Megatrend · Cybersecurity & Digital Trust

Every company gets attacked every day — this is the “control room” that catches what slips through

No matter how good your firewall is, something always gets through in the end. The real question isn't “can we block it” but “how fast can we see it — and respond in time?” That work happens in a room called the SOC (Security Operations Center) — a monitoring hub that pulls logs from every part of the organization into one place, hunts for the shadow of an intruder, and shuts the door before the damage spreads. Behind it sit four families of tools (SIEM · SOAR · XDR · MDR) that are turning into a multi-billion-dollar battlefield — and the spot where AI is changing how the work gets done fastest.

Category Cybersecurity & Digital Trust Level Sub-theme Layer platform layer Read time ~15 min
A quiet security control room with a single analyst sitting in front of a wall of monitors that pulls alerts from across the whole organization into one picture
ภาพประกอบ (hero.png)
The control room of security. When the walls can't hold everything, the most valuable thing is “visibility” — knowing who is inside the system right now.

01What it is (the four letters you need to know)

When people hear “cybersecurity,” most picture walls — firewalls, antivirus, passwords. That's the protection side. But there's a truth the industry has long accepted: no matter how good the wall, one day it gets breached. An attacker only needs one gap; the defender has to plug every one.

That's why this node exists — Security Operations, the detection & response side. It starts from the opposite assumption to the wall: “assume the enemy is already in — how fast can we find them?” The work happens in a room called the SOC (Security Operations Center), where people, tools, and procedures run 24 hours a day to “catch what slips through.”

The tools in this room split into four main families — four acronyms that sound scary but are actually easy once you see them as “job roles” in the same room:

  • SIEM (the eye that sees everything): short for Security Information & Event Management — the heart of the SOC. It pulls logs and alerts from every part of the organization — servers, employee machines, cloud, email — into one place, then hunts for “suspicious patterns.” It's the organization's “central logbook.”
  • SOAR (the hands that act): short for Security Orchestration, Automation & Response — when SIEM finds something, SOAR is what acts automatically along a ready-made procedure (a playbook). For example: “if this machine is infected with malware → cut it off the network immediately → alert the team” — without waiting for a human to click anything.
  • XDR (connects the puzzle): short for eXtended Detection & Response — instead of watching each spot separately, XDR links clues across everywhere — endpoints, network, cloud, email — to piece together what one attack actually passed through.
  • MDR (rent a professional team): short for Managed Detection & Response — for companies without their own SOC team (which is most companies on Earth), MDR means “renting” someone else's SOC — an outside firm that watches around the clock. It's like hiring a security company to guard your building instead of staffing your own guards.
Key terms
Detection & Response vs Protection

Cybersecurity has two halves · Protection = keep them out (firewalls, antivirus) · Detection & Response = assume they're already in, then quickly find and evict them. This node is the second half — and the key number everyone measures is “dwell time”, how long an intruder hides in the system before getting caught. Shorter is better.

On the megatrend map, this node is a sub-theme of Cybersecurity & Digital Trust and sits in the “platform layer” — not the wall itself, but the system that sits above everything to watch what's happening. If Endpoint & Network Security is the “guard at the door,” the SOC is the “central camera room” that sees every door at once.

02Why it matters — catching what slips through

The first reason is simple logic you can't argue with: the most damaging attack isn't the one that gets blocked — it's the one that slips in and goes unseen for months. The ransomware that locks down a whole hospital, or the leak of millions of customer records, usually starts at a small gap the wall missed, then creeps quietly through the system until it's too late. The SOC's job is to shrink that “quiet” window as much as possible.

The second reason is money — and it's a far bigger market than most people think. SIEM (the heart of the SOC) alone is worth around $10–11B in 2025 and is expected to grow to roughly $19B by 2030 (about 12% a year). The MDR market (SOC-as-a-rental) is smaller but growing harder, at about $4B in 2025 and climbing around 20% a year — a sign that huge numbers of companies are choosing to “rent a team” rather than build their own.

The size of the Security Operations market
2025 market value (billions of dollars) — SIEM is the core, MDR is the fastest-growing piece
Source: Mordor Intelligence (SIEM ~$10.8B 2025 → $19.1B 2030, CAGR ~12%), Mordor Intelligence (MDR ~$4.2B 2025, CAGR ~22%) — midpoints across several firms

But the third reason is what makes this node “important and painful” at once: not enough people, too much to look at. The world is short about 4 million cybersecurity specialists (per ISC2's survey), while the volume of alerts to review keeps flooding in. A typical organization gets about 3,000 alerts a day, but more than 60% are never touched — because there aren't enough people to keep up.

