Megatrend · Cybersecurity & Digital Trust
Every company gets attacked every day — this is the “control room” that catches what slips through
No matter how good your firewall is, something always gets through in the end. The real question isn't “can we block it” but “how fast can we see it — and respond in time?” That work happens in a room called the SOC (Security Operations Center) — a monitoring hub that pulls logs from every part of the organization into one place, hunts for the shadow of an intruder, and shuts the door before the damage spreads. Behind it sit four families of tools (SIEM · SOAR · XDR · MDR) that are turning into a multi-billion-dollar battlefield — and the spot where AI is changing how the work gets done fastest.
01What it is (the four letters you need to know)
When people hear “cybersecurity,” most picture walls — firewalls, antivirus, passwords. That's the protection side. But there's a truth the industry has long accepted: no matter how good the wall, one day it gets breached. An attacker only needs one gap; the defender has to plug every one.
That's why this node exists — Security Operations, the detection & response side. It starts from the opposite assumption to the wall: “assume the enemy is already in — how fast can we find them?” The work happens in a room called the SOC (Security Operations Center), where people, tools, and procedures run 24 hours a day to “catch what slips through.”
The tools in this room split into four main families — four acronyms that sound scary but are actually easy once you see them as “job roles” in the same room:
- SIEM (the eye that sees everything): short for Security Information & Event Management — the heart of the SOC. It pulls logs and alerts from every part of the organization — servers, employee machines, cloud, email — into one place, then hunts for “suspicious patterns.” It's the organization's “central logbook.”
- SOAR (the hands that act): short for Security Orchestration, Automation & Response — when SIEM finds something, SOAR is what acts automatically along a ready-made procedure (a playbook). For example: “if this machine is infected with malware → cut it off the network immediately → alert the team” — without waiting for a human to click anything.
- XDR (connects the puzzle): short for eXtended Detection & Response — instead of watching each spot separately, XDR links clues across everywhere — endpoints, network, cloud, email — to piece together what one attack actually passed through.
- MDR (rent a professional team): short for Managed Detection & Response — for companies without their own SOC team (which is most companies on Earth), MDR means “renting” someone else's SOC — an outside firm that watches around the clock. It's like hiring a security company to guard your building instead of staffing your own guards.
Cybersecurity has two halves · Protection = keep them out (firewalls, antivirus) · Detection & Response = assume they're already in, then quickly find and evict them. This node is the second half — and the key number everyone measures is “dwell time”, how long an intruder hides in the system before getting caught. Shorter is better.
On the megatrend map, this node is a sub-theme of Cybersecurity & Digital Trust and sits in the “platform layer” — not the wall itself, but the system that sits above everything to watch what's happening. If Endpoint & Network Security is the “guard at the door,” the SOC is the “central camera room” that sees every door at once.
02Why it matters — catching what slips through
The first reason is simple logic you can't argue with: the most damaging attack isn't the one that gets blocked — it's the one that slips in and goes unseen for months. The ransomware that locks down a whole hospital, or the leak of millions of customer records, usually starts at a small gap the wall missed, then creeps quietly through the system until it's too late. The SOC's job is to shrink that “quiet” window as much as possible.
The second reason is money — and it's a far bigger market than most people think. SIEM (the heart of the SOC) alone is worth around $10–11B in 2025 and is expected to grow to roughly $19B by 2030 (about 12% a year). The MDR market (SOC-as-a-rental) is smaller but growing harder, at about $4B in 2025 and climbing around 20% a year — a sign that huge numbers of companies are choosing to “rent a team” rather than build their own.
But the third reason is what makes this node “important and painful” at once: not enough people, too much to look at. The world is short about 4 million cybersecurity specialists (per ISC2's survey), while the volume of alerts to review keeps flooding in. A typical organization gets about 3,000 alerts a day, but more than 60% are never touched — because there aren't enough people to keep up.
Put simply, the biggest problem for today's SOC isn't “we can't see” but “we see too much to find the real thing” — which is why every conversation about the SOC in 2025–2026 loops back to one thing: can AI sift through this pile of alerts?
