Hacking Humans

Security Operations Center (SOC) (noun) [Word Notes]

10 min
Jul 28, 202627 days ago
Listen to Episode
Summary

This Word Notes episode defines Security Operations Centers (SOCs) as centralized facilities responsible for monitoring, detecting, and responding to cybersecurity incidents. The episode traces the historical evolution of operations centers from ancient organizational practices through AT&T's network operations centers to modern cybersecurity SOCs, explaining how they coordinate security efforts across organizations.

Insights
  • SOCs represent a fundamental organizational pattern that emerges whenever tasks become too complex for single teams to manage, a principle dating back millennia
  • Modern SOCs evolved from network operations centers and were formalized in cybersecurity following the 1988 Morris worm, leading to CERT-CC and FIRST
  • SOCs serve as centralized intelligence hubs that aggregate data from across organizations, enabling analysts to make recommendations that leadership then coordinates across teams
  • Third-party SOC services (MSSPs, CERTs, ISACs, ISALs) provide critical capabilities for organizations unable to build internal SOC infrastructure
  • The SOC model represents a shift from reactive incident response to coordinated, 24/7 monitoring and response capabilities requiring specialized security professionals
Trends
Formalization of incident response as a discipline following major security events (Morris worm 1988, leading to CERT-CC establishment)Growth of information sharing frameworks (ISACs, ISALs) enabling threat intelligence collaboration across organizationsRise of managed security service providers (MSSPs) in late 1990s-early 2000s as alternative to internal SOC developmentShift toward 24/7 monitoring and response as organizational security baseline rather than exceptionEvolution of SOC from physical facilities to virtual/distributed models supporting modern security operations
Companies
Carnegie Mellon University
Established the first CERT Coordination Center (CERT-CC) in 1988 with DARPA sponsorship following the Morris worm
AT&T
Built the first network operations center (NOC) in 1977 in Bedminster, New Jersey to manage telephone switching
OpenAI
Hosting talks at SpecterOps Kennel Club at Black Hat USA regarding AI-accelerated attack paths
UK AI Security Institute
Co-hosting talks with SpecterOps and OpenAI at Black Hat USA on AI security topics
People
Friedrich Klimm
Author of 'A History of Western Technology' cited for historical perspective on operations centers dating to 5000 BC
President Clinton
Established the ISAC system through Presidential Decision Directive 63 on May 22, 1998
President Obama
Established the ISAO framework in February 2015 to enable threat intelligence sharing beyond critical infrastructure
Tim Nodar
Word Notes episode writer
Rick Howard
Host and editor of Word Notes episode
Peter Kilpie
Executive producer of Word Notes
John Petrick
Editor of Word Notes
Elliot Peltzman
Created mix, sound design, and original music for Word Notes
Quotes
"Most environments trust far more than they should, and attackers know it."
ThreatLocker (sponsor message)
"Any time an organization grows big enough, either in terms of people or in function, where one small team can't do everything, leaders have built these centers to manage the workflow and status of the various groups and to coordinate actions among them."
Friedrich Klimm (via narrator)
"In terms of cybersecurity, a SOC is a network defender's centralized point, either physical or virtual, where they bring in relevant information from all corners of the organization."
Rick Howard (narrator)
"SOC teams are typically staffed with skilled security analysts, incident responders, threat hunters, and other cybersecurity professionals who work in shifts to provide 24 by 7 monitoring and response capabilities."
Rick Howard (narrator)
Full Transcript
You're listening to the Cyber Wire Network, powered by N2K. This episode is supported by Black Hat USA. If you follow the research, you know a lot of it breaks on Black Hat stages. Hundreds of peer-reviewed briefings, more than 100 hands-on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow, August 1st through the 6th. Use code CYBERWIRE for $200 off your briefings pass at blackhat.com. We'll see you in Vegas. If you're heading to Black Hat USA this year, make plans to visit the Specter Ops Kennel Club. As creators of Bloodhound, the SpecterOps team will host talks with OpenAI and the UK AI Security Institute, as well as hands-on workshops aimed at helping you understand AI-accelerated attack paths and the latest in identity tradecraft. Visit specterops.io to pre-register and learn more. SpecterOps Kennel Club is adjacent to Libertine Social inside Mandalay Bay. While you're there, visit the N2K CyberWire podcast studio, where we'll be capturing expert perspectives and conversations from across Black Hat. You're listening to the CyberWire Network, powered by N2K. Most environments trust far more than they should, and attackers know it. ThreatLocker solves that by enforcing default deny at the point of execution. With ThreatLocker allow listing, you stop unknown executables cold. With ring fencing, you control how trusted applications behave. And with ThreatLocker DAC, defense against configurations, you get real assurance that your environment is free of misconfigurations and clear visibility into whether you meet compliance standards. ThreatLocker is the simplest way to enforce zero-trust principles without the operational pain. It's powerful protection that gives CISOs real visibility, real control, and real peace of mind. ThreatLocker makes zero-trust attainable, even for small security teams. See why thousands of organizations choose ThreatLocker to minimize alert fatigue, stop ransomware at the source and regain control over their