~60% of alerts are never looked at A typical organization receives about 3,000 security alerts a day, but roughly six in ten are never opened — and nearly half of the ones that are turn out to be “false positives.” This is the “gap born of overload” the whole industry is trying to fix.

Put simply, the biggest problem for today's SOC isn't “we can't see” but “we see too much to find the real thing” — which is why every conversation about the SOC in 2025–2026 loops back to one thing: can AI sift through this pile of alerts?

03How it works (the SOC's assembly line)

The best way to understand the SOC is to see it as “an assembly line that turns a flood of raw data into decisions”. Raw data comes in one end, defensive action goes out the other, and along the way there are four stations — matching the four acronyms exactly.

  1. Collect (SIEM): records from everywhere — thousands of employee machines, servers, cloud, email — flow into the SIEM, which acts as a searchable “central logbook.”
  2. Connect the puzzle (XDR): scattered records alone don't show the picture. XDR links the clues dot to dot — “suspicious email on machine A → a strange login on the cloud → a file copy on server B” — and tells you “this is one and the same attack, not three separate things.”
  3. Respond (SOAR): once it's confirmed as a real threat, SOAR runs the playbook automatically right away — cut the infected machine off the network, reset passwords, open a ticket — in seconds, not hours.

But between “collect” and “respond” sits the real bottleneck: people. Thousands of alerts a day need someone to sort the real from the fake. This is where AI steps in — playing the “first-line analyst,” narrowing the pile of alerts down to the few a human really has to decide on. MDR, meanwhile, lifts this whole assembly line out to an outside firm with a team of experts running it for you.

The SOC's assembly line Records from every source flow into the SIEM, get sifted by AI amid a flood of alerts, XDR connects clues across spots into one threat, then SOAR acts automatically in response Data sources across the organization Employee machines Cloud Servers Email SIEM Collect all the records 1 Alerts ~3,000/day AI Sift 2 Drop the fakes ~90% XDR Connect clues across spots 3 = the same attack SOAR Auto-respond in “seconds” 4 Cut infected machine · reset password · alert team
From raw logs to response. Collect (SIEM) → AI sifts the pile of alerts → connect the puzzle (XDR) → act (SOAR) — the colored circle is where AI stands in for the “first-line analyst,” the most overloaded job of all.

04The most expensive problem: data flood & exploding bills

If you understand just one thing about this node, understand this: most SIEMs charge by “the volume of data they ingest” (per gigabyte). Sounds reasonable — until you remember just how much logging the modern digital world produces. Every click, every login, every network packet becomes data that gets ingested into the SIEM and billed.

The real numbers bring it into focus — Splunk, the original SIEM leader, charges roughly $1,000–3,500 per gigabyte per year. For an organization ingesting 5 terabytes a day (not an unreasonably large amount for a big company), the ingest cost alone can run around $3.6–7.3 million a year — before infrastructure and people, which add another 30–50%.

SIEM costs spike with the volume of data ingested
Approximate annual ingest cost (dollars) by daily log volume — it grows in a straight line with the data
Source: Estimates from analysis of Splunk's public pricing (UnderDefense, SIEM cost calculators 2025–2026) at ~$2–4/GB ingested — real figures vary by usage and discounts

This problem creates a self-contradicting tension: the safer you want to be, the more data you need to collect — but the more you collect, the more the bill explodes. So security teams get pushed into dangerous calls, like “let's just stop collecting this log, it's wasteful” — and sometimes the one they cut turns out to be the key clue to the next attack.

Key terms
Next-Gen SIEM & “index-free”

Old SIEMs had to index every piece of data up front, which was expensive and slow · Next-Gen SIEM (like CrowdStrike's, which uses the LogScale engine) takes an “ingest first, search later” (index-free) approach, so you can keep more data at a lower cost and search it much faster. This is the new battlefield — the challengers attacking the incumbent's most expensive weak spot head-on.

This is why the biggest deal in Cisco's history — buying Splunk for $28B (closed March 2024) — shook the industry so hard. It wasn't just buying a company; it was a bet that “whoever controls the SOC's data controls the heart of all security.” And at the same time, new challengers are eating in from another direction: cheaper to charge, longer to keep.

