SOC / SOC-02
Co-managed SOC and internal-team support
Complement an existing security team with expertise, triage capacity or shared monitoring scope. The service specifies who monitors, decides and acts, and how cases transfer between teams.

WHEN IT HELPS
A focused response
to a defined need.
Skilled but overloaded internal team, need for specialist support, coverage gaps on selected systems or difficulty operating an existing platform effectively.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Operating-model assessment
- task allocation
- rule review
- investigation support
- case handovers
- analyst coaching
- service reviews
- continuous improvement
Deliverables
- RACI
- shared procedures
- case template
- agreed coverage schedule
- detection backlog
- knowledge-transfer workshops
- escalation-quality metrics
Acceptance evidence
A test case is handled without ownership gaps; tools and access are shared securely; decisions and handovers are tracked; each party accepts its commitments.
DELIVERY
How the work is structured.
Approach
Scope service and roles; connect and validate data; test scenarios; start operations; measure and improve.
Prerequisites & responsibilities
Customer: assets, logs, contacts and response authority. Provider: collection/analysis as contracted. Business decisions and recovery are explicitly allocated.
Scope factors
Assets, sources, events, volume, retention, integrations, hours and response level. Separate onboarding, licenses, consumption and recurring service.
Questions to clarify
What does the internal team want to retain? Where is time or expertise lacking? Who owns each incident during handover?
IMPORTANT BOUNDARIES
Co-management fails without clear ownership. Sensitive-data access and support hours must be defined; reinforcement does not automatically mean continuous on-call coverage.
Hours and response times only after contractual approval. No guaranteed detection rate or resolution; collection gaps and failed sources remain visible in reporting.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A mid-sized company owns a SIEM but its team mostly handles emergencies. Project: outsource triage for a defined scope while retaining business decisions internally. Target outcome: increased capacity without removing team ownership.
Scenario 02
An internal SOC wants stronger cloud analysis. Project: review use cases, support investigations and run workshops. Target outcome: transferred skills and consistent case files; collection gaps become assigned actions.
Technology and reference context
Examples: the customer’s existing SIEM/EDR, ticketing and secure collaboration tools; no mandatory replacement.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
