Security analist aan het werk in een Security Operations Center

Samen sterkTogether Strong

Joint SOC

Het samenwerkingsverband van Security Operations Centers en Cyber Defence Centers binnen de Rijksoverheid. Samen maken we het Rijk weerbaarder tegen cyberdreigingen.

The partnership of Security Operations Centers and Cyber Defence Centers within the Dutch central government. Together we make the government more resilient against cyber threats.

Wat is het Joint SOC?What is the Joint SOC?

Het Joint SOC (J-SOC) verbindt de Security Operations Centers (SOC's) en Cyber Defence Centers (CDC's) van verschillende ministeries en uitvoeringsorganisaties.

Elk SOC bewaakt zijn eigen systemen en netwerken: security analisten monitoren proactief met SIEM-technologie, kwetsbaarheidsscanners en dreigingsplatformen om hackpogingen, cyberdreigingen en verdacht verkeer op te sporen. Binnen het J-SOC delen we kennis en expertise over incidenten, use cases, threat intelligence en tooling. Zo hoeft niet iedere organisatie zelf het wiel uit te vinden.

We werken daarbij ook samen met partners zoals het Nationaal Cyber Security Centrum en de inlichtingendiensten.

The Joint SOC (J-SOC) connects the Security Operations Centers (SOCs) and Cyber Defence Centers (CDCs) of various ministries and government agencies.

Each SOC protects its own systems and networks: security analysts proactively monitor using SIEM technology, vulnerability scanners and threat platforms to detect hacking attempts, cyber threats and suspicious traffic. Within the J-SOC we share knowledge and expertise on incidents, use cases, threat intelligence and tooling, so no organisation has to reinvent the wheel.

We also work together with partners such as the National Cyber Security Centre and the intelligence services.

"… wij als Rijk weerbaarder zijn tegen cybersecurity dreigingen."

"… we as the government are more resilient against cyber security threats." (translated)

Mark van Uffelen, SOC Manager, SSC-ICT

Kennis delenSharing knowledge

Incidenten, use cases, red teaming, automatisering en tooling.

Incidents, use cases, red teaming, automation and tooling.

Samen oefenenTraining together

Gezamenlijk opleidingsplan en oefeningen zoals BOTS, CTF en NetWars.

A joint training plan and exercises such as BOTS, CTF and NetWars.

Hoe het begonHow it started

Het idee ontstond tijdens de Nuclear Security Summit 2014 in Den Haag, waar de Belastingdienst en SSC-ICT (Ministerie van BZK) samen de beveiliging monitorden.

In 2015 kreeg het een vervolg tijdens de ONE Conference van het NCSC en de Global Conference on CyberSpace (GCCS 2015). Daar werkten de Belastingdienst, SSC-ICT, het Nationaal Cyber Security Centrum en Rijkswaterstaat in één gezamenlijk SOC samen. Dat was het begin van het Joint SOC.

The idea came up during the Nuclear Security Summit 2014 in The Hague, where the Tax and Customs Administration and SSC-ICT (Ministry of the Interior) jointly monitored security.

In 2015 this was followed up during the NCSC's ONE Conference and the Global Conference on CyberSpace (GCCS 2015). There, the Tax and Customs Administration, SSC-ICT, the National Cyber Security Centre and Rijkswaterstaat worked side by side in one joint SOC. That was the start of the Joint SOC.

J-SOC coin met het motto Samen sterk

10 jaar J-SOC10 years of J-SOC

In 2025 vierden we het tienjarig bestaan van het Joint SOC. Wat begon als een tijdelijke samenwerking rond een topconferentie, is uitgegroeid tot een netwerk van tien organisaties.

In 2025 we celebrated ten years of the Joint SOC. What started as a temporary collaboration around a summit has grown into a network of ten organisations.

