Security Jul 24, 2026 7 min read 1,282 words 56 views Updated Aug 2026

Building a SOC in UAE with IBM

Building a SOC in the UAE with IBM takes more than QRadar. What the stack covers, what changed in 2024, and what assessors actually ask for.

Table of Contents
Building a SOC in UAE with IBM – cybersecurity guide by Basim Ibrahim

A Security Operations Centre (SOC) is the team, process and tooling an organisation runs to detect, investigate and respond to security incidents. For UAE enterprises it is also an audit target: NESA-aligned assessors and CBUAE examiners expect evidence that monitoring is staffed, tested and covering the systems that matter.

TL;DR
  • IBM covers the technology layer well: QRadar SIEM, QRadar SOAR (the product formerly sold as Resilient) and X-Force threat intelligence.
  • IBM sold its QRadar SaaS business to Palo Alto Networks in 2024. On-premises QRadar continues, but get roadmap commitments in writing before you buy.
  • Technology is roughly a third of the build. The 24x7 rota, log source onboarding and detection tuning decide whether the SOC catches anything.
  • Assessors do not ask which SIEM you bought. They ask for coverage maps, retention evidence and proof that response has been exercised.

IBM can sell you most of a SOC's technology layer. It cannot sell you the part that decides whether the SOC catches anything: analysts on a sustainable rota, the right log sources onboarded and parsed, and a detection lifecycle that keeps rules current as the estate changes. Price all three from the start, or the project stalls at the technology stage, which is where most stalled UAE SOC builds are sitting.

What IBM actually supplies

The IBM SOC stack rests on three products. QRadar SIEM handles collection, correlation and alerting. QRadar SOAR, which IBM acquired as Resilient, adds case management and response playbooks. X-Force supplies threat intelligence, and IBM Consulting sells the surrounding services, from incident response retainers to fully managed operations.

QRadar's strengths are real. It is mature at on-premises scale, the regional talent pool knows its correlation engine, and its DSM library parses most enterprise log sources without custom work. For a UAE bank or government entity with a heavy on-premises estate and a data residency constraint, that profile still fits.

Licensing needs eyes open. QRadar is metered in events per second and flows per minute, so an unfiltered logging estate inflates the bill quickly. Size from your measured volumes, document the filtering assumptions, and treat any figure produced from a questionnaire as a guess.

The 2024 change nobody should skip

In 2024 IBM sold its QRadar SaaS assets to Palo Alto Networks, which offers those cloud customers a migration path to Cortex XSIAM. On-premises QRadar remains an IBM product with continued support, but the sale tells you where IBM judged the cloud SIEM market to be heading, and it was not towards QRadar.

For a UAE buyer this cuts two ways. If your constraint is data residency and your estate is on-premises, QRadar remains a defensible choice, and the installed base across the Gulf means experienced QRadar analysts are easier to hire than specialists in most rival platforms. If you are cloud-first, ask IBM to commit its on-premises roadmap to writing for your full contract term, and evaluate the alternatives honestly before standardising on a platform whose SaaS future now belongs to a competitor.

The two-thirds no vendor ships

A genuine 24x7 rota is the expensive part. Cover the shift patterns, annual leave and attrition and you need eight to twelve analysts before you add a SIEM engineer, a detection developer and someone senior enough to say no to the business. In the Gulf market those people are scarce and mobile: salary bands move quickly, and a trained QRadar analyst is a recruitment target for every MSSP in the region. Budgeting for retention, training and progression is not an HR nicety. It is the difference between a SOC and a room of vacancies.

Process is the other missing shipment. Log source onboarding is a project in its own right: custom applications need parsers built and maintained, network teams need persuading to forward the right telemetry, and every source needs an owner who notices when it goes quiet. Detection content needs a lifecycle of build, test, tune and retire, or the default rule set generates the alert fatigue that has analysts closing offences without reading them. Alert fatigue is not a staffing problem. It is engineering debt.

