SOC (security operations center)
A SOC (security operations center) is the team of analysts, processes and tools that watches a company's systems around the clock and handles every alert, from investigation to containment. As a service (SOCaaS), an outside provider runs it under a subscription.
How TecnetOne handles it: TecnetSOC
security operations center, SOC as a service, SOCaaS, TecnetSOC
Related terms
Endpoint
An endpoint is any device that connects to your company network and is used to work or process data: laptops, desktops, phones, tablets and servers. Every endpoint is a possible way in, which is why each one is protected with antivirus, EDR and management policies.
Red team, blue team and purple team
The red team simulates real attacks against an organization to find its weak points; the blue team defends, detects and responds. The purple team brings both together so every simulated attack immediately turns into a concrete improvement to the defenses.
SOAR (security orchestration, automation and response)
SOAR (security orchestration, automation and response) is a platform that connects a company's security tools and runs automatic responses to alerts. For example, if the SIEM detects a suspicious sign-in, SOAR can lock the account, isolate the device and open a ticket in seconds, without waiting for an analyst.
SOC as a Service (SOCaaS)
SOC as a Service (SOCaaS) is a model in which a company hires a specialized provider to monitor, detect and respond to threats around the clock instead of building its own security operations center. It gets the technology, analysts and processes for a monthly fee, without investing in infrastructure or hiring a full team.
Agentic SOC
An agentic SOC is a security operations center in which AI agents triage alerts, correlate them and start the investigation of each incident, while human analysts supervise and make the critical decisions. Unlike traditional automation, which follows fixed scripts, the agent reads the context of each case and decides the next step.
SIEM (security information and event management)
A SIEM (security information and event management) is the platform that collects the logs from every system in a company and correlates them, raising an alert when a sequence matches the way an attack behaves. It's the central screen of a SOC.
Ready to put this into practice in your operation?
Tell us what you need and a TecnetOne engineer will get back to you.
Talk to an engineerTalk to an engineer
Tell us what you need and we’ll reply the same business day.