Extras · 1 of 4
A typical shift
In a SOC (security operations centre), you watch dashboards of alerts from across the company's network. Most are false alarms; you learn to tell in seconds. A real one means investigating: what did the attacker touch, is it still happening, who needs to know. You write it up and hand off at shift change. Outside the SOC, analysts review new systems for weaknesses, run phishing tests on staff, and patch what the last audit found. When a real breach hits, everything else stops.