Louis Zezeran
8. okt 2026
Inside the SOC: what really happens between the alert and the answer
When a security alert fires at 3am on a holiday, who looks at it? In many organizations the honest answer is “an automated rule, and maybe someone on call.” At NEVERHACK Estonia, the answer is a person.
In this episode of the Cybercast by NEVERHACK, host Louis Zezeran, Technical Sales Engineer, is joined again by Fotul “Forhan” Karim Forhan, Head of SOC at NEVERHACK Estonia. Their first conversation covered the philosophy of a Security Operations Center and how aspiring analysts can prepare for the job. This second part goes onto the SOC floor. It follows an analyst’s day from the shift handover to the client escalation, and asks a bigger question: what is a SOC actually for?
If you buy managed security services, run a SOC or want to work in one, this episode gives you a rare, frank view from the inside.
One queue, many tools
Forhan begins with a problem every managed security service provider (MSSP) knows well. NEVERHACK does not serve one client. It serves many organizations, from small businesses to large enterprises, and each runs its own security stack. Forhan estimates the team works with four to eight different EDR products and three or four SIEM platforms.
Analysts do not jump between a dozen consoles. Instead, everything is funneled into one ticket queue. NEVERHACK built a custom integration layer that pulls the key context into each ticket: the timeline, file hashes, the type of malware and more. An analyst does not open a ticket that just says “malware found on this device”. They open one that already tells most of the story.
Key takeaway: Tool sprawl is unavoidable for an MSSP, but analyst sprawl doesn’t have to be. A normalized, enriched queue lets people spend their time on judgment instead of copy-paste.
The handover: no ticket belongs to one person
An analyst’s day starts with coffee, a chat with colleagues and a handover from the previous shift. The handover follows a set format. It covers what happened, any critical or interesting events, which tickets are carried over and how urgent they are. Serious incidents already have a bridge call and a group chat running before the new shift sits down.
One principle stands out. At NEVERHACK, no ticket is one analyst’s private responsibility. This is for standardization and transparency, and Forhan links it to a “six-eye” principle of shared oversight. Knowledge stays with the team, not with one person.
Coverage is also non-negotiable. The SOC runs 24/7, 365 days a year, including weekends and Christmas. Forhan notes that in the past four years there has not been a single day without people on shift. Many providers offer “24/7 monitoring” that relies on automation and an on-call phone at night. NEVERHACK puts humans behind the automation, because, as Forhan says, “the best judgment comes from human.”
Why the vendor’s “critical” isn’t the final word
This is one of the most useful parts of the episode for anyone who buys security tools. Every EDR and SIEM assigns its own severity. Defender might call something critical, and another product might call it high. Forhan explains that NEVERHACK does not simply accept that label.
Each client’s infrastructure is different, so what is critical for one may be routine for another. The first step for an analyst is initial triage. They correlate the alert, often look briefly in the source platform, and set NEVERHACK’s own priority. That priority decides the order of work. High and critical alerts are handled first, and anything judged low goes back into the queue while the next unprioritized ticket is triaged.
The reason is simple. If analysts dug into every low alert as it arrived, a critical one could sit untouched past its deadline. Prioritization by human judgment protects the response time that matters most.
Key takeaway: Severity is about context. A good SOC re-scores alerts against your environment rather than repeating the vendor’s label.
From investigation to escalation
After prioritization comes the deep work. Analysts look beyond the events in the alert itself. They examine earlier data, what happened next, and related sources. An EDR alert might be checked against firewall and network logs or identity data in Entra ID and Active Directory. The aim, in Forhan’s words, is “contextual awareness”: getting everything into one picture.
NEVERHACK encourages analysts to use the Analysis of Competing Hypotheses (ACH), a structured method from intelligence analysis. Analysts weigh several explanations of an event against the evidence before reaching a verdict. When a threat is confirmed, it goes through an escalation process. Critical incidents follow one path, and medium and low findings follow another. If the client has given NEVERHACK the right permissions, the team also resolves the issue directly, for example by isolating a device or changing firewall rules.
