CUSTOMER PATHWAY
Operational SOC
We have tools but no one handles alerts.

THE LOGIC
Address the cause.
Then build the capability.
Connect useful sources and test escalation before declaring the service live.
A POSSIBLE SEQUENCE
Select the steps
that fit your situation.
The starting point, sequence and scope depend on existing controls and evidence. Services remain separately scoped.
01 / END-01
EDR/XDR deployment and integration
Deploy and configure detection and response tools on workstations and servers. EDR focuses on endpoints; XDR correlates multiple security sources according to the platform and licensing.
02 / SOC-03
Log collection and SIEM deployment
Centralise useful security events and make them usable for searching, alerting and investigations. The project addresses quality, timestamps, retention and cost as much as platform installation.
03 / SOC-01
Managed SOC — monitoring, triage and escalation
Entrust a specialist team with monitoring agreed sources, analysing alerts and escalating incidents. A SOC combines people, processes and tools; its service level depends on scope and contract.
04 / SOC-04
Detection engineering and rule improvement
Design and maintain detection rules tied to customer risks, with testing and investigation procedures. The aim is useful, explainable alerts rather than an uncontrolled catalogue of enabled rules.
05 / RES-02
Incident-response readiness and assistance retainer
Prepare contacts, permissions, access and procedures before an incident to avoid delays at activation. A retainer specifies assistance conditions; it must not be sold as guaranteed intervention without a formal commitment.
START A CONVERSATION
Let’s scope your route.
Bring the business objective, your current environment and the constraints. We will help define the next useful step.
