Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Security operations center (SOC)

Also known as: SOC, OT SOC, Cyber defense center

German: Security Operations Center (SOC)

In cybersecurity, a security operations center (SOC) is a team, with its processes and tools, that continuously monitors an organization's systems for security events, analyzes alerts, coordinates incident response and supports vulnerability management. An OT SOC or a SOC with OT expertise covers industrial control systems.

  • OT security

In one sentence

A security operations center (SOC) is the team, process and tools that continuously monitor systems, analyze alerts and coordinate incident response.

Example

The company's SOC receives an alert from the OT intrusion detection system and calls the plant's shift lead to confirm whether a firmware update was planned before escalating.

How it applies

  • Operation: SOC analysts triage alerts, investigate, escalate and coordinate responses. For OT, they need process context and contacts on site, because containment decisions can stop production or affect safety.
  • Organization: SOCs can be internal, outsourced or hybrid. Many companies extend an IT SOC to OT; this works when OT data sources, playbooks and escalation paths to plant staff are defined.
  • Compliance: Continuous monitoring and incident handling support NIS 2 obligations, including the short reporting deadlines for significant incidents.
  • Documentation: SOC playbooks for OT should reference plant-specific documentation: network drawings, asset inventory, safe shutdown procedures and supplier contacts. Keep these references current, or analysts will act on outdated information.

SOC vs. CSIRT

A SOC monitors and detects continuously. A computer security incident response team (CSIRT) handles incidents; national CSIRTs also receive reports under NIS 2. In smaller organizations one team may do both.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Knowledge editorial definition, based on industrial cybersecurity practice

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!