03How it works (the SOC's assembly line)
The best way to understand the SOC is to see it as “an assembly line that turns a flood of raw data into decisions”. Raw data comes in one end, defensive action goes out the other, and along the way there are four stations — matching the four acronyms exactly.
- Collect (SIEM): records from everywhere — thousands of employee machines, servers, cloud, email — flow into the SIEM, which acts as a searchable “central logbook.”
- Connect the puzzle (XDR): scattered records alone don't show the picture. XDR links the clues dot to dot — “suspicious email on machine A → a strange login on the cloud → a file copy on server B” — and tells you “this is one and the same attack, not three separate things.”
- Respond (SOAR): once it's confirmed as a real threat, SOAR runs the playbook automatically right away — cut the infected machine off the network, reset passwords, open a ticket — in seconds, not hours.
But between “collect” and “respond” sits the real bottleneck: people. Thousands of alerts a day need someone to sort the real from the fake. This is where AI steps in — playing the “first-line analyst,” narrowing the pile of alerts down to the few a human really has to decide on. MDR, meanwhile, lifts this whole assembly line out to an outside firm with a team of experts running it for you.
04The most expensive problem: data flood & exploding bills
If you understand just one thing about this node, understand this: most SIEMs charge by “the volume of data they ingest” (per gigabyte). Sounds reasonable — until you remember just how much logging the modern digital world produces. Every click, every login, every network packet becomes data that gets ingested into the SIEM and billed.
The real numbers bring it into focus — Splunk, the original SIEM leader, charges roughly $1,000–3,500 per gigabyte per year. For an organization ingesting 5 terabytes a day (not an unreasonably large amount for a big company), the ingest cost alone can run around $3.6–7.3 million a year — before infrastructure and people, which add another 30–50%.
This problem creates a self-contradicting tension: the safer you want to be, the more data you need to collect — but the more you collect, the more the bill explodes. So security teams get pushed into dangerous calls, like “let's just stop collecting this log, it's wasteful” — and sometimes the one they cut turns out to be the key clue to the next attack.
Old SIEMs had to index every piece of data up front, which was expensive and slow · Next-Gen SIEM (like CrowdStrike's, which uses the LogScale engine) takes an “ingest first, search later” (index-free) approach, so you can keep more data at a lower cost and search it much faster. This is the new battlefield — the challengers attacking the incumbent's most expensive weak spot head-on.
This is why the biggest deal in Cisco's history — buying Splunk for $28B (closed March 2024) — shook the industry so hard. It wasn't just buying a company; it was a bet that “whoever controls the SOC's data controls the heart of all security.” And at the same time, new challengers are eating in from another direction: cheaper to charge, longer to keep.
05How it connects in the ecosystem
The SOC is the “central brain” of security. So it has to take in data from every layer and is tightly wired to the rest of the trends:
- Feeds on data from Endpoint & Network Security: the front-line guards (endpoints, network) are the “sensors” that feed signals to the SOC — which is why CrowdStrike, having started in endpoint protection, moved into SIEM easily: it already had the data in hand.
- Overlaps with Observability & DevOps on “the same log data”: the logs engineers use to find “where is it slow” and the logs security teams use to find “is anyone breaking in” are usually the same set — which is why Cisco buying Splunk is slowly fusing these two worlds.
- Has to handle AI Security & Agent Guardrails: once organizations start using AI agents for real work, the SOC gets a “new surface” to watch — AI that's been tricked, hacked, or gone off the rails becomes a threat the SOC has to catch.
- Driven by AI and Agentic AI: AI isn't just something to watch — it's becoming a “tool in the SOC's own hands,” the first-line analyst that sifts alerts in place of people (this is the heart of the next chapter).
Put another way, every time the world adds something new to protect — cloud, IoT devices, AI agents, digital finance systems — the SOC gets more “things to watch” too. So it's a trend that grows with the complexity of the entire digital world. The more we lean on software, the more indispensable the control room that catches what slips through.
06Where it stands now + the players
The 2025–2026 picture of the SOC has two big currents colliding.