Beyond tickets, analysts also work on automation, detection engineering and process writing. The day is not only about alerts.
Radical transparency: “there is no hiding”
One of the episode’s strongest themes is NEVERHACK’s client portal. Clients do not only see the tickets that get escalated to them. They see every ticket about their organization, in real time. That includes past months, who is working on a ticket right now, the SLA timings (when the ticket was picked up and when it was escalated) and the analysts’ own investigation notes.
Forhan admits this level of visibility is rare among MSSPs. He says it reflects confidence in the team’s work. Louis adds that the notes clients see are not raw tool output. They are mostly findings that a human analyst has processed. If an SLA is missed, it is visible. As Forhan says, it makes the job “more fun and more client-oriented, because you know that you are doing a good job… So there is no hiding.”
Key takeaway: When evaluating a SOC provider, ask what you will actually be able to see. Transparency is a strong sign of quality.
Rules of engagement and the trust gap
Louis shares a memorable story from a recent summit. On stage, he discussed rules of engagement: the agreement on which actions the SOC may take on its own, such as isolating an endpoint or closing a firewall port. Some clients let NEVERHACK act quickly. A few say “don’t touch a thing; tell us, and we’ll act.”
Louis argued that this is a trust and education challenge for the provider, not a criticism of the client. Then he looked into the third row and caught the eye of one of those very customers, who smiled and gave him a thumbs up.
The point is serious. Detection can be fast, but if every response waits for client approval, attackers gain time. Trust is built step by step, and it is the provider’s job to earn it.
What a SOC is really for: fewer alerts over time
Asked how clients see value from a SOC when nothing bad happens, Forhan gives the episode’s most thought-provoking answer: “SOC doesn’t want to deal with alerts.”
Monitoring and detection are the baseline. The real goal is to raise the client’s security maturity. A SOC with full visibility sees configuration gaps, weak policies and missing controls. NEVERHACK’s analysts do not only report incidents. They recommend changes to policies and configurations, through individual tickets and in monthly meetings. Forhan compares it to vulnerability management: find the weakness, then close it.
Clients who act on this advice see fewer attacks and fewer tickets over time. That lowers the workload on both sides and frees the SOC to spend more time on threat hunting and better detection rules. With trust in place, there is a final benefit: the client can sleep better. “I don’t want to call the clients at midnight,” says Forhan. The next morning, they simply learn there was an attack, it was stopped, and all is well.
Key takeaway: Measure your SOC by how much it improves your security posture, not by how many alerts it processes.
Analysts who stay
Louis observes that analysts often stay longer at NEVERHACK than the industry average. Forhan, speaking from his own time as an analyst, credits the tierless model. SOC work is often seen as a short entry point to a cyber career, but at NEVERHACK analysts take part in client conversations, see the full picture and see the impact of their recommendations. They can also grow into engineering work without leaving the SOC. Forhan stresses that a modern SOC includes platform, automation and detection engineers, and that understanding analyst work makes those roles better.
The conversation ends with Louis reflecting on NEVERHACK’s investment in research and development, its Center of Excellence in Tallinn and its offensive security team. He also shares a lesson in leading multilingual teams: trust your people, and let a colleague run an engineering meeting in Estonian if that serves the customer better. Forhan closes on teamwork: what matters is that “we are rowing in the same direction.”
Why you should listen
This episode is a practical, honest look at how a modern SOC works. You will learn:
- How an MSSP manages alerts from many tools in one queue
- Why human prioritization beats vendor severity scores
- How structured methods like ACH improve analyst verdicts
- What true SOC transparency looks like, and why it builds trust
- Why the best SOC is working to make itself less busy
Listen now to the full episode of the Cybercast by NEVERHACK. Visit our website to learn more about NEVERHACK’s SOC services, and subscribe so you don’t miss next month’s episode. You can also connect with Louis and Forhan on LinkedIn to continue the conversation.