Eyes on Your Estate, Always
SOC as a Service
Attacks do not keep office hours, so neither do we. Our analysts watch your environment around the clock, catch threats early and act fast, without you having to build and staff your own security operations centre.
See the engagement path, 6 phasesSee the full Managed Services service index
Overview
SOC as a service gives you a full security operations centre without the cost of building one. We collect logs from across your estate, tune detections to your environment and monitor them every hour of every day. When something looks wrong, our analysts investigate, confirm whether it is real and respond. You get faster detection, calm and capable response, and monthly reporting that shows exactly what we caught and stopped.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the SOC as a Service engagement, 6 phases in order, each one selectable. Phase 1, Onboarding and Log Sources. We connect your endpoints, servers, cloud and network to our monitoring platform, and agree what good and bad look like for your business. Activities: Connect log sources and validate parsing for each one; Baseline normal activity across users, servers and cloud; Agree severity levels and escalation contacts; Set log retention to match your compliance obligations. Hands over Onboarding Runbook and Log Source Inventory. Phase 2, Detection Tuning. We tune detection rules to your environment so real threats stand out and noise is filtered away. Fewer false alarms means faster response to the alerts that matter. Activities: Tune detections against MITRE ATT&CK coverage; Suppress known-good behaviour that generates repeat noise; Write custom rules for your business-specific applications; Validate each rule with simulated attack activity. Hands over Tuned Detection Ruleset. Phase 3, 24/7 Monitoring and Triage. Our analysts watch alerts around the clock. Each one is triaged, confirmed or dismissed, and escalated to you only when it needs your attention. Activities: Triage every alert against the agreed severity matrix; Enrich alerts with threat intelligence and asset context; Escalate confirmed threats to your named contacts; Track time to detect and time to respond for each case. Hands over Triage Log with Response Times. Phase 4, Threat Hunting. We proactively hunt for attackers who slip past automated detection, using threat intelligence and behavioural analysis to find what alerts miss. Activities: Form hunt hypotheses from current threat intelligence; Search historical telemetry for matching behaviour; Investigate anomalies in authentication and outbound traffic; Convert successful hunts into permanent detections. Hands over Threat Hunt Findings. Phase 5, Incident Response. When we confirm an incident, we contain it, guide your team through the response and help you recover, following an agreed IR playbook. Activities: Isolate affected hosts and revoke compromised credentials; Run the agreed IR playbook with your technical team; Preserve evidence for later forensic review; Guide recovery and confirm the attacker is out. Hands over Incident Report with Root Cause. Phase 6, Monthly Reporting. You get a clear monthly report covering what we saw, what we stopped, how fast we acted and where you can reduce risk further. Activities: Summarise alert volume, confirmed incidents and outcomes; Report detection and response times against agreed targets; Show ATT&CK coverage gained and gaps remaining; Recommend the next changes to reduce risk. Hands over Monthly SOC Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Onboarding and Log Sources
We connect your endpoints, servers, cloud and network to our monitoring platform, and agree what good and bad look like for your business.
What Happens In This Phase
- Connect log sources and validate parsing for each one
- Baseline normal activity across users, servers and cloud
- Agree severity levels and escalation contacts
- Set log retention to match your compliance obligations
The Handover
Onboarding Runbook and Log Source Inventory
The next phase starts from this.
Phase 01 Onboarding and Log Sources
We connect your endpoints, servers, cloud and network to our monitoring platform, and agree what good and bad look like for your business.
What Happens In This Phase
- Connect log sources and validate parsing for each one
- Baseline normal activity across users, servers and cloud
- Agree severity levels and escalation contacts
- Set log retention to match your compliance obligations
The Handover
Onboarding Runbook and Log Source Inventory
The next phase starts from this.
- 01
Onboarding and Log Sources
We connect your endpoints, servers, cloud and network to our monitoring platform, and agree what good and bad look like for your business.
OutputOnboarding Runbook and Log Source InventoryActivities
- Connect log sources and validate parsing for each one
- Baseline normal activity across users, servers and cloud
- Agree severity levels and escalation contacts
- Set log retention to match your compliance obligations
- 02
Detection Tuning
We tune detection rules to your environment so real threats stand out and noise is filtered away. Fewer false alarms means faster response to the alerts that matter.
OutputTuned Detection RulesetActivities
- Tune detections against MITRE ATT&CK coverage
- Suppress known-good behaviour that generates repeat noise
- Write custom rules for your business-specific applications
- Validate each rule with simulated attack activity
- 03
24/7 Monitoring and Triage
Our analysts watch alerts around the clock. Each one is triaged, confirmed or dismissed, and escalated to you only when it needs your attention.
OutputTriage Log with Response TimesActivities
- Triage every alert against the agreed severity matrix
- Enrich alerts with threat intelligence and asset context
- Escalate confirmed threats to your named contacts
- Track time to detect and time to respond for each case
- 04
Threat Hunting
We proactively hunt for attackers who slip past automated detection, using threat intelligence and behavioural analysis to find what alerts miss.
OutputThreat Hunt FindingsActivities
- Form hunt hypotheses from current threat intelligence
- Search historical telemetry for matching behaviour
- Investigate anomalies in authentication and outbound traffic
- Convert successful hunts into permanent detections
- 05
Incident Response
When we confirm an incident, we contain it, guide your team through the response and help you recover, following an agreed IR playbook.
