Managed defense

Managed SOC

Continuous monitoring of your estate by analysts who triage what the tooling raises and escalate only what is real. We onboard your log sources, tune the detections against your environment rather than a generic template, and give you a named team that answers when something fires at three in the morning.

At a glance

Timeline

Two to four weeks to onboard and tune before coverage begins. We do not start the clock on day one — monitoring an untuned estate is how alert fatigue starts.

You get

  • Continuous analyst coverage on an agreed schedule
  • A coverage map showing which sources are monitored and which are not
  • Detections tuned to your environment, reviewed as it changes
Who needs this

If any of these is your week, this is the service.

You have alerts and nobody watching them overnight

The tooling is in place and generating volume, but it is being read during office hours by engineers who have another job.

What we do

Analyst coverage outside your hours, with a defined escalation path so only real incidents reach your phone.

Alert fatigue has set in and nobody trusts the console

Untuned detections produce so much noise that a genuine alert is statistically likely to be dismissed with the rest.

What we do

Detections tuned against your actual environment, and analyst triage in front of your team so you see incidents, not alerts.

A customer or insurer requires 24/7 monitoring

The obligation is contractual, and hiring three shifts of analysts to satisfy it is not proportionate to the business.

What we do

Documented continuous coverage, with monthly reporting written to be handed to the party that asked for it.

How it works

Every step, and what leaves our hands at the end of it.

  1. 01

    Onboard sources

    We connect your log sources — endpoints, cloud, identity, network — and confirm what each one is actually sending.

    → Source inventory & coverage map

  2. 02

    Tune detections

    Detections are tuned against your environment and your normal, not a vendor template. This is the step that decides whether the service is useful.

    → Tuned detection set

  3. 03

    Monitor & triage

    Analysts work the queue around the clock, investigating each alert and closing what is benign before it ever reaches you.

  4. 04

    Escalate

    A real incident is escalated on the agreed path with the investigation already done — what happened, what is affected, what to do now.

    → Incident notification with context

  5. 05

    Report & refine

    Monthly reporting on what fired, what was real and what changed, plus the tuning we made so the next month is quieter.

    → Monthly service report

What you get

Deliverables.

  • Continuous analyst coverage on an agreed schedule
  • A coverage map showing which sources are monitored and which are not
  • Detections tuned to your environment, reviewed as it changes
  • Escalation with the investigation already done, not a raw alert forwarded
  • Monthly service reporting suitable for a customer or an insurer
  • A named analyst team and a defined escalation contact
What we need

Before we can quote.

  • 01The log sources you have, and admin access to connect them
  • 02Your asset inventory, or at least the systems that matter most
  • 03The escalation path, and who may be called outside business hours
  • 04Any maintenance or automation that will look anomalous and is not
  • 05Your required coverage hours, and what an incident means to your business

Do not worry about having all of it. Send what you have and we will work out the rest on the scoping call.

Questions

Managed SOC, answered.

Do we need to buy a SIEM first?

No. If you already have one we work in it. If you do not, we bring the pipeline as part of the service, and you are not locked into it if you later choose your own.

Do you take action, or only tell us?

By default we investigate and escalate; containment stays your decision, because it is your business that goes offline. Where you want us to act — isolating an endpoint, disabling an account — we agree those actions in writing in advance.

What happens on a real incident?

You are escalated with the investigation already done. If it needs full response, Incident Response is the next service along and the same team stays on it — no handover to strangers mid-incident.

Next step

Scope a Managed SOC.

Managed SOC is already selected below. Tell us what you are trying to protect and what is driving the timing — if a different service fits better, we will say so rather than sell you this one.

Scope a Managed SOC1 business day

By submitting you agree to be contacted about your enquiry. We never share your details.