Inside the SOC

what actually happens between 3am and someone fixing it.

Most security companies describe this in language you would need a background in the field to follow. Here is the same thing without any of that, because you should understand what you are buying before you buy it.

The chain

six steps, and only one of them is software.

Every managed SOC does roughly this. The difference between a good one and a bad one is almost entirely in step four.

1

find out what you actually have.

Before anything can be watched, it has to be known about. We map every device, server, cloud service and internet facing system connected to your business, including the ones nobody remembers setting up.

Why it mattersAlmost every business we look at has something exposed that nobody knew was there. An old server, a test site, a contractor's device. You cannot defend what is not on the list.
2

put sensors where the evidence is.

Small pieces of software go onto your computers and servers. Your cloud services, email and login systems get connected to us directly. Together these produce a continuous record of what is happening across your business.

In practiceNothing is installed on personal phones, and none of this reads the content of your staff's email. It records behaviour, not correspondence.
3

let the machines read all of it.

Your business generates millions of these records a day. Software compares them against known attack patterns, current threat intelligence, and a picture of what normal looks like specifically for you. Anything that stands out gets raised.

The catchThis is the part every vendor sells you, and it is the part that is closest to a commodity. Good software generates good alerts. It does not answer them.
4

a person decides whether it is real.

This is the whole thing. Most alerts are nothing: someone logging in from a hotel, a legitimate tool behaving oddly, a scan that hit nothing. A small number are the start of a serious problem, and they rarely look dramatic at first.

An analyst looks at what was raised, works out which category it falls into, and either closes it or escalates. Around the clock, including at 4:47 on a Friday.

Why this is the productEvery business we speak to already owns software that would have caught the initial alert. What they do not have is somebody reading it. That gap, between the machine noticing and a human knowing, is what you are actually buying.
5

contain it before it spreads.

When something is real, the priority is stopping it moving. That can mean cutting a machine off the network, disabling a compromised account, or blocking traffic to somewhere it should not be going. Minutes matter, so some of this is automated and some needs a decision.

Agreed in advanceWe settle with you beforehand what we can do without asking. Isolating one laptop at 2am, yes. Shutting down your order system, no, that is a phone call.
6

tell you what happened and what to fix.

After the event, a plain account of what occurred, how far it got, and what allowed it. Monthly, a short report of what we saw and the specific things worth fixing, in priority order, with the reasons.

Written for youTwo versions. One a technical person can act on, one you could hand to your board or your insurer without translating it first.

Coverage

where we watch.

Attacks rarely arrive through one door. These are the places we collect from.

computers and servers

Laptops, desktops, physical and virtual servers. Where ransomware runs and where attackers land first.

identity and logins

Who signed in, from where, on what. Stolen credentials are the most common way in, and the hardest to spot without this.

cloud services

Microsoft 365, Google Workspace, and whatever else your business runs on. Configuration changes and unusual access.

email

The delivery route for most initial compromises. Phishing, impersonation, and the invoice that is not from who it says.

network edge

Firewalls, VPNs and remote access. What is reaching your business from outside, and what is leaving it.

known weaknesses

Continuous checking of your systems against newly published vulnerabilities, so you hear it from us and not from an attacker.

Translation

the words vendors use, in english.

You will meet these in proposals, insurance questionnaires and supplier assessments. None of them are complicated once someone tells you plainly.

SOCSecurity Operations Centre

A team of people whose entire job is watching for and responding to attacks. Historically something only large organisations could afford, because covering every hour of the week takes five or six analysts.

SIEMSecurity Information and Event Management

The system that gathers records from everywhere in your business into one place and looks for patterns across them. On its own it is a very expensive way to generate alerts nobody reads.

EDR and XDREndpoint or Extended Detection and Response

The software on your computers that spots suspicious behaviour and can stop it. The extended version adds cloud, email and identity to the picture rather than looking only at devices.

MDRManaged Detection and Response

All of the above, but with people running it for you instead of you hiring them. This is what we sell.

SOARSecurity Orchestration, Automation and Response

Automating the repetitive parts, so that a common alert triggers the standard checks and containment steps without waiting for a human. Speed on the routine, people on the judgement.

Vulnerability managementAlso: continuous scanning

Regularly checking your systems against the list of publicly known weaknesses and telling you which ones actually matter for you. Roughly forty thousand new ones are published each year, so the prioritising is the work.

Attack surface

Everything of yours an attacker could reach from the internet. Usually larger than the business thinks, because it includes things set up years ago and forgotten.

Dwell time

How long an attacker was inside before anyone noticed. The single number that best predicts how bad an incident becomes. Everything on this page exists to make it smaller.

still not sure what you would be buying?

Ask. We would rather spend half an hour explaining it than sell something you do not understand.

Book a consultation