
Day 8: Security Operations Centre (SOC) 101
The regulator did not ask the question our technology team expected. We had spent weeks preparing architecture diagrams, firewall maps, endpoint statistics, licence schedules and a beautiful slide showing a Security Operations Centre with six large screens. Then the supervisor looked across the table and asked: “If someone steals an administrator’s credentials at 2:00 a.m., who sees it, who decides, and how quickly can you stop it?”
That question captures what many organisations misunderstand about the regulatory demand for a SOC. Regulators are not really asking you to build a television studio filled with blinking dashboards. They are asking you to prove that your institution can continuously detect suspicious activity, investigate it, contain damage, preserve evidence, escalate serious incidents and recover safely. Bank of Uganda’s public information-security position stresses risk-informed protection, incident management, operational resilience, monitoring and continuous improvement. That is the substance, the rest are optional.
I learned this the expensive way.
Years ago, I watched a team buy an impressive security platform before deciding which events mattered. Within weeks, the analysts were receiving thousands of alerts. Most were noise. The SOC was technically busy and operationally blind. Attackers do not care how many licences you purchased. They care whether your people notice the one abnormal event hidden among ten thousand normal ones.
I recommend you build or operate your SOCs from the incident backwards. I would take the following approach to operating a SOC.
First, I protect the crown jewels.
What we are told to do: collect every log from every device because “more visibility is better.”
What I actually do: identify the systems whose compromise would hurt the institution most, then instrument those first. I start with identity systems, email, internet-facing applications, payment platforms, critical databases, administrator activity, endpoints and backups. If money is tight, I would rather have excellent visibility over ten critical systems than poor visibility over five hundred.
For low-cost environments, I have used tools such as Wazuh for endpoint and security monitoring, Suricata or Zeek for network visibility, MISP for threat intelligence, and TheHive for incident case management. Open-source does not mean free. Someone must install, tune, patch and operate it. But it lets me spend scarce money on skilled people instead of impressive procurement ceremonies.
Second, I design detections around attacker behaviour.
What we are told to do: switch on every vendor rule and call the resulting alert stream “24/7 monitoring.”
What I actually do: begin with twenty high-consequence scenarios. A new administrator account appears. A privileged user logs in at an unusual hour. Antivirus is disabled. A mailbox suddenly forwards messages externally. Backups are deleted. PowerShell behaves strangely. Hundreds of files change rapidly. A dormant account wakes up. Data leaves the network unusually fast.
For each scenario, I ask four questions: what evidence will show it, who investigates it, what makes it critical, and what action can we take immediately?
That is a SOC.
Third, I measure decisions, not activity.
What we are told to do: report alerts received, tickets opened and incidents closed.
What I actually do: measure how quickly my team detects, understands and contains meaningful threats. I track critical-system coverage, false-positive rates, failed log sources, repeat incidents, time to escalation, time to containment and whether playbooks actually worked.
A regulator should be able to pick one serious incident and trace the entire chain: detection, analyst decision, escalation, containment, evidence, communication, recovery and lessons learned.
That audit trail matters more than the wall screens.
The resistance always comes from the same places. Procurement wants a product. Technology wants a project. Management wants a dashboard. Analysts want more people. Vendors want subscriptions.
I want evidence.
A small institution can begin surprisingly lean: two capable analysts, an experienced security lead, centralised logging, endpoint protection, vulnerability scanning, disciplined incident playbooks and an on-call escalation arrangement. Instead of pretending to staff a full 24-hour operation with exhausted employees, I often prefer a hybrid model: internal ownership during business hours, automated detection throughout, and a competent managed provider for nights, weekends and specialist escalation.
The important distinction is ownership. Outsourcing monitoring does not outsource accountability.
When I brief boards, I no longer ask whether the organisation “has a SOC.” I ask whether it can survive Tuesday night.
Can we see an attacker using stolen credentials? Can we isolate the machine? Can we disable the account? Can we preserve evidence? Can we contact the decision-maker? Can we keep serving customers?
If the answer is yes, I have a SOC. If the answer is no, I have furniture, software licences and a regulatory problem.
My rule is simple: build the response muscle before buying the gym. Start small, test relentlessly, document every decision and improve monthly. Regulators can forgive modest technology. Customers may forgive an attempted attack. Neither will forgive an institution that collected warnings, missed the obvious, and could not act.
I remain, IFIS Faculty champion
This October, we are extending that conversation beyond the SOC room.
Cybersecurity Awareness Month is the right moment for boards, executives, auditors, risk leaders, IT teams and frontline staff to confront one uncomfortable question: if an attack starts tonight, are we actually ready?
Join us during this Cybersecurity Awareness Month 2026 that runs from 1st to 30th October 2026 for practical sessions, demonstrations and executive conversations on detecting attacks earlier, responding faster and building resilience without wasting money on security theatre. Come with your toughest questions, current gaps and real constraints. Leave with actions you can implement immediately.
Cybersecurity awareness is not an IT campaign. It is an organisational survival discipline. Be part of the conversation today.



