The Value of Human Teams in a SOC: Enhancing Security Operations

Global, May 27, 2025

The Value of Human Teams in a SOC: Enhancing Security Operations

Why technology alone isn't enough to safeguard your organisation

Technologies keep evolving, so it's challenging for companies to keep up with the pace and hire all the operational staff they need to acquire all the protection they need for security. By leveraging a Security Operations Center (SOC) service, businesses can externalise the operations and have specialists manage tools and threats 24/7.

The Human Element in a SOC

When we think about the SOC, we often envision the team that works there. What is the value of having a human team in the SOC? Having a SOC based solely on technology makes it predictable and easier for threat actors to bypass. The extra mile is when people configure the tools and handle operational tasks after the technology has done its part. Having a senior analyst look at how tools are used, and fine-tune processes is essential. Even with emerging technologies like SOAR or automation tools, senior analysts are needed to ensure everything functions optimally.

The Impact of AI on Security Threats

As of now, AI is not a threat actor by itself, but it is used by attackers to develop complex tools quickly. AI's role in security threats is evolving, making it imperative for SOC teams to stay ahead of the curve.

Advantages of XDR in a SOC

Extended Detection and Response (XDR) is crucial for SOC teams because it enhances both detection and response capabilities. XDR can automatically correlate data and take predefined actions on systems, such as blocking an IP address or responding to an endpoint threat. This automation and correlation make XDR an essential tool alongside vulnerability scanners and other security measures.

At Logicalis we recently announced the successful completion of our Cisco XDR CPS audit, to become one of only six partners in the world to have this prestigious title and the only partner to be able to deliver Cisco XDR as a global managed service. This gives our customers confidence they are receiving the best-in-class managed service utilising the advanced technology from Cisco XDR.

Evolving Threats and Ransomware

Over the last three years, ransomware has evolved significantly. Our 2025 CIO Report surveying 1,000 tech leaders across the globe identified that 88% of organisations experienced a cybersecurity incident in the past year, with malware and ransomware attacks accounting for 42% of these breaches. 

Threat actors have developed new methods for gaining initial access to systems, escalating privileges, and performing lateral movements. Statistics show that ransomware is growing rapidly and becoming more sophisticated. The severity of these threats is also increasing, with larger ransoms and more damage to business operations being observed.

In conclusion, while technology plays a vital role in SOCs, the value of human teams cannot be understated. Senior analysts and specialised personnel are crucial for configuring tools, fine-tuning processes, and staying ahead of sophisticated threats. The integration of advanced technologies like XDR further enhances the capabilities of SOC teams, making them better equipped to protect organisations from evolving security challenges.

For more details, visit our MXDR page and SOC page.

Topic

Related Insights