environments Schedule your demo at threatlocker slash n2k today The word is SOCK. Spelled S for security, O for operations, and C for center. Definition. A centralized facility or team responsible for monitoring, detecting, analyzing, and responding to cybersecurity incidents within an organization. Example sentence. SOC teams are typically staffed with skilled security analysts, incident responders, threat hunters, and other cybersecurity professionals who work in shifts to provide 24 by 7 monitoring and response capabilities. Origin and context. The idea of operations centers has been around seemingly forever. Friedrich Klimm, in his A History of Western Technology, suggests that the concept goes as far back as 5000 BC. Klimm said that any time an organization grows big enough, either in terms of people or in function, where one small team can't do everything, leaders have built these centers to manage the workflow and status of the various groups and to coordinate actions among them. Fast forward to the early 1960s, AT&T handled most telephone switching in the United States and built a network operations center, a NOC, to manage it in 1977 in Bedminster, New Jersey. In the aftermath of the infamous Morris worm in 1988, the first destructive internet worm, the Defense Advanced Research Projects Agency, DARPA, a science and technology organization of the U.S. Department of Defense, sponsored Carnegie Mellon University to establish the first CERT Coordination Center, CERT-CC, in 1988. By 1990, the Forum of Incident Response and Security Teams, FIRST, had become a non-profit to bring together incident response and security teams from every country across the world to ensure a safe internet for all. As of today, there are 657 teams in 101 different countries that belong to FIRST. On the commercial side it unclear of the exact date but we started to see the first managed security service providers MSSPs in the late 1990s and early 2000s MSSPs are essentially contracted SOGs President Clinton established the ISAC system, the Information Sharing and Analysis Center framework, when he signed Presidential Decision Directive 63, PDD 63, on May 22, 1998, in an effort to better protect the country's critical infrastructure. In February 2015, President Obama established the information sharing and analysis organization ISAL framework, clearing the legal hurdles for all like-minded organizations, not just critical infrastructure groups, to share threat intelligence with each other. CERTs, ISACs, ISALs, and MSSPs provide SOC-type services for those that can't do it themselves or provide supplemental help for those that can't. The bottom line is that when a task gets so big in scope that it requires multiple teams to complete it, an operations center is needed to coordinate those efforts, just like Friedrich Klimm said. In terms of cybersecurity, a SOC is a network defender's centralized point, either physical or virtual, where they bring in relevant information from all corners of the organization. Analysts review the information and make recommendations to leadership. Leadership makes decisions, and then the SOC coordinates the deployment of those actions out to the individual organizational teams to execute. Nerd reference. In 1979, AT&T distributed a documentary film called AT&T Long Lines about their network operations center in Bedminster, New Jersey. And just revel in the glory of that 1970s jazz rock backbeat. Kansas City here. It looks like we might be in for some trouble. Hi. Oh, before we start the tour, it'll only take a minute if you don't mind. We've had some severe storms out here. We've really got generally hazardous conditions all along Tornado Alley. And our radio tower at Plains, Kansas is on emergency power. Okay, I'll tell you what. While you're checking the free plans, we'll establish the restoration priorities. Keep us busy. Would you keep an eye on this one, please? Thanks for waiting. Sometimes the telephone network can't. You know, keeping the lines clear between more than 170 million telephones and making sure over half a billion local and long-distance calls get to their destination every day, well, that's quite a job. And basically that what we do here Welcome to the Network Operations Center NOC for short and to AT Longline headquarters here in Bedminster New Jersey Word Notes is written by Tim Nodar, executive produced by Peter Kilpie, and edited by John Petrick and me, Rick Howard. The mix, sound design, and original music have all been crafted by the ridiculously talented Elliot Peltzman. Thanks for listening. AI is transforming every industry, but it's also creating new risks that traditional frameworks can't keep up with. Assessments today are fragmented, overlapping, and often specific to industries, geographies, or regulations. That's why Black Kite created the BKGA3 AI Assessment Framework to give cybersecurity and risk teams a unified, evolving standard for measuring AI risk across their own organizations and their vendors' AI use. It's global, research-driven, built to evolve with the threat landscape, and free to use. because BlackKite is committed to strengthening the entire cybersecurity community. Learn more at BlackKite.com. This episode is supported by Black Hat USA. If you follow the research, you know a lot of it breaks on Black Hat stages. Hundreds of peer-reviewed briefings, more than 100 hands-on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow, August 1st through the 6th. Use code CyberWire for $200 off your briefings pass at blackhat.com. We'll see you in Vegas. Heading to Black Hat USA, the N2K CyberWire team will be on-site recording from our podcast studio in the SpecterOps Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, stop by the studio and meet the N2K CyberWire team. SpecterOps's Kennel Club is adjacent to Libertine Social inside Mandalay Bay.