Building SOC Capacity for SMEs: SOC4SME at the European SOC Innovation Forum 2026
September 23, 2026
On 15 September 2026, SOC4SME joined 19 EU-funded projects in Bucharest for the European SOC Innovation Forum 2026 (ESIF 2026), bringing together projects developing technologies, solutions and capabilities for Security Operations Centres across Europe.
Organised by the Romanian National Cybersecurity Directorate (DNSC) as part of the CYDERCO project, the Forum was designed not simply as a space for projects to present their work, but as an opportunity to exchange knowledge, identify synergies and explore new forms of cooperation across Europe’s SOC community. The Forum brought together EU-funded teams working across detection and response, threat intelligence, critical infrastructure protection and SOC capacity building, creating a dedicated space for Europe’s SOC project community to connect and exchange knowledge.
Building SOC capacity for SMEs
SOC4SME was represented by Dimitrios Koupatsiaris, Project Manager at consortium partner CyberSafe, who presented the project’s approach to strengthening cyber resilience among Greek SMEs.
His presentation focused on an important distinction at the heart of the SOC4SME approach: building SOC capacity does not necessarily mean building a SOC.
For most SMEs, developing and maintaining a fully operational Security Operations Centre in-house is simply not realistic. It requires specialised cybersecurity expertise, significant infrastructure investment, continuous operations and the resources needed to maintain and evolve these capabilities over time.
Building SOC capacity for SMEs therefore requires a different approach: enabling them to access and effectively use advanced cybersecurity capabilities without having to develop all of those capabilities internally. SOC4SME addresses this challenge by giving SMEs access to capabilities including real-time monitoring, timely threat detection, prediction and recommendations, and agile incident response.
This distinction between simply having access to cybersecurity technology and being able to use it effectively is particularly important.
The project combines three elements that contribute to strengthening SME cybersecurity capacity: tools that provide the technical foundation, expertise that gives SMEs access to specialised cybersecurity teams, and connections that strengthen the wider cybersecurity ecosystem. Together, these elements help move SMEs from simply having cybersecurity tools available to being better equipped to understand risks and respond when incidents occur.
Technology alone is not enough
A further message from the SOC4SME contribution was that effective SOC capacity cannot be created through technology alone.
Mr Koupatsiaris noted that technology provides the enabling foundation, but cyber resilience ultimately depends on people being able to understand risks, use available capabilities and act when incidents occur. Awareness and knowledge, access to expert support and collaboration therefore complement the technical capabilities provided through SOC services. For SMEs with limited internal cybersecurity resources, this combination is particularly important.
From onboarding to operational use
Making SOC capabilities accessible is only the first step. They must also become part of the organisation’s actual operations.
Within SOC4SME, this transition follows a structured process, beginning with the definition of scope, roles and responsibilities, followed by the integration of relevant systems and, ultimately, the move into continuous operation with monitoring, analysis and response capabilities activated.
The objective is to bridge the gap between access to cybersecurity capabilities and their effective operational use. For SMEs, the question is not simply whether a SOC service is available, but whether it can be integrated into the organisation in a way that strengthens its ability to detect, understand and respond to threats.
Stronger SOC capacity through collaboration
SOC4SME’s contribution also connected closely with the wider message of ESIF 2026.
Across the Forum, 19 European projects brought different perspectives on detection and response, threat intelligence, critical infrastructure protection and SOC capacity building. Despite their different areas of focus, a common theme emerged: cybersecurity capabilities cannot develop effectively in isolation.
Knowledge, experience and lessons learned need to move between projects, cybersecurity professionals, organisations and national ecosystems.
For SOC4SME, this collaborative dimension is particularly relevant. Strengthening SME cyber resilience is not solely a question of deploying individual technologies. It requires bringing together technical capabilities, specialised expertise, awareness and connections to the wider cybersecurity ecosystem.
ESIF 2026 provided an opportunity to share this approach with the wider European SOC community, exchange perspectives with other EU-funded projects and explore the connections between different approaches to strengthening Europe’s cybersecurity capabilities.
As ESIF’s central message captured it: “Built separately. Stronger together.”



