Research Brief: Large SOCs Take a Multifaceted Approach to Optimizing Security Operations
Research Brief

May 21, 2025
by Dave Gruber, Emily Marsh, Bill Lundell, Enterprise Strategy Group Research
Security operations is a core function of cybersecurity, requiring a combination of skilled people, refined processes, and scalable technologies. While once focused on more reactive security functions, modern security operations centers (SOCs) are increasingly responsible for more proactive security functions, including monitoring security posture and status, managing threats and exposure, and analyzing threat intelligence, while continuing to triage, investigate, and respond to suspicious or malicious behavior. Recent research by Enterprise Strategy Group investigated how the size of a SOC impacts the adoption of technologies such as GenAI, leveraging third-party services and increasing organizations’ spending to better support their security operations and fortify their security posture.
 

Page Count: 4