Inside the SOC
Most security companies describe this in language you would need a background in the field to follow. Here is the same thing without any of that, because you should understand what you are buying before you buy it.
The chain
Every managed SOC does roughly this. The difference between a good one and a bad one is almost entirely in step four.
Before anything can be watched, it has to be known about. We map every device, server, cloud service and internet facing system connected to your business, including the ones nobody remembers setting up.
Small pieces of software go onto your computers and servers. Your cloud services, email and login systems get connected to us directly. Together these produce a continuous record of what is happening across your business.
Your business generates millions of these records a day. Software compares them against known attack patterns, current threat intelligence, and a picture of what normal looks like specifically for you. Anything that stands out gets raised.
This is the whole thing. Most alerts are nothing: someone logging in from a hotel, a legitimate tool behaving oddly, a scan that hit nothing. A small number are the start of a serious problem, and they rarely look dramatic at first.
An analyst looks at what was raised, works out which category it falls into, and either closes it or escalates. Around the clock, including at 4:47 on a Friday.
When something is real, the priority is stopping it moving. That can mean cutting a machine off the network, disabling a compromised account, or blocking traffic to somewhere it should not be going. Minutes matter, so some of this is automated and some needs a decision.
After the event, a plain account of what occurred, how far it got, and what allowed it. Monthly, a short report of what we saw and the specific things worth fixing, in priority order, with the reasons.
Coverage
Attacks rarely arrive through one door. These are the places we collect from.
Laptops, desktops, physical and virtual servers. Where ransomware runs and where attackers land first.
Who signed in, from where, on what. Stolen credentials are the most common way in, and the hardest to spot without this.
Microsoft 365, Google Workspace, and whatever else your business runs on. Configuration changes and unusual access.
The delivery route for most initial compromises. Phishing, impersonation, and the invoice that is not from who it says.
Firewalls, VPNs and remote access. What is reaching your business from outside, and what is leaving it.
Continuous checking of your systems against newly published vulnerabilities, so you hear it from us and not from an attacker.
Translation
You will meet these in proposals, insurance questionnaires and supplier assessments. None of them are complicated once someone tells you plainly.
A team of people whose entire job is watching for and responding to attacks. Historically something only large organisations could afford, because covering every hour of the week takes five or six analysts.
The system that gathers records from everywhere in your business into one place and looks for patterns across them. On its own it is a very expensive way to generate alerts nobody reads.
The software on your computers that spots suspicious behaviour and can stop it. The extended version adds cloud, email and identity to the picture rather than looking only at devices.
All of the above, but with people running it for you instead of you hiring them. This is what we sell.
Automating the repetitive parts, so that a common alert triggers the standard checks and containment steps without waiting for a human. Speed on the routine, people on the judgement.
Regularly checking your systems against the list of publicly known weaknesses and telling you which ones actually matter for you. Roughly forty thousand new ones are published each year, so the prioritising is the work.
Everything of yours an attacker could reach from the internet. Usually larger than the business thinks, because it includes things set up years ago and forgotten.
How long an attacker was inside before anyone noticed. The single number that best predicts how bad an incident becomes. Everything on this page exists to make it smaller.
Ask. We would rather spend half an hour explaining it than sell something you do not understand.
Book a consultation