Security · Security Operations
Security Operations
The people, process and platform that monitor, triage, investigate and respond to security events continuously.
IntermediateUpdated 2026-09-01
Overview
A security operations function turns telemetry into decisions. Whether it is a 24/7 in house SOC, a hybrid model, or an MDR partnership, the same components exist: data collection, detection engineering, triage, investigation, response and continuous improvement.
Operating model choice matters more than tooling. Small teams should optimise for high signal detections and a strong partner relationship rather than attempting round the clock staffing.
Sequence
- 1Telemetry
- 2Collection
- 3SIEM / XDR
- 4Detection
- 5Investigation
- 6Response
- 7Improvement
Layer model
Data sources
EndpointsIdentityEmailNetworkCloud control planesApplicationsFirewallsDNSSaaS audit logs
Functions
Triage (Tier 1)Investigation (Tier 2)Hunting and detection engineeringIncident commandThreat intelligenceAutomation
Measures
Time to detectTime to containDetection coverage by techniqueFalse positive rateEscalation quality
Security considerations
- Define severity and escalation before go live, including who may authorise containment actions.
- Track coverage against ATT&CK and close gaps as a backlog, not an aspiration.
- Automate enrichment first, it saves analyst time with far less risk than automated blocking.
Common misconfigurations
- Alerts delivered to email rather than a queue with ownership and SLA.
- Response actions available in tooling but not permitted by process, so analysts wait hours for approval.
- No feedback loop from incidents into detection improvements.
