SOC / SOC-01
Managed SOC — monitoring, triage and escalation
Entrust a specialist team with monitoring agreed sources, analysing alerts and escalating incidents. A SOC combines people, processes and tools; its service level depends on scope and contract.

WHEN IT HELPS
A focused response
to a defined need.
Organisation with security tools but no team to analyse alerts, need for regular monitoring or customer expectations for detection and incident follow-up.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Onboarding
- source inventory
- collection and quality
- detection use cases
- triage
- contacts
- escalation
- authorised actions
- reporting
- service reviews
- coverage tracking
Deliverables
- Service description
- responsibility matrix
- detection catalogue
- escalation procedures
- triaged tickets
- periodic reports
- agreed metrics and improvement plan
Acceptance evidence
Priority sources are collected; test scenarios are detected; contact chain is exercised; contractual times are defined by event type; authorised response and limits are documented.
DELIVERY
How the work is structured.
Approach
Scope service and roles; connect and validate data; test scenarios; start operations; measure and improve.
Prerequisites & responsibilities
Customer: assets, logs, contacts and response authority. Provider: collection/analysis as contracted. Business decisions and recovery are explicitly allocated.
Scope factors
Assets, sources, events, volume, retention, integrations, hours and response level. Separate onboarding, licenses, consumption and recurring service.
Questions to clarify
Which assets and logs are available? What monitoring hours are required? Who decides and performs actions when an incident is confirmed?
IMPORTANT BOUNDARIES
Monitoring hours, mobilisation, notification, containment and resolution are distinct commitments. Each is defined with the response authority and capacity required by the operating agreement.
Hours and response times only after contractual approval. No guaranteed detection rate or resolution; collection gaps and failed sources remain visible in reporting.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A company receives EDR alerts without handling them. Project: onboard endpoints to the SOC, define contacts and test a simulated incident. Target outcome: triaged alerts and escalations tracked to an operational decision.
Scenario 02
A group wants monitoring for critical applications. Project: select useful logs and create sensitive-access scenarios. Target outcome: explicit coverage; applications lacking sufficient telemetry enter an onboarding plan rather than being labelled protected.
Technology and reference context
SIEM, EDR/XDR and ticketing integrated into an agreed operating model, with platform and service responsibilities specified during scoping.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