What NESA-aligned assessors actually ask for

Assessors have largely stopped asking which SIEM you bought. Across NESA-aligned reviews, CBUAE examinations and ISO 27001 audits, the requests converge on operational evidence:

  • a coverage map showing which critical systems feed the SOC, which do not, and who owns each gap
  • log retention demonstrated against your stated policy, not asserted in a slide
  • incident response runbooks that have been exercised, with dates and findings recorded
  • detection and response metrics reported to someone with the authority to act on them
A modest SIEM with demonstrated coverage and a tested runbook scores better than a flagship deployment feeding three log sources and a binder of untested plans. If you do not yet measure detection and response times, start there; the SOC metrics and KPIs guide covers which numbers are worth reporting and which are vanity.

Build the team, or buy the operation?

Most UAE mid-market organisations cannot fill the rota, and a SOC staffed for business hours fails quietly: the attacker who lands at 2am on a Friday gets the whole weekend. The realistic options are a fully managed service, or a hybrid model where you own the platform and the data and rent the overnight shifts. Hybrid is where most regulated UAE entities land, because it keeps data in-country while making the staffing problem someone else's. The full trade-off is worked through in the managed SOC versus in-house guide.

Budget honestly across both options. Whatever the software quote says, people dominate the running cost of an in-house SOC, and the commitment scales with coverage: every hour of the week you want watched is an hour someone must be paid to watch. If the IBM stack plus the headcount is beyond reach, a leaner platform run with discipline beats a flagship run badly. A FortiSIEM deployment with fifty tuned use cases and an owned onboarding backlog will out-detect an under-staffed QRadar every week of the year.

Where UAE SOC builds stall

The failure modes repeat across the region, and none of them are technology faults:

  • Onboarding stops after the easy sources. Firewalls and Windows logs arrive in month one; the core banking platform and the custom applications that actually matter are still "in progress" a year later.
  • The SIEM becomes a compliance logging appliance. It retains logs, satisfies an audit checkbox, and nobody investigates anything.
  • Nobody owns tuning after go-live. The integrator leaves, default rules pile up offences, and analysts learn to bulk-close.
  • SOAR arrives before there is a process to automate. Playbooks encode a workflow; if the workflow does not exist, you have automated nothing and licensed it anyway.
IBM's own 2024 Cost of a Data Breach Report put the average global breach at USD 4.88 million. The case for detection makes itself. The case that needs making inside most organisations is for the unglamorous parts of detection: parsers, rotas and tuning hours.

Five questions before you sign

  1. Will IBM commit the on-premises QRadar roadmap to writing for your full contract term?
  2. Was licensing sized from measured events per second and flows, with filtering assumptions documented?
  3. Who owns detection content after go-live, and how many engineering hours a week are budgeted for it?
  4. Can you genuinely fill a 24x7 rota, and if not, which managed or hybrid model covers the nights?
  5. For each control an assessor will probe, which report or dashboard produces the evidence?
If the answers are thin, fix the operating model before the purchase order goes out. The security operations centre guide walks the whole build sequence, and technology selection is deliberately not step one.

Frequently Asked Questions

A Security Operations Center (SOC) is a centralized unit that deals with security issues on an organizational and technical level, using people, processes, and technology to detect, analyze, and respond to cybersecurity incidents, ensuring compliance with NESA regulations.

The cost of building and managing a SOC in the UAE with IBM Security solutions varies depending on the organization's size, complexity, and specific security requirements, but it typically includes investment in technology, personnel, and training, with costs ranging from AED 500,000 to AED 5 million annually.

To build a SOC in the UAE that meets NESA compliance requirements with IBM Security solutions, enterprises should follow a structured approach, including assessing security risks, designing a tailored SOC architecture, implementing IBM Security technologies, and providing ongoing training and support to SOC personnel.
Basim Ibrahim, Senior Cybersecurity Presales Consultant Dubai
Basim Ibrahim OSCP CEH CySA+ Pentest+
Senior Cybersecurity Presales Consultant, Dubai, UAE

5+ years delivering enterprise cybersecurity presales, VAPT assessments, and security advisory across the UAE and GCC. Currently Senior Presales & Technical Consultant at iConnect IT, Dubai.

Connect on LinkedIn

Was this article helpful?


Comments

Leave a Comment

Comments are moderated before appearing.

Related Articles

Weekly Cyber Insights

One email per week. UAE/GCC focused. No spam, unsubscribe any time.