A service desk agent is taking a SOC analyst training course and, together with an instructor, is reviewing an incoming report on a screen.

From Service Desk to SOC: The Talent Pool You Already Have in-House.

The path from the service desk to the SOC is the best internal career progression available—one that most organizations never establish. Two floors down, there’s a team that assesses, prioritizes, follows up on, and documents reports every day. That’s triage work. The content may differ, but the thought process doesn’t, and that makes the learning curve to an analyst role shorter than the job titles suggest.

What makes this group so attractive goes beyond mere availability. Service desk staff know the users, are aware of which departments routinely operate outside standard procedures, and can tell from the tone of a report whether someone is holding something back. With an external hire, it takes months—if you ever get it at all—to gain that context. So, moving from the service desk to the SOC starts with a head start that you simply can’t buy anywhere.

What the service desk can already do without actually calling it that

A SOC analyst does three things: assess incoming signals, determine what’s urgent, and document the investigation so that someone else can take over. A service desk agent does exactly the same thing, only with service outages instead of alerts. So, anyone making the move from the service desk to the SOC is changing their focus, not their skills.

Ticket discipline is often underestimated in this context. Anyone who has recorded reports according to a set pattern for years writes investigation notes that remain useful. That sounds trivial until you encounter an analyst who, after an incident, cannot reconstruct what he himself did three days earlier. A service desk agent already has this habit ingrained, because his tickets are always handled by someone else. The NCSC emphasizes during the incident response phases that the analysis must be accurately documented, because that information may later serve as evidence.

There is another reason why the service desk is closer to the SOC than the organizational chart suggests. The NCSC lists setting up a reporting center as a standard step in an incident response plan: there must be a place where employees can quickly raise the alarm, preferably 24/7. In virtually every Dutch organization, that place is the service desk. They are, in fact, already the first line of defense in your detection process—only without a mandate, training, or escalation procedure. That makes the path from the service desk to the SOC more of a formalization of existing work than a leap into something new.

This is most evident in the case of phishing. The reports that come in the fastest are received through the service desk, which we’ve developed as a team-based discipline for phishing detection. The staff there already assess on a daily basis whether something is malicious, usually without anyone recognizing that assessment as security work.

What signs indicate a suitable candidate?

The biggest mistake when moving someone from the service desk to the SOC is focusing on what they can already do technically. Technical skills are exactly the part that a training program takes off your hands. What you want to assess beforehand is their way of thinking, because that’s the part you can’t teach in fifteen weeks. When moving someone from the service desk to the SOC, that way of thinking is a better predictor of learning outcomes than any prior knowledge.

What you're looking forHow to Spot It at the Service Desk
Curiosity About the CauseFind out why a ticket is being returned, even if it has been resolved
Pattern RecognitionNotes that three reports this week appear to be similar
PerseveranceTries to reproduce the issue himself first before escalating it
Careful DocumentationWrites tickets that a coworker can still understand a week later
Healthy SkepticismAsk for clarification if a request sounds just a little too urgent

What these six have in common is that they all revolve around attitude and none of them involve knowledge. They aren’t listed on an evaluation form and are rarely discussed in a performance review. So be sure to ask the service desk team leader about them explicitly before announcing the transition from the service desk to the SOC. The team leader will know within thirty seconds who qualifies, and that assessment is usually more reliable than a resume. Be sure to verify this afterward, though, because a team leader might sometimes name their best employee—and other times, the very person they want to let go.

Also pay attention to employees who find the work too easy. An employee who handles their tickets well within the standard timeframe and is bored is at risk of leaving. A career path from the service desk to the SOC captures exactly that type of person before they leave to work for another company—a dynamic we described in the section on career paths as a retention tool.

The problem that no one solves in advance

The service desk is usually the most understaffed team in the IT organization. If you take your two sharpest people away from there, service quality will measurably decline, and the entire organization will notice it within a week. Without a plan, a transfer from the service desk to the SOC will therefore happen exactly once and never again, because the team leader will block it the second time. That’s not because he’s unwilling—he’s held accountable for response times, yet you’re taking his best people away.

Three measures can prevent that. Replace staff in advance, not after the fact: recruit the successor for the service desk before the transition begins, so there’s an overlap rather than a gap. It takes weeks to fill a service desk position, but months to fill an analyst position—and that difference is the whole reason why moving from the service desk to the SOC is the best path.

