In-house SOC or SOCaaS in the Swedish Public Sector: Investigation of the factors influencing the choice of Security Operations Center in the Swedish public sector
2025 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesis
Abstract [en]
In recent years there has been a significant increase in cyberthreats for a multitude of reasons. Many organizations have therefore decided to employ a Security Operations Center (SOC) to strengthen their security work. Employing a SOC allows for monitoring, detection, and responses to different cyberthreats aimed at them. The public sector is one of the most important sectors in society due to its impact on the public, which has led to it being the target of many malicious attacks. The need for SOC in this sector is therefore crucial, but because of the many unique laws it abides by, it may be difficult to make an informed decision that will not be regretted.
This study aims to analyze and compare the different implementations of SOC that being in-house, hybrid, and SOCaaS and highlight the main benefits and challenges of each approach. It also aims to present the primary factors that have an influence on which implementations may be preferred for different organizations in the public sector. Understanding these allowed a framework to be developed that aimed to assist organizations within Sweden’s public sector in their decision-making process.
The data needed to understand these factors was collected using semi-structured interviews with ten participants from six organizations within Sweden's public sector. The participants were either security experts directly working in a security team or in a management position overseeing it. The interviews examined what current implementation they used, along with the different factors that influenced their choice. To analyze the data collected, a thematic analysis was used featuring an abductive approach to reasoning. This allowed for comparisons to past research, along with discoveries of new theories based on insights provided by the participants.
The results provided by our chosen research method showcased a variety of factors that were shown to have an influence on what implementation may be preferred given different circumstances. The factors that were the most impactful were the need for continuous monitoring, strong competence, and abiding by legal and regulatory requirements. Reasons for this include the difficulty of achieving 24/7 monitoring internally because most organizations operate during regular office hours. Finding the necessary competence to uphold a SOC is also difficult because of the resources and time required. In the public sector, abiding to laws and regulations also play a key role, due to them ensuring that sufficient security is in place to protect critical services and sensitive information.
Place, publisher, year, edition, pages
2025. , p. 80
Keywords [en]
Cybersecurity, In-house SOC, Outsourcing, Public Sector, Security Operations Center (SOC), SOC-as-a-Service (SOCaaS), SOC decision-making.
National Category
Information Systems
Identifiers
URN: urn:nbn:se:hj:diva-68760OAI: oai:DiVA.org:hj-68760DiVA, id: diva2:1972983
Subject / course
JTH, Informatics
Supervisors
Examiners
2025-06-192025-06-192025-10-13Bibliographically approved