What is a SOC, and does a small business need 24/7 security monitoring?
A SOC, or security operations centre, is the team that watches security alerts and acts on them, around the clock. A small business needs the function, not the department: attacks and failures do not keep office hours, and the practical way to get 24/7 eyes at small-business scale is a managed provider whose plans already include one.
Here is what a SOC actually does, stripped of mystique. Signals stream in from every defended thing you own: endpoint protection such as Microsoft Defender on each computer, detection tools such as Huntress, sign-in logs from Microsoft 365 and Entra ID, email filters, backup jobs. Almost all of it is noise. The SOC's job is triage: dismiss the noise, investigate the odd, and act on the real, which might mean isolating a machine from the network, disabling a compromised account, or ringing you. It is judgement work sitting on top of automation, not someone staring at a wall of screens.
The around-the-clock part is not marketing. Attackers deliberately work your night and your long weekend, because encryption that starts at 6pm Friday has until Tuesday to finish. And it is not only attackers: controls fail silently at all hours, and a backup job that quietly errored at 11pm is exactly the kind of event that either gets caught by monitoring or discovered months later, on the day the backup is needed. The human signals read differently after hours too: a login from a country nobody is visiting means one thing in a Monday report and quite another at 3am, live.
So does a ten-person business need one? It needs the function, and it cannot sensibly staff the department. A genuine 24/7 rotation needs several trained people once you account for nights, weekends, leave and resignations, which is an absurd payroll for a small business and a stretch even for mid-sized ones. This is the textbook case for buying a shared function: the SOC watches many businesses at once, and each pays a slice. The economics work on the tooling side too, because the platforms a serious SOC runs would be unaffordable for any one small business alone.
That is how we deliver it. Our managed plans are backed by a 24/7 network and security operations centre, so the watching is included in the same per-user monthly fee as the IT support, rather than sold as a separate subscription. We have run business IT since 2006, and the operational lesson of those years is blunt: the incidents that hurt are the ones nobody saw start.
One thing a SOC is not: a substitute for controls. Monitoring an unpatched network with no multi-factor authentication is hiring a scribe for the burglary; the notes will be excellent and the loss identical. The order of operations matters. Essential Eight controls first, so most attacks simply fail, then eyes on the alerts, so the exceptions get caught. A provider who sells you monitoring while your controls gape is selling the second storey before the foundation. Get the order right and the SOC's workload shrinks to the exceptions, which is precisely what makes it affordable.
If a provider claims 24/7 monitoring, three questions sort the real ones from the brochures. Who, specifically, is watching at 2am: their staff, a partner SOC, or unattended software? Walk me through the last alert that mattered: a real one, anonymised, from detection to resolution. And what happens when the alert concerns my business: who decides to isolate a machine, and when do you ring me? Concrete answers exist if the service does. Ask in writing; the quality of the answers you get back now is the quality of the service you will get later.
The honest caveat is that a portal is not a SOC. Some providers sell monitoring that amounts to a dashboard you can log into, which makes you the analyst. Others forward every raw alert by email, which is worse than silence, because alert fatigue trains everyone to ignore the one that matters. A good SOC is measured by responses, not by alerts counted, and its best month is one where you heard nothing because nothing required you.
If you want to know whether your current setup would even generate the right alerts, our free Essential Eight Cyber Security Scorecard is the place to start, or call us on 1800 456 567.
See what 24/7 monitoring includes
Our managed plans are backed by our own around-the-clock network and security operations centre, included in the same per-user monthly fee as the IT support.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business