Next, make career advancement the norm rather than the exception. If the service desk knows that someone can advance each year, it becomes a reason to work there. If you treat your service desk like a SOC when handling incidents, every departure will feel like a loss. This follows the same logic as offering training as an employment benefit.

Finally, don’t let the candidate disappear all at once. A phased transition—where the candidate first spends one day a week shadowing the security team—keeps the service desk running and gives you an early indication of their suitability. It also gives the candidate a realistic picture, because security work is less spectacular than most people expect.

How to Manage the Transition

Phase one lasts about a month and costs almost nothing. The candidate remains at the service desk and is assigned an additional task: labeling security-related reports separately and discussing them weekly with a member of the security team. This allows you to assess the candidate’s interest and perseverance, and the organization immediately benefits from improved threat detection. If the candidate is eliminated during this phase, you’ve lost a month rather than a training budget.

Phase two is the training program and the point at which the transition from the service desk to the SOC becomes a real investment. This is when the candidate actually leaves, and by this point, a replacement for the service desk must already be in place. The SOC T1 + T2 Analyst training program is the best fit, as it focuses entirely on alert assessment, investigation, and escalation: the same work, but with a different type of incident. For candidates with ambitions beyond the SOC alone, the Cyber Security Specialist training program is the alternative.

Phase three consists of the first ninety days on the security team. Expect the first few weeks to be disappointing. The candidate is used to closing out incidents, but in a SOC, many issues remain open without anyone ever declaring them resolved. That uncertainty is the main reason why internal transferees have second thoughts during the first quarter. Our 90-day onboarding roadmap describes how to structure that period. Exactly where the candidate starts depends on the level of your team—a consideration we discussed when comparing Tier 1 versus Tier 2.

What the market is saying about this entry-level product

The assumption that cybersecurity work can only be entrusted to experienced professionals is no longer shared by the certifying bodies themselves. With “Certified in Cybersecurity,” ISC2 offers an entry-level certification that explicitly does not require work experience, aimed at people entering the field. This acknowledges that the talent pool must be broader than the traditional path through technical education and years of experience.

In ISC2’s study of the profession, recruitment, retention, and team building are highlighted alongside the well-known labor shortage. This combination explains why internal promotion is more important than recruitment: you’re not just filling a position; you’re also retaining someone who might otherwise have left.

With SP 800-61 Revision 3, NIST has restructured incident response around the functions of the Cybersecurity Framework, making response part of broader risk management. In practical terms, this means that response begins with the initial report, which is received by the service desk. An organization that establishes a flow from the service desk to the SOC thereby also enhances the quality of that initial assessment.

The Math, in a Nutshell

Transitioning from a service desk to a SOC involves a training program, temporary double staffing, and a salary adjustment. Hiring an external analyst involves a recruitment process, a competitive salary with a scarcity premium, and several months of onboarding during which no output is delivered. We factored the cost of that second option into the cost of a vacant position.

Once again, the difference lies in time. Moving from a service desk to a SOC yields, within six months, someone who already knows the organization and has simply learned a new skill. The reverse route requires someone who already has the expertise but still needs years to get to know the organization. We described the practical benefits of hiring a junior employee in our article on smart hiring of cybersecurity professionals.

There are limits, though. Moving from the service desk to the SOC fills your first-line roles but does not lead to a senior position. Anyone who needs an experienced investigator must expect a longer, multi-level learning path, and when putting together a SOC team, we worked out how those levels relate to one another.

How to Start Your Monday

Discuss with the service desk team leader who is interested in pursuing this career path. Have a brief conversation with those individuals, because forcing someone to move from the service desk to the SOC will result in an unmotivated analyst and an empty seat at the service desk. Arrange for a replacement before you communicate the training decision, because that order determines whether the team will support or hinder the process.

Document the level the participant has mastered upon completion, the tasks they will then be able to perform independently, and the corresponding salary adjustment. The page for employers lists the in-company options, and the full range of training programs is organized by level. The calendar shows the upcoming start dates, which you’ll need to plan for a replacement.

We’ve described other career paths outside the service desk that can lead to a career in cybersecurity in our section on career transitions into cybersecurity, and anyone looking to implement this on a structural basis will find the multi-year model in our guide to setting up a traineeship. If you’d like to discuss who on your team might be a good fit, please schedule an introductory meeting.