Inside a 24/7 security operations center
A security operations centre is far quieter than the film version. The work is procedural, the pace is deliberate, and the difference between a contained incident and a breach is usually decided in the first quarter of an hour.
Across our twelve command centres, median time from detection to triage is four minutes. That number is not a function of how fast analysts read. It is a function of how much context arrives with the alert — asset criticality, recent changes, the last three similar detections and what they turned out to be.
Context is the whole job
An alert without context forces an analyst to reconstruct the environment from scratch under time pressure. An alert with context turns the same decision into a comparison. Most of the engineering investment in a mature SOC goes into that enrichment layer, not into the detections themselves.
The maturity of a security operation is measured in what an analyst does not have to look up.
The second investment is in rehearsal. Teams that exercise containment monthly make the call faster than teams that have only read the runbook, and the gap widens under genuine pressure. We schedule exercises the way infrastructure teams schedule failover tests — on a calendar, with results reviewed.
What we would change first
If a client asked for one improvement before anything else, it would rarely be a new tool. It would be to name, in advance, the person with authority to disconnect a production system — and to make sure that person is reachable at three in the morning on a public holiday.