Glossary / SOC (Security Operations Center)

SOC (Security Operations Center)

A centralized team and process for continuously monitoring an organization's environment for signs of a security incident, investigating what's found, and coordinating the response — distinct from "SOC 2," the unrelated audit report that happens to share the same three letters.

A SOC's job is detection and response: correlating log and alert data (often through a SIEM), triaging what's a real threat versus noise, investigating anything that looks like an actual compromise, and containing it — ideally before it spreads, not after a client discovers it independently.

The acronym collision with "SOC 2" trips people up constantly, and it's worth being explicit about: a Security Operations Center is a monitoring function, while SOC 2 is an audit framework a vendor gets assessed against. A vendor can run a SOC and separately be SOC 2 audited, or do either without the other — they're unrelated concepts that happen to share an initialism.

Running a genuinely 24/7 SOC in-house is expensive — round-the-clock staffing for a function that's idle most of the time — which is exactly why MDR (Managed Detection and Response) exists as a category: an organization buys the SOC function as a service rather than building and staffing one itself.

How Nexus handles this

Nexus doesn't run a 24/7 SOC on a client's behalf — its security suite surfaces vulnerability findings and breach-monitoring alerts as an owned, SLA-tracked ticket in the same PSA record a technician already works, rather than a separate console nobody's watching.

Ready to see it in the platform?

Join the design-partner cohort and we'll show you exactly where this lives.