Thursday, 3 September 2026 SourcesAbout🌓
🇿🇦 ZA ▾
BREAKING
Technology

How to build a security operations centre that actually works

TechCentral ·
How to build a security operations centre that actually works

Cybersecurity teams overwhelmed by alerts, critical infrastructure left unmonitored and budgets drained without results: these are some of the consequences of security operations centre (SOC) deployment mistakes. This step-by-step guide from Kaspersky is designed to help you avoid the pitfalls and build an effective SOC.

Businesses are distinct entities that navigate unique challenges. There are, however, common triggers that set the SOC-creation process in motion. Some are logical and proactive:

Other triggers are reactive and therefore less desirable. A business that has already been attacked realises it lacks the capability to respond effectively. It starts its SOC journey from a position of financial insecurity, while fighting to undo reputational damage.

Once an organisation has established that it needs a SOC and can afford one, it must work out early what the SOC needs in order to function, and build foundations it can scale from. At the top of the list is human capability. Every SOC rests on three core roles:

Between them, these roles cover operations , technical maintenance and development for threat protection . Each requires expertise a fledgling SOC will fail without.

The cybersecurity skills gap makes staffing a SOC harder, so factor substantial time and budget into sourcing talent.

Headcount matters too, because a SOC requires round-the-clock coverage. A foundational team runs to at least 10 people: a manager, five analysts, two engineers and two researchers. Small teams quickly face unsustainable workloads and alert fatigue, and many of those alerts will be false positives. That leads to burnout, which in turn raises the odds of a missed threat.

An organisation that cannot staff a SOC properly is better off appointing an external provider to monitor threats on its behalf. Managed security service providers (MSSPs) can deliver monitoring and incident response matched to the organisation’s industry, capability and budget.

For a business that is ready to build, the focus shifts to scalability. Core systems – telemetry pipelines, correlation engines and the rest – need to scale horizontally. Anticipate architectural limits early so you are prepared for growth and can account for future costs such as disaster recovery.

A successful SOC deploys not only people and technology but processes, and there is an order in which they should come.

There are shortcuts to SOC functionality. One is to draw on third-party knowledge in the form of frameworks, which act as a blueprint and can accelerate the design process.

“First-time SOCs often rely too heavily on technology and default vendor content, assuming that tools will function effectively without tuning or skilled operators. Expecting instant results from out-of-the-box solutions leads to missed threats and false confidence. Another common pitfall is neglecting continuous improvement – treating the SOC as static rather than an evolving capability, which prevents adaptation to new attack techniques,” says Roman Nazarov, head of SOC consulting at Kaspersky.

A SOC must deliver value early.

Read the full article on TechCentral ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on techcentral.co.za — the content belongs to TechCentral.

More from TechCentral

See all ›

More in Technology

See all ›