Skip to content

Home Expertise / Security operations

SOC / SOC-01

Managed SOC — monitoring, triage and escalation

Entrust a specialist team with monitoring agreed sources, analysing alerts and escalating incidents. A SOC combines people, processes and tools; its service level depends on scope and contract.

WHEN IT HELPS

A focused response
to a defined need.

Organisation with security tools but no team to analyse alerts, need for regular monitoring or customer expectations for detection and incident follow-up.

AT A GLANCE

Family
Security operations

Engagement
Service or implementation

Reference
SOC-01

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Onboarding
  • source inventory
  • collection and quality
  • detection use cases
  • triage
  • contacts
  • escalation
  • authorised actions
  • reporting
  • service reviews
  • coverage tracking

Deliverables

  • Service description
  • responsibility matrix
  • detection catalogue
  • escalation procedures
  • triaged tickets
  • periodic reports
  • agreed metrics and improvement plan

Acceptance evidence

Priority sources are collected; test scenarios are detected; contact chain is exercised; contractual times are defined by event type; authorised response and limits are documented.

DELIVERY

How the work is structured.

Approach

Scope service and roles; connect and validate data; test scenarios; start operations; measure and improve.

Prerequisites & responsibilities

Customer: assets, logs, contacts and response authority. Provider: collection/analysis as contracted. Business decisions and recovery are explicitly allocated.

Scope factors

Assets, sources, events, volume, retention, integrations, hours and response level. Separate onboarding, licenses, consumption and recurring service.

Questions to clarify

Which assets and logs are available? What monitoring hours are required? Who decides and performs actions when an incident is confirmed?

IMPORTANT BOUNDARIES

Monitoring hours, mobilisation, notification, containment and resolution are distinct commitments. Each is defined with the response authority and capacity required by the operating agreement.

Hours and response times only after contractual approval. No guaranteed detection rate or resolution; collection gaps and failed sources remain visible in reporting.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A company receives EDR alerts without handling them. Project: onboard endpoints to the SOC, define contacts and test a simulated incident. Target outcome: triaged alerts and escalations tracked to an operational decision.

Scenario 02

A group wants monitoring for critical applications. Project: select useful logs and create sensitive-access scenarios. Target outcome: explicit coverage; applications lacking sufficient telemetry enter an onboarding plan rather than being labelled protected.

Technology and reference context

SIEM, EDR/XDR and ticketing integrated into an agreed operating model, with platform and service responsibilities specified during scoping.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.