TijdlijnTimeline

  1. Idee tijdens de Nuclear Security SummitIdea during the Nuclear Security Summit
  2. Start tijdens ONE Conference en GCCS 2015Start at the ONE Conference and GCCS 2015
  3. J-SOC Best Practice 1.0
  4. Rijksbreed Threat Intelligence PlatformGovernment Threat Intelligence Platform
  5. Gezamenlijk opleidingsplan (SANS)Joint training plan (SANS)
  6. Toetreding DICTUDICTU joins
  7. J-SOC Best Practice 2.0
  8. Werkgroepen Blue team en Red teamBlue team and Red team working groups
  9. Toetreding Ministerie van Justitie en VeiligheidMinistry of Justice and Security joins
  10. Eerste gezamenlijke maturity assessment (SOC-CMM)First joint maturity assessment (SOC-CMM)
  11. J-SOC KenniseventJ-SOC Knowledge Event
  12. Toetreding DUO en Ministerie van DefensieDUO and Ministry of Defence join
  13. Security Battle (wervingsevent)Security Battle (recruitment event)
  14. Toetreding PolitiePolice joins
  15. Tweede gezamenlijke maturity assessment (SOC-CMM)Second joint maturity assessment (SOC-CMM)
  16. Toetreding UWVUWV joins
  17. 10 jaar J-SOC10 years of J-SOC
  18. J-SOC Best Practice 3.1

Deelnemende organisatiesMember organisations

Wat hebben we bereikt?What have we achieved?

  • J-SOC Best Practice (van versie 1.0 naar 3.1)
  • Kennisdeling over incidenten, use cases en red teaming
  • Gezamenlijk opleidingsplan
  • Gezamenlijke oefeningen (BOTS, CTF, NetWars)
  • Gezamenlijke inkoop van een Threat Intelligence Platform
  • Het Nationaal Responsnetwerk als basis voor uitwisseling van medewerkers
  • Workshops voor cybertrainees
  • Maturity assessments (van SIM3 naar SOC-CMM)
  • J-SOC Best Practice (from version 1.0 to 3.1)
  • Knowledge sharing on incidents, use cases and red teaming
  • Joint training plan
  • Joint exercises (BOTS, CTF, NetWars)
  • Joint procurement of a Threat Intelligence Platform
  • The National Response Network as a foundation for staff exchange
  • Cyber trainee workshops
  • Maturity assessments (from SIM3 to SOC-CMM)

VooruitblikLooking ahead

We blijven kennis delen over SOC-inrichting, automatisering, use cases, threat intelligence, incidenten en tooling. Daarnaast organiseren we:

  • de jaarlijkse J-SOC Dag;
  • werkgroepen rond actuele gebeurtenissen en thema's;
  • maandelijkse bijeenkomsten voor analisten;
  • tweewekelijks overleg voor leads en managers.

J-SOC On Tour

Waar we eerder vaste werkgroepen hadden (Blue, Red en CTI), werken we vanaf 2026 informeler. Elke maand staat één thema centraal en is één SOC of CDC gastheer. Iedere organisatie stuurt twee deelnemers met kennis van het thema. De gastheer kan laten zien hoe zij het thema binnen hun eigen SOC/CDC aanpakken. Kennis uitwisselen en netwerken staan voorop.

We will keep sharing knowledge on SOC setup, automation, use cases, threat intelligence, incidents and tooling. In addition we organise:

  • the annual J-SOC Day;
  • working groups based on current events and themes;
  • monthly analyst meetings;
  • bi-weekly meetings for leads and managers.

J-SOC On Tour

Where we used to have fixed working groups (Blue, Red and CTI), from 2026 onwards we work more informally. Each month focuses on one theme, hosted by one SOC or CDC. Every organisation sends two participants with expertise in that theme. The host can present how they handle the theme within their own SOC/CDC. Knowledge exchange and networking come first.

J-SOC Best Practice 3.1

Tien jaar gezamenlijke ervaring in het inrichten en volwassen maken van een SOC, gebundeld in één document.

Ten years of shared experience in setting up and maturing a SOC, bundled in one document.

Bekijk en download de Best PracticeView and download the Best Practice

Werken in een SOC van het RijkWorking in a government SOC

Wil je weten hoe het is om als security analist bij de Rijksoverheid te werken? Lees het verhaal van het SOC van SSC-ICT: "Wij staan paraat om elke cyberdreiging te ondervangen" op Werken voor Nederland.

Curious what it is like to work as a security analyst for the Dutch government? Read the story of the SSC-ICT SOC: "We stand ready to counter every cyber threat" on Werken voor Nederland (in Dutch).