What the SOC actually does
A modern SOC has four core jobs. Collect telemetry from endpoints, servers, network devices, cloud platforms, identity providers and applications. Correlate and detect patterns that suggest an attack — credential abuse, unusual lateral movement, suspicious file activity, data exfiltration. Triage and investigate alerts to separate real threats from noise. Respond by containing affected systems, recovering, and producing the evidence the institution and its regulator need.
Why “after hours” matters in Kenya
Most attacks aimed at Kenyan financial institutions originate from groups operating in time zones eight hours ahead or six hours behind Nairobi. The peak of ransomware deployment activity sits between 10pm and 5am local time — precisely when in-house IT teams are off shift. A 24/7 SOC closes that window. It is also when regulator-relevant events — failed audit logs, integrity issues, anomalous payment instructions — most often slip past unmonitored controls.
What good looks like
- Defined SLAs: critical alerts triaged within 15 minutes, containment within an hour.
- Named analysts, not anonymous queue handlers.
- Coverage of endpoint, network, cloud and identity — not just one signal source.
- Detection content updated weekly against current threat intelligence.
- Monthly executive reporting and quarterly tabletop exercises.
- Pre-agreed incident response retainer for when something does break through.
What CBK and SASRA expect
The Central Bank of Kenya’s cybersecurity guidance and SASRA’s ICT risk framework both expect continuous monitoring, independent testing, documented incident response and timely incident reporting. A managed SOC is the most efficient way to evidence all four — and to do so without trying to recruit a 24/7 security team that, in 2026, is essentially unhireable at scale in Nairobi.
Build or buy?
Building an in-house SOC at the scale a Tier-1 bank can sustain requires 12–18 people, a SIEM, detection engineering, threat intelligence and 24/7 shift cover. For most Kenyan institutions, partnering with a managed SOC delivers the same outcomes at a fraction of the cost — provided the partner is local, accountable and operating at the standard your regulator expects. That is the bar Market Light operates to.