The sheer complexity of ordering and configuring a SOC room inside your own company has always been a deterrent, even for organizations to which an operations center is fundamentally important.
The questions everyone asks
What is a SOC for?
A Security Operations Center (SOC for short) is the part of a company tasked with monitoring the security of the corporate infrastructure and keeping up with the latest developments in vulnerabilities and attacks.
Who is responsible for the SOC?
The person who sets the SOC’s direction is usually the same one responsible for information security across the organization. A SOC is built to be autonomous, but a degree of coordination is needed in order to establish the guidelines to adopt, and to define the department’s duties properly.
Who works inside the SOC?
SOC operators are IT technicians, often specialized in cybersecurity or otherwise trained for the role. Their purpose is to use the tools available to monitor the company’s information security, to design and improve the company’s cybersecurity, to respond to and investigate incidents, to keep up with the latest vulnerabilities and attacks, and to make sure the company is ready to face them.
Which tools are used inside a SOC?
Besides the physical tools (such as the video wall and the operator stations), the main software tools are: an event and alarm management system (a SIEM, for example), a network monitoring system for anomaly detection, tools for the forensic analysis of disks and network traffic, a system for monitoring the latest vulnerabilities and attacks worldwide, and a defence system to act when an attack is detected.
How does the SOC interface with my infrastructure?
The software installed inside the SOC can interface with the company in several ways: if the company already has software and appliances monitoring alarms, events, logs or network traffic, the SOC can connect to them; moreover the security applications already in use (firewalls, endpoint protection and so on) can be managed by the SOC for monitoring and response in case of an attack.
What are the main difficulties I might run into?
If your company lacks technical staff to run the SOC, we can supply trained operators, remotely or on site, or we can train technical staff the company already has. If the company has no monitoring software configured yet, we can help set up a new monitoring system in the SOC to start collecting the most important data. And if the company has no well-defined security policies, or vague procedures for configuring the security of the infrastructure, we at Trantor® help you put it all down in writing.
The team behind Trantor® is trained to follow closely those companies venturing into building an internal SOC. The solution Trantor® proposes is meant to speed up both the commissioning of the SOC and the training of the people who will work in it.
An entire SOC, in one cabinet
The SOC does not arrive as a list of separate orders: it arrives as a system. Trantor® handles transport, assembly and configuration, and you find everything standing and working in your datacenter. This is the standard supply, item by item.
32 units: the entire SOC infrastructure arrives cabled and tested inside it.
The SOC platform: the applications and the operator VDIs run virtualized on Trantor® TVirt©.
The laboratory where potentially malicious software is examined and tested: separate by design.
The SOC’s internal network, redundant in high availability.
The SOC’s perimeter, redundant in high availability.
Power continuity for rack, servers and network. Redundant in high availability.
Five operator stations, one of which is the malware-lab station. Each one: a thin client reaching its own VDI through Trantor® VDesk, two 28-inch 4K 60 Hz monitors, speakers, mouse and keyboard.
Power continuity for the five operator stations.
Four 75-inch 4K 60 Hz screens with a video matrix: the situation always in view of the whole team.
«The SOC is not an integration project: we assemble it, cable it and commission it ourselves. Turnkey.»
Transport, assembly, training
Transport is our business
A whole SOC cannot travel assembled, and that is not your problem: components and machines travel with us, all the way to your datacenter.
Assembled and cabled on site
Rack, servers, network, stations and video wall: the Trantor® team assembles and cables everything on the spot, down to the last cable. The malware lab stays on separate machines, separate by design.
Delivered and commissioned
We leave only once the system is standing: configured, tested, working. On-premise, inside your perimeter: the operations room is yours from day one.
Training on site or remotely
Our team trains the staff who will run the SOC, so that you end up completely self-sufficient.
32 units, one single system: redundant firewalls and switches at the top, the four TVirt© servers in the middle together with the malware lab, power at the bottom. This is what gets assembled in your datacenter.
The technology behind the SOC is home-grown
The applications and the operator VDIs run virtualized on TVirt©, malware lab included: separate by design, on its own machines.
Every operator station is a thin client reaching its own VDI through Trantor® VDesk.
Last updated: 10 August 2026. The contents of this page follow the brochure of that revision.
Let’s talk.
A session on your perimeter: what the SOC needs to see, who will operate it, where the cabinet will stand. All tailored to your company.

