Loading summary
N2K CyberWire Host
You're listening to the Cyberwire Network powered by N2K. This episode is supported by Black Hat usa. If you follow the research, you know a lot of it breaks on. Black Hat stages hundreds of peer reviewed briefings, more than 100 hands on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow, August 1st through the 6th, use code CYBERWIRE for $200 off your briefings pass@blackhat.com we'll see you in Vegas. If you're heading to Black Hat USA this year, make plans to visit the Spectrops Kennel Club. As creators of Bloodhound, the Spectrops team will host talks with OpenAI and the UK AI Security Institute, as well as hands on workshops aimed at helping you understand AI accelerated attack paths and the latest in identity trade craft. Visit Spectrops IO to pre register and learn more. SpectreOps Kennel Club is adjacent to Libertine Social inside Mandalay Bay. While you're there, visit the N2K CyberWire podcast studio where where we'll be capturing expert perspectives and conversations from across Black Hat. You're listening to the Cyberwire Network powered by N2K. Most environments trust far more than they should, and attackers know it. ThreatLocker solves that by enforcing default deny at the point of execution. With ThreatLocker allowlisting, you stop unknown executables cold. With ring fencing, you control how trusted applications behave, and with Threat Locker DAC defense against configurations, you get real assurance that your environment is free of misconfigurations and clear visibility into whether you meet compliance standards. ThreatLocker is the simplest way to enforce zero trust principles without the operational pain. It's powerful protection that gives CISOs real visibility, real control, and real peace of mind. ThreatLocker makes zero trust attainable even for small security teams. See why? Thousands of organizations choose ThreatLocker to minimize alert fatigue, stop ransomware at the source, and regain control over their environments. Schedule your demo@threatlocker.com N2K today.
Rick Howard
The word is soc, Spelled S for security, O for operations, and C for center. Definition A centralized facility or team responsible for monitoring, detecting, detecting, analyzing, and responding to cybersecurity incidents within an organization. Example sentence SOC teams are typically staffed with skilled security analysts, incident responders, threat hunters, and other cybersecurity professionals who work in shifts to provide 24x7 monitoring and response capabilities. Origin and Context the idea of operations centers has been around seemingly forever. Friedrich Klim, in his A History of Western Technology, suggests that the concept goes as far back as 5000 BC. Klem said that anytime an organization grows big enough, either in terms of people or in function where one small team can't do everything, leaders have built these centers to manage the workflow and status of the various groups and to coordinate actions among them. Fast forward to the early 1960s. AT&T handled most telephone switching in the United States and built a network operations center to manage it in 1977 in Bedminster, N.J. in the aftermath of the infamous Morris worm. In 1988, the first destructive Internet worm, the Defense Advanced Research Projects Agency, a science and technology organization of the U.S. department of Defense, sponsored Carnegie Mellon University to establish the first Cert Coordination Center, CERTCC in 1988. By 1990, the Forum of Incident Response and Security Teams first had become a non profit to bring together incident Response and security teams from every country across the world to ensure a safe Internet for all. As of Today there are 657 teams and in 101 different countries that belong to FERS. On the commercial side, it's unclear of the exact date, but we started to see the first Managed security service providers, MSSPs in the late 1990s and early 2000s. MSSPs are essentially contracted SOCs. President Clinton established the ISAC system, the Information Sharing and Analysis Center Framework, when he signed Presidential Decision Directive 63 on May 22, 1998 in an effort to better protect the country's critical infrastructure. In February 2015, President Obama established the Information Sharing and Analysis Organization ISAO Framework, clearing the legal hurdles for all like minded organizations, not just critical infrastructure groups, to share threat intelligence with each other. Certs, ISACs, ISAOS and MSSPs provide SOC type services for those that can't do it themselves or provide supplemental help for those that can't. The bottom line is that when a task gets so big in scope that it requires multiple teams to complete it, an operations center is needed to coordinate those efforts. Just like Friedrich Klim said, in terms of cybersecurity, a SOC is a network defender's centralized point, either physical or virtual, where they bring in relevant information from all corners of the organization. Analysts review the information and make recommendations to leadership. Leadership makes decision decisions and then the SOC coordinates the deployment of those actions out to the individual organizational teams to execute. NERD Reference In 1979, AT&T distributed a documentary film called AT&T Long Lines about their Network Operations center in Bedminster, New Jersey and just revel in the glory of that 1970s jazz rock backbeat Pittsburgh, Kansas City, here.
AT&T Network Operations Center Narrator
It looks like we might be in for some trouble. Hi. Oh, before we start the tour, it'll only take a minute, if you don't mind. We've had some severe storms out here. We've really got generally hazardous conditions all along Tornado Alley. And our radio tower at Plains, Kansas is on emergency power. Okay, I'll tell you what. While you're checking the free plans will establish the restoration priorities.
N2K CyberWire Host
Keep us posted.
AT&T Network Operations Center Narrator
Keep an eye on the screen, please. Thanks for waiting. Sometimes the telephone network can't, you know, keeping the lines clear between more than 170 million telephones and making sure over half a billion local and long distance calls get to their destination every day. Well, that's quite a job. And basically, that's what we do here. Welcome to the Network Operations Center, NOC for short, and to AT&T Longlines headquarters here in Bedminster, New Jersey.
Rick Howard
Wordnotes is written by Tim Nodar, executive produced by Peter Kilpe and edited by John Petrick and me, Rick Howard. The mix, sound design and original music have all been crafted by the ridiculous, endlessly talented Elliot Peltzman. Thanks for listening.
N2K CyberWire Host
AI is transforming every industry, but it's also creating new risks that traditional frameworks can't keep up with with. Assessments today are fragmented, overlapping, and often specific to industries, geographies or regulations. That's why Black kite created the BKGA3AI assessment framework to give cybersecurity and risk teams a unified, evolving standard for measuring AI risk across their own organizations and their vendors. AI use. It's global, research driven, built to evolve with the threat landscape, and free to use because Black Kite is committed to strengthening, strengthening the entire cybersecurity community. Learn more@blackkite.com. Heading to Black Hat USA, the N2K CyberWire team will be on site recording from our podcast studio in the Spectrops Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, stop by the studio and meet the N2K CyberWire team. Spectrops Kennel Club is adjacent to Libertine Social inside Mandalay Bay.
Host: Rick Howard, N2K Networks
Episode Date: July 28, 2026
Theme: Deception, influence, and social engineering in the world of cyber crime
In this “Word Notes” edition of Hacking Humans, Rick Howard explores the concept of the Security Operations Center (SOC)—a critical hub for cybersecurity monitoring, detection, and response. The episode dives into the origin and evolution of operations centers, their role in defending against cyber threats, and how SOCs have become central to both organizational and global cyber defense strategies.
This episode provides a concise yet comprehensive overview of Security Operations Centers, illustrating their critical function in modern cybersecurity with both technical definition and rich historical context. Listeners gain a clear understanding of the SOC’s evolving role as the backbone of organizational and national cyber defense efforts—rooted in necessity as threats grow and operations become more complex.
For more word origins and security insights, tune into Hacking Humans on the CyberWire Network.