A SOC is the team that watches your network while nobody else is looking. Most South African businesses cannot staff one, because the analysts do not exist to hire at any reasonable price. This guide explains what a security operations centre actually does hour by hour, what the three staffing models cost in practice, and how to judge whether an outsourced SOC is genuinely watching your environment or simply forwarding you alerts you have no capacity to action.

What is a SOC in cyber security?

A SOC, or security operations centre, is a team of analysts and the tooling they use to monitor an organisation’s systems continuously, investigate anything suspicious, and respond before an intrusion becomes a breach. It is usually pronounced to rhyme with rock, and you will also see it written as security operations center in American vendor documentation.

The distinction that matters is between owning security tools and operating them. A business can buy a firewall, endpoint protection and email filtering, and still have nobody reading what those products report at 03:00 on a Sunday. A SOC is the answer to the question of who is actually watching.

Three functions define it. Detection, meaning someone or something notices the anomaly. Investigation, meaning a human decides whether it matters. Response, meaning somebody has the authority and the access to act on it.

What does a SOC do day to day?

A SOC works through a queue of alerts, separating the handful that matter from the thousands that do not. That triage is the job. Modern security tooling is noisy by design, because a product that misses an intrusion is worse than one that cries wolf, and the consequence is an alert volume no unassisted human can read.

The daily work breaks into five activities.

Monitoring. Log data from firewalls, endpoints, servers and cloud services flows into a central platform, typically a SIEM, where correlation rules flag patterns worth a human look.

Triage. An analyst grades each alert. Most are noise: a legitimate admin logging in from an unusual location, a backup job that looks like bulk data movement.

Investigation. Anything that survives triage gets pulled apart. Which account, which machine, what did it touch, when did it start.

Response. Isolate the endpoint, disable the account, block the address, restore from backup.

Hardening. Between incidents, the SOC tunes detection rules, patches what the last incident exposed and hunts for threats nobody has alerted on yet.

The last one separates a real SOC from an alert-forwarding service. If nobody is proactively hunting, you have a notification system.

In-house, outsourced or hybrid

There are three SOC models, and for most South African mid-market businesses only two of them are realistic. The constraint is not budget for tools. It is people.

Model What it means Realistic for Main risk
In-house Your own analysts, your own tooling, on your premises Large enterprise, banks, telcos Cannot hire or retain the analysts
Outsourced A provider monitors your environment from their SOC Most mid-market businesses Provider lacks context on your systems
Hybrid Provider handles 24/7 monitoring, your IT team owns response Businesses with an existing IT function Unclear handover at the boundary

Running a genuine 24/7 in-house SOC needs roughly eight to twelve analysts once you account for three shifts, leave, sick cover and attrition. Not four. That maths is what pushes almost everyone below enterprise scale toward an outsourced or hybrid arrangement.

If you are an MSP planning to deliver monitoring to your own clients, the enablement and vendor accreditation side matters as much as the tooling. You can apply to become an accredited partner and build the practice on vendors you are certified to support.

Why South Africa cannot staff SOCs

South Africa has a structural shortage of the exact people a SOC needs. Cybersecurity skills shortages are the most acute talent constraint reported across sub-Saharan Africa, and the MICT SETA lists cybersecurity among its critical scarce skills, with SOC analysts named specifically alongside penetration testers and security engineers.

This is not a temporary hiring squeeze. It is a pipeline problem. Analysts take years to become useful, competent ones are recruited internationally at rand-unfriendly salaries, and a business competing for them is bidding against London and Dubai.

The practical consequence is that building your own SOC is rarely the decision it appears to be. A company that budgets for a SOC platform and two analysts has bought a tool and a rota gap. The 22:00 to 06:00 window, when a meaningful share of ransomware deployment happens, is exactly the window two people cannot cover.

Pooling is the only economic answer at mid-market scale. One team of analysts watching forty environments can be staffed and retained. Forty teams of two cannot.

What a SOC costs and what it saves

SOC pricing is usually per endpoint or per log volume per month, and the honest comparison is not against zero but against the cost of the incident it prevents. That framing matters because a SOC never demonstrates value on a quiet month.

The cost side is straightforward: platform licensing, log ingestion, and the analyst time. The saving side is where estimates get soft, so anchor it in something concrete instead.

South Africa recorded 17,849 ransomware detections in a single year, the highest of any African country, according to Interpol’s 2025 Africa Cyberthreat Assessment. A ransomware event that reaches encryption stops a business trading. Add forensic investigation, legal advice, the rebuild, and the POPIA obligation to notify.

Detection speed is the variable a SOC actually moves. Ransomware operators typically spend days inside a network before they encrypt anything, escalating privileges and locating backups. Every hour of that dwell time is an hour something could have noticed. A business with no monitoring finds out at encryption. A monitored business finds out during reconnaissance.


NEED SOC-GRADE SKILLS ON YOUR TEAM?
LOOPHOLD trains and accredits South African partners on the security stack behind modern monitoring.
See partner enablement


SOC vs NOC vs MSSP

A SOC watches for attackers, a NOC watches for outages, and an MSSP is the commercial vehicle that sells you either as a service. The three get conflated in sales conversations, occasionally deliberately.

A network operations centre exists to keep systems available. Its questions are about uptime, latency and capacity. A slow link is a NOC problem.

A security operations centre exists to keep systems trustworthy. Its questions are about intrusion and misuse. A slow link caused by data being exfiltrated is a SOC problem, and the NOC will not spot it because from a NOC’s view the network is doing exactly what it was asked.

A managed security service provider is a business model, not a facility. When buying, read what is actually in scope: some MSSP contracts include full investigation and response, others deliver an alert to your inbox and consider the obligation met.

Questions to ask before signing

Ask who is on shift at 02:00 on a public holiday, and get the answer in writing. Everything else follows from whether that answer is credible.

Is monitoring genuinely 24/7 with staffed shifts, or is it business-hours coverage with an after-hours on-call pager?

What is the contracted response time, measured from detection rather than from when you raise a ticket?

Can the provider act, or only advise? A SOC that must phone you for permission to isolate an infected laptop at 03:00 is not going to isolate it at 03:00.

Where does your log data live, and does that placement satisfy your POPIA obligations around cross-border transfer?

What happens on day one of an actual incident? Ask them to describe their last real one.

Does it integrate with the security products you already own, or does it require you to replace them?

If the answers are vague on any of these, the vagueness is the finding. For the wider context on how monitoring fits alongside the rest of a security programme, our guide to cyber security for South African businesses sets out the full layered model, and teams building the underlying skills can start with SonicWall certification training.


BUILDING A MONITORING PRACTICE?
Talk to LOOPHOLD about the vendor accreditation and technical enablement behind it.
Start my partner enquiry


Pin It on Pinterest

Share This