OutputIncident Report with Root CauseActivities
- Isolate affected hosts and revoke compromised credentials
- Run the agreed IR playbook with your technical team
- Preserve evidence for later forensic review
- Guide recovery and confirm the attacker is out
- 06
Monthly Reporting
You get a clear monthly report covering what we saw, what we stopped, how fast we acted and where you can reduce risk further.
OutputMonthly SOC ReportActivities
- Summarise alert volume, confirmed incidents and outcomes
- Report detection and response times against agreed targets
- Show ATT&CK coverage gained and gaps remaining
- Recommend the next changes to reduce risk
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the SOC as a Service scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Splunk, Elastic / ELK, Wazuh, Microsoft Sentinel, TheHive, MISP, Suricata, Velociraptor. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: NIST SP 800-61, MITRE ATT&CK, SANS incident handling, ISO 27035, MITRE D3FEND.
What We Run
8 tools
- Splunk
- Elastic / ELK
- Wazuh
- Microsoft Sentinel
- TheHive
- MISP
- Suricata
- Velociraptor
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- NIST SP 800-61
- MITRE ATT&CK
- SANSIncident handling
- ISO 27035
- D3FENDMITRE
Deliverables
What You Receive
- 24/7 monitoring with agreed response times
- Tuned detection ruleset for your environment
- Incident reports for every confirmed event
- Monthly security operations report
- Quarterly review with recommendations
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
What does 24/7 actually mean on this service?
Analysts are on shift around the clock, so an alert is triaged when it fires rather than when the next working day starts. An event at 02:00 on a Sunday is looked at by a person, not queued until Monday. Confirmed threats are escalated to your named contacts at the time they are confirmed; routine activity is not pushed to you, it is recorded and summarised in the monthly SOC report, with a quarterly review of what to change next. Every case carries a tracked time to detect and time to respond, and those numbers appear in the report rather than being asserted. What around the clock does not mean is a fixed published response time. Targets are agreed with you up front by severity, because what counts as urgent on a payment system is not what counts as urgent on a test box. Coverage also stops where your telemetry stops.
What do we have to send you, and what happens to sources you cannot read?
Endpoints, servers, cloud tenants and network devices at minimum, plus whatever else carries evidence of the attacks you care about. During onboarding we connect each source, validate that it parses correctly, and record it in a log source inventory, so there is a written list of what is watched and what is not. That list matters more than it sounds: detection is bounded by telemetry, and a system that sends us nothing stays invisible to us no matter how good the rules are. You supply access to the sources and a technical contact who can approve connections. We handle parsing, baselining and retention, which is set to match your compliance obligations rather than left at a default. Where a source cannot be connected, a legacy application with no usable logging for instance, we say so in the inventory rather than leaving a silent gap in the picture.
What happens when something is detected?
It is triaged by an analyst, confirmed or dismissed, and escalated to your named contacts only when it is real. The sequence is fixed. The alert is checked against the severity matrix agreed at onboarding, enriched with asset context and current threat intelligence, then investigated far enough to decide whether it is an attack, a misconfiguration, or normal behaviour nobody told us about. Dismissals are logged rather than silently dropped, and repeat benign activity is suppressed so the same non-event does not wake anyone twice. For a confirmed incident we move to the response playbook agreed with you before go-live: isolate affected hosts, revoke compromised credentials, preserve evidence for later forensic review, and work through containment and recovery alongside your technical team. You receive an incident report with root cause. What you do not receive is a raw alert forwarded to your inbox for you to interpret.
How is this different from building our own SOC, or buying an MDR product?
An in-house SOC needs headcount on a 24-hour rota, a platform, and someone senior to tune it. This gives you the operational outcome without that hiring problem. Against a product, the difference is tuning and judgement. Detection content shipped in a box fires on generic behaviour, which is why teams who buy one often end up ignoring the console. We tune detections to your environment, suppress known-good activity that generates repeat noise, write rules for your business-specific applications, and validate each one with simulated attack activity. Alerts are worked by a person before they reach you, so what lands is a confirmed incident with context rather than a notification you have to research. What you still own is the fixing. We isolate hosts, revoke credentials and guide containment, but patching, rebuilding and change approval stay with your IT team, and neither a product nor this service removes that work.
How long does onboarding take before monitoring is live?
Monitoring goes live once your log sources are connected, parsed correctly and baselined, and the detections have been tuned against your environment. It starts with a 30 to 45 minute scoping call, after which you get a written scope with a timeline and a fixed price, so the duration is committed before anything is connected rather than discovered halfway through. The variable is your side: how many sources are in scope, how quickly access and approvals arrive, and whether anyone can answer what normal looks like for the odd application nobody documented. Baselining needs real traffic, so it cannot be compressed without buying yourself a noisier first month. We do not switch on alerting to your contacts before tuning is done, because an untuned ruleset sends you generic detections you would learn to ignore. Onboarding produces a runbook and a log source inventory, so what is watched is written down.
Related Reading
Articles on SOC as a Service
Keep Moving Through Managed Services
Service 2 of 9 in this practice area
Practice Area
More in Managed Services
- Red Team AssessmentGoal-based adversary simulation across people, process and technology
- Attack Surface ManagementRecurring discovery of what you expose to the internet, and what is wrong with it
- Dark Web MonitoringAnalyst-validated monitoring for leaked credentials, documents and brand abuse
- vCISOSenior security leadership on demand, without a full-time hire
- vDPOA data protection officer as a service for the DPDP Act and beyond
- Phishing SimulationsSafe, realistic phishing tests that build lasting instincts
- Awareness TrainingsSecurity training your people actually remember and use
- Digital and Cyber ForensicsSound investigation and evidence when something has gone wrong