05How it connects in the ecosystem

The SOC is the “central brain” of security. So it has to take in data from every layer and is tightly wired to the rest of the trends:

  • Feeds on data from Endpoint & Network Security: the front-line guards (endpoints, network) are the “sensors” that feed signals to the SOC — which is why CrowdStrike, having started in endpoint protection, moved into SIEM easily: it already had the data in hand.
  • Overlaps with Observability & DevOps on “the same log data”: the logs engineers use to find “where is it slow” and the logs security teams use to find “is anyone breaking in” are usually the same set — which is why Cisco buying Splunk is slowly fusing these two worlds.
  • Has to handle AI Security & Agent Guardrails: once organizations start using AI agents for real work, the SOC gets a “new surface” to watch — AI that's been tricked, hacked, or gone off the rails becomes a threat the SOC has to catch.
  • Driven by AI and Agentic AI: AI isn't just something to watch — it's becoming a “tool in the SOC's own hands,” the first-line analyst that sifts alerts in place of people (this is the heart of the next chapter).

Put another way, every time the world adds something new to protect — cloud, IoT devices, AI agents, digital finance systems — the SOC gets more “things to watch” too. So it's a trend that grows with the complexity of the entire digital world. The more we lean on software, the more indispensable the control room that catches what slips through.

06Where it stands now + the players

The 2025–2026 picture of the SOC has two big currents colliding.

The first current is the “platform war” (consolidation). Organizations used to run dozens of scattered security tools, but now everyone wants to cut down to a single platform that can do SIEM + XDR + SOAR in one place. The result: the giants are flooding in to claim this ground. Cisco bought Splunk ($28B), Microsoft pushed Sentinel (cloud SIEM) into the lead, while CrowdStrike and Palo Alto, which started in endpoint protection, are charging into next-gen SIEM from another direction.

A giant hand sweeping several scattered security tools together into a single platform
ภาพประกอบ (consolidate.png)
From ten tools to one platform. Customers are tired of stitching together ten brands of tools — that pressure is driving multi-billion-dollar consolidation deals.

The second current is a clash of “pricing philosophies”. The incumbent Splunk charges by data volume (expensive as you grow), while the challenger CrowdStrike touts Next-Gen SIEM that “ingests first, searches later” — far cheaper and many times faster to search. The numbers tell the story clearly: CrowdStrike's Next-Gen SIEM alone has already crossed $585 million in annual recurring revenue (ARR) — from zero in just a few years.

Challengers growing fast in the next-gen SIEM arena
Status figures for each player (dollars / customer count) — reflecting momentum, not the size of the whole company
Source: Cisco (Splunk adding ~$4B ARR), CrowdStrike (Next-Gen SIEM ARR ~$585M), Sacra (Arctic Wolf revenue ~$541M, +23%)

The third current is quiet but big — MDR, “renting a SOC”. Most companies in the world can't afford to staff their own 24-hour monitoring team (short on both people and budget), so they turn to outside experts. This market is growing around 20% a year, and the leader Arctic Wolf (private) does about $541 million in revenue, up around 23% — a sign that “expertise you can rent” is a product the market wants in huge volume.

Key players in this field
Note
We place the players by their role and share in each corner of the SOC, not raw market cap — because many of them do security as part of a much bigger business · Educational, not investment advice.
Splunk (Cisco)CSCO · US
US · the original SIEM leader
The SIEM/SOAR heavyweight that has ruled large enterprises for years. Cisco bought it for $28B in 2024 (adding ~$4B in ARR to Cisco) — now fusing into Cisco's networking and observability.
secondary · incumbent leader
MicrosoftMSFT · US
US · cloud SIEM leader
Microsoft Sentinel is a cloud SIEM that climbed to leader per Gartner/Forrester — its edge is bundling Defender (XDR) and Entra (identity) into one platform. Existing Microsoft customers can plug it in easily.
secondary · cloud platform
CrowdStrikeCRWD · US
US · Next-Gen SIEM challenger
Started in endpoint protection (Falcon), then stormed into SIEM with the LogScale engine's “ingest first, search later” approach — cheaper and much faster to search. Its Next-Gen SIEM crossed ~$585M in ARR from zero in a few years.
secondary · rising challenger
US · AI-first SOC
Pushing Cortex XSIAM — a SOC platform redesigned with AI at the core from the start (SIEM+XDR+SOAR combined), aiming to replace the entire traditional SOC. It has around 270 customers and is growing fast in the large-enterprise market.
core · AI-first SOC
Arctic WolfPrivate · US
US · MDR leader (SOC for rent)
One of the MDR leaders — “SOC-as-a-service” for organizations without their own team. Revenue around $541M (+23%), valued at ~$4.3B. It's the face of the “rent the expertise” trend.
core · MDR leader
Trend Micro4704 · JP
Japan · the Asian XDR
Japan's major security player, touting its Vision One (XDR) platform that links clues across email-machine-cloud-network — the Asian representative in an arena where most players are American.
core · XDR

07The road ahead: an AI-driven SOC

The future of this node has one word that dominates every conversation: AI. And the reason loops back to the same problem — people overloaded, alerts flooding, the real thing lost in the pile.

