When this fits
You have a SIEM producing alerts that nobody has the hours to triage.
An incident would currently be handled by whoever happened to notice it.
A customer or regulator has asked who watches your estate outside working hours.
How we work within it
Detections tuned to your estate
Rules that fire on what actually matters in your environment, rather than a vendor's default content that alerts on everything and therefore on nothing.
Response authority agreed in advance
What we may do without asking, what needs your call, and who that call goes to at three in the morning. Decided before the incident, not during it.
Post-incident review that changes something
Every significant incident produces a change to detection, configuration or process. A review that produces only a document has not closed the loop.
What you get it on
SOC, across these domains
A delivery model is not a product. These are the technology domains we work in through it — start from the one your problem sits in.
Engagement and pricing model
A monthly subscription sized by the estate and the data volume being monitored. Incident response beyond an agreed threshold is a separate engagement, and that threshold is set with you rather than discovered during a crisis.
What we commit to, and what we measure
Time to detect and time to contain, measured per severity rather than averaged into a single flattering number.
False positive rate, tracked because a noisy SOC is one that gets ignored.
Detections added or tuned per month — the measure of whether it is improving or just running.
Targets are set per engagement and written into the agreement. We do not publish a number here, because a service level that is not attached to a specific scope is not a commitment.
Questions we are asked
Is this the same as an MDR product?
A product produces alerts. This is people, process and agreed authority acting on them. Buying the first without the second is the most common way security spend produces no change in outcome.
Do you need to send our logs outside the country?
Not necessarily. Where residency requires telemetry to stay in-country the architecture keeps it there, and that constraint is settled before anything is procured.
What can you actually do during an incident?
Exactly what the agreed authority says — which may include isolating a host or disabling an account. The boundary is written down before it is needed, because the middle of an incident is the worst time to discover it was never agreed.
Can you work with our existing SIEM?
Usually. Most estates are under-configured rather than under-tooled, and replacing a platform is a conclusion an assessment reaches rather than a starting position.
What do you need from us for this to work?
A named person who can make decisions out of hours, and accurate asset context — a SOC that does not know which server matters will escalate the wrong things politely and on time.
Start with an assessment
The fastest way to a useful answer is a short, scoped look at what you already have.