In the modern world everything is connected, and because of that the need for a cybersecurity function is a priority.
The days when an antivirus protected your personal computer are now memories of a make-believe world. Cyber thieves have evolved into organisations where attacks are more complex, more organised and more effective — and worse still, we are all an easy target.
The problem
When we hear about 'hacks' or attacks on the internet, most of us picture a kid typing code in a dark room.
While that is one possibility, in reality the attacks you hear about in the news are carried out by organisations that have spent months planning their strategy before making a move. They have workplaces, teams, schedules, even salaries, like any other job.
There is an entire market for this business with customers from different cultures and ideologies: curious people in search of knowledge, self-styled 'hackers', the IT person looking for power, companies trying to get their competitors' secrets, governments or countries at war, among others.
What can we do?
Switching the internet off entirely is clearly not an option. We have to step forward and take on the challenge by finding a way to face the internet's negative side. The SOC — Security Operations Center — is the one called on to fight and defend what so far looks indefensible.
What is a SOC? Why are they needed?
SOC stands for Security Operations Center. Wikipedia's definition says: 'a SOC relates to the people, processes and technologies involved in providing methods for detecting, containing and remediating threats.'
What a SOC can give the company is continuous prevention, protection and detection of possible attacks inside its network. Knowing that a virus can spread across the network very quickly, every second counts.
Being able to stop an attack while it is happening, contain an infected file or prevent malicious traffic from leaving or entering your network is invaluable.
A SOC from scratch
A SOC can start with a single person with IT knowledge and access to the PCs and network devices. There are open-source tools that can be used for the implementation: Pfsense and Shorewall firewalls, IPS such as Snort and Suricata, IDS such as Bro and OSSEC, and a traffic analyser such as Wireshark.
To get everything in one place you can look at Security Onion, a Linux distribution specialising in intrusion detection, network security monitoring and documentation management.
There are tutorials that can teach you how to start, and there is even a book dedicated exclusively to Security Onion — how it works and how you can start your own SOC.



