2\/media?parent=8291"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.islanetworks.com\/en\/wp-json\/wp\/v2\/categories?post=8291"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.islanetworks.com\/en\/wp-json\/wp\/v2\/tags?post=8291"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}