The first current is the “platform war” (consolidation). Organizations used to run dozens of scattered security tools, but now everyone wants to cut down to a single platform that can do SIEM + XDR + SOAR in one place. The result: the giants are flooding in to claim this ground. Cisco bought Splunk ($28B), Microsoft pushed Sentinel (cloud SIEM) into the lead, while CrowdStrike and Palo Alto, which started in endpoint protection, are charging into next-gen SIEM from another direction.
The second current is a clash of “pricing philosophies”. The incumbent Splunk charges by data volume (expensive as you grow), while the challenger CrowdStrike touts Next-Gen SIEM that “ingests first, searches later” — far cheaper and many times faster to search. The numbers tell the story clearly: CrowdStrike's Next-Gen SIEM alone has already crossed $585 million in annual recurring revenue (ARR) — from zero in just a few years.
The third current is quiet but big — MDR, “renting a SOC”. Most companies in the world can't afford to staff their own 24-hour monitoring team (short on both people and budget), so they turn to outside experts. This market is growing around 20% a year, and the leader Arctic Wolf (private) does about $541 million in revenue, up around 23% — a sign that “expertise you can rent” is a product the market wants in huge volume.
07The road ahead: an AI-driven SOC
The future of this node has one word that dominates every conversation: AI. And the reason loops back to the same problem — people overloaded, alerts flooding, the real thing lost in the pile.
The hottest phrase of 2025–2026 is “agentic SOC” — the idea of an AI agent playing the “first-line analyst (Tier-1)” in place of a person: receiving alerts, pulling context from across the system, connecting the dots, and ruling on whether it's real or fake — then passing on only what truly needs human judgment. Many vendors claim AI can handle as much as ~90% of first-line triage, which hits the target exactly, because Tier-1 is the repetitive, monotonous work people get most bored with and quit.
But here's where you have to be careful — strong as the wave is, the reality is it's still just beginning. Per Gartner's 2025 report, the “AI SOC agent” is still an earliest-stage technology, with real use at only about 1–5% of the target market. The gap between “what's sold on the slide” and “what actually works in an organization” is still fairly wide.
The second direction is consolidation that doesn't stop. Customers will keep pushing harder for a single platform that does everything, and multi-billion-dollar consolidation deals will keep coming — the big questions being how many large players are left in the end, and how much the cloud giant (Microsoft) swallows the market with “SIEM that already comes bundled with the cloud.”
08Challenges & risks
The SOC is a trend that's “certainly necessary,” but the road ahead is full of traps that both investors and users need to understand.
The first risk is the “bill that explodes with the data”. A pay-by-volume model is both a money printer (revenue grows on its own as data grows) and a weakness — when an organization tightens its belt, the first thing on the chopping block is “cut the SIEM cost.” That expense opens the door for cheaper challengers like Next-Gen SIEM to take the incumbent's customers head-on — the player who once had the edge from “locking customers in” may lose margin in a price war.
The second risk is “alert fatigue,” harder to fix than it looks. The people shortage doesn't vanish easily, because ~70% of SOC analysts report burnout and the younger generation quits very fast. If AI really solves this as claimed, it's gold — but if it only gets halfway there, the staffing shortage keeps weighing on the whole industry.
The third risk is “overhyped AI-SOC” (hype). Every vendor slaps on the “AI” and “agentic” labels, but real use is still only 1–5% of the market. The danger is that organizations may trust AI too much — letting it decide on its own to cut systems off or shut accounts down — and if the AI gets it wrong (both catching false ones and letting real ones through), the damage lands on the organization. AI in security is a double-edged sword: it helps the defenders, but attackers also use AI to craft more convincing attacks.
The fourth risk is consolidation that swallows the small players. As the giants (Cisco, Microsoft, Palo Alto, CrowdStrike) all rush to build platforms that do everything, the small specialized players risk getting squeezed out — either acquired or out-competed for customers. For investors, the question is “which platform will customers plug everything into” — because that's the one with the deepest moat.
In short: every company on Earth is tested on security every day, and the brutal truth is that something always slips through in the end. Security Operations is the quiet industry that does the “see it fast, fix it in time” work for us. It isn't as flashy as AI or chips, but as long as the world keeps leaning on software — and attackers keep getting smarter — this control room only gets more indispensable.