A tiny analyst standing under an unceasing rain of alerts, holding an umbrella, with only a few drops being real threats
ภาพประกอบ (flood.png)
A rain of alerts that never stops. Nearly half the alerts are “fake,” and ~60% are never looked at — this is the problem AI is being called in to solve.

The hottest phrase of 2025–2026 is “agentic SOC” — the idea of an AI agent playing the “first-line analyst (Tier-1)” in place of a person: receiving alerts, pulling context from across the system, connecting the dots, and ruling on whether it's real or fake — then passing on only what truly needs human judgment. Many vendors claim AI can handle as much as ~90% of first-line triage, which hits the target exactly, because Tier-1 is the repetitive, monotonous work people get most bored with and quit.

A simply-shaped AI assistant sifting an enormous pile of alerts down to the few it hands off to a human analyst to decide on
ภาพประกอบ (aisoc.png)
AI sifts, humans decide. The new direction isn't “AI replaces people entirely” — it's AI clearing away the repetitive work so people have time for what really takes a brain.

But here's where you have to be careful — strong as the wave is, the reality is it's still just beginning. Per Gartner's 2025 report, the “AI SOC agent” is still an earliest-stage technology, with real use at only about 1–5% of the target market. The gap between “what's sold on the slide” and “what actually works in an organization” is still fairly wide.

The second direction is consolidation that doesn't stop. Customers will keep pushing harder for a single platform that does everything, and multi-billion-dollar consolidation deals will keep coming — the big questions being how many large players are left in the end, and how much the cloud giant (Microsoft) swallows the market with “SIEM that already comes bundled with the cloud.”

08Challenges & risks

The SOC is a trend that's “certainly necessary,” but the road ahead is full of traps that both investors and users need to understand.

The first risk is the “bill that explodes with the data”. A pay-by-volume model is both a money printer (revenue grows on its own as data grows) and a weakness — when an organization tightens its belt, the first thing on the chopping block is “cut the SIEM cost.” That expense opens the door for cheaper challengers like Next-Gen SIEM to take the incumbent's customers head-on — the player who once had the edge from “locking customers in” may lose margin in a price war.

The second risk is “alert fatigue,” harder to fix than it looks. The people shortage doesn't vanish easily, because ~70% of SOC analysts report burnout and the younger generation quits very fast. If AI really solves this as claimed, it's gold — but if it only gets halfway there, the staffing shortage keeps weighing on the whole industry.

The third risk is “overhyped AI-SOC” (hype). Every vendor slaps on the “AI” and “agentic” labels, but real use is still only 1–5% of the market. The danger is that organizations may trust AI too much — letting it decide on its own to cut systems off or shut accounts down — and if the AI gets it wrong (both catching false ones and letting real ones through), the damage lands on the organization. AI in security is a double-edged sword: it helps the defenders, but attackers also use AI to craft more convincing attacks.

The fourth risk is consolidation that swallows the small players. As the giants (Cisco, Microsoft, Palo Alto, CrowdStrike) all rush to build platforms that do everything, the small specialized players risk getting squeezed out — either acquired or out-competed for customers. For investors, the question is “which platform will customers plug everything into” — because that's the one with the deepest moat.

The bottom line for beginners Security Operations is the “control room” that catches what the walls couldn't — three keys: (1) the main problem isn't “can't see” but “see too much to find the real thing” (alert flood + people shortage) · (2) the business battlefield is “how you price the data” — incumbents charge more by volume, challengers offer cheaper · (3) AI is both the biggest hope (clearing first-line work) and the most overhyped risk — whoever makes AI actually work in a single platform first is the winner of the next round.

In short: every company on Earth is tested on security every day, and the brutal truth is that something always slips through in the end. Security Operations is the quiet industry that does the “see it fast, fix it in time” work for us. It isn't as flashy as AI or chips, but as long as the world keeps leaning on software — and attackers keep getting smarter — this control room only gets more indispensable.

Explore this theme — live data, stocks & news →