Prevention fails eventually. A Security Operations Centre is the function that notices when it has, and does something about it before a foothold becomes a breach.
What a SOC actually does
- Collect. Logs and telemetry from endpoints, servers, firewalls, cloud platforms, identity providers and applications flow into a central platform.
- Detect. Correlation rules, threat intelligence and behavioural analytics turn raw events into alerts — impossible travel on a login, a service account suddenly running PowerShell, mass file encryption on a share.
- Triage. Analysts separate the real from the noise. This is most of the work: a good SOC tunes relentlessly, because an analyst drowning in false positives will miss the true positive.
- Respond. Isolate the host, disable the account, block the indicator, and hand over to incident response if it is serious.
- Improve. Every incident produces a detection rule or a hardening change so the same thing is caught faster next time.
The tools, in plain language
- SIEM — the log warehouse and correlation engine. It answers "what happened, everywhere, in order".
- EDR — the agent on each endpoint. It sees process trees and can kill or isolate a machine remotely.
- SOAR — automation. It runs the first ten minutes of the playbook — enrich, check, contain — before a human reads the alert.
- Threat intelligence — the feed of known-bad indicators and current attacker behaviour.
Tools do not make a SOC. People and tuned process do. A SIEM nobody watches is an expensive log archive.
In-house or managed?
True 24/7 coverage needs roughly 8–10 analysts once you account for shifts, leave and attrition — plus a SIEM licence, an EDR licence and an engineer to run the platform. For most organisations in Bangladesh that is not proportionate, which is why managed SOC (also called MDR) is the common route.
| In-house SOC | Managed SOC | |
|---|---|---|
| Cost | High fixed cost — salaries, licences, tooling | Predictable monthly fee |
| Time to value | 6–12 months | Weeks |
| Coverage | Hard to sustain 24/7 | 24/7 by design |
| Context | Deep knowledge of your business | Needs onboarding to learn it |
A hybrid is common: a managed SOC watches around the clock, and one internal owner handles context, escalation and remediation.
Do you need one?
You probably do if any of these are true: you hold customer financial or health data; you are regulated; you have more than a handful of servers or 50+ endpoints; you operate an e-commerce or fintech platform; you have already had an incident; or a customer contract requires monitoring.
You probably do not yet if MFA is not deployed, backups are not tested, and patching is ad hoc. Fix those first — monitoring will only tell you loudly what you already know.
Ask any SOC provider these five questions: What is your alert-to-analyst ratio? What is your mean time to detect and to respond, measured? Can you isolate an endpoint yourself, or only advise? Where is my log data stored and for how long? Who exactly will I be talking to at 3am?
Oriole Security's SOC analysts monitor client environments around the clock from Dhaka. See our SOC and threat-monitoring services or book a free consultation.