Services · Cybersecurity · SOC as a service

SOC as a service

Someone is watching at 03:00. That someone is us. You get 24/7 detection and response from a security operations centre staffed in your time zone, with response times written into the contract rather than promised on a web page.

01 — Who this is for

Four reasons this lands on someone's desk.

01

Logs collected, never read

Your logs are collected and nobody reads them — until something goes wrong, and by then it's too late.

02

Seen on Monday

An alert fired at the weekend and was seen on Monday, three days after it mattered.

03

Monitoring you can't staff

You have compliance obligations that require monitoring you cannot staff yourself, around the clock.

04

Once was enough

You have been breached once and are not prepared to find out the same way twice.

02 — What we do

Detection that doesn't wait for Monday.

  • 01Monitor continuously. Endpoints, network, cloud, identity, and your critical applications, correlated in one place.
  • 02Triage every alert so your team receives incidents, not noise. Tuning is our job, not yours.
  • 03Contain fast. Pre-agreed containment actions we are authorised to take immediately, so the first ten minutes are not spent waiting for approval.
  • 04Hunt proactively against MITRE ATT&CK techniques and threat intelligence relevant to your sector and region.
  • 05Report monthly, including what we saw, what we stopped, and what it tells you about where to invest next.
03 — Response commitments

Written into the contract, not promised on a web page.

SeverityAcknowledged withinContainment beginsEscalation
Critical 15 minutes 30 minutes Named responder plus your incident contact, by phone
High 1 hour 4 hours Named responder, by phone
Medium 4 hours Next business day Ticket and monthly report
04 — Why local presence changes the outcome

The delay is rarely technical.

During an incident, the delay is rarely technical. It is a responder in another time zone waiting for your team to wake up, working through a translation layer, on a call scheduled for the following afternoon. Our responders work your hours, speak your language, and can be on site in Casablanca, Nador, Lagos, Abidjan, or Cairo when remote is not enough.

A nexaya analyst monitoring for security threats
05 — What you receive

Coverage you can point to, not take on faith.

  • 01Onboarding and log source integration inside 30 days, with a documented detection coverage map.
  • 02A tuned detection rule set specific to your environment, reviewed quarterly.
  • 03An incident response plan and playbooks, tested with your team before you need them.
  • 04Monthly reporting and a quarterly review, both audit-ready.
06 — Frequently asked questions

Straight answers, before you ask.

What is monitored?

Endpoints, network, cloud, identity, and your critical applications, correlated in one place, monitored continuously.

How fast do you respond to a critical alert?

Acknowledged within 15 minutes, with containment beginning within 30 minutes, escalated to a named responder and your incident contact by phone. High and medium severity have their own stated commitments, all written into the contract.

Why does local presence matter for incident response?

During an incident, the delay is rarely technical — it is a responder in another time zone waiting for your team to wake up, working through a translation layer. Our responders work your hours, speak your language, and can be on site in Casablanca, Nador, Lagos, Abidjan, or Cairo when remote is not enough.

How long does onboarding take?

Onboarding and log source integration are completed inside 30 days, with a documented detection coverage map so you know exactly what is and is not being watched.

Do you just alert us, or actually contain incidents?

We contain fast, using pre-agreed containment actions we are authorised to take immediately, so the first ten minutes are not spent waiting for approval. Your team receives incidents, not noise — tuning every alert is our job, not yours.

Book this review

Find out what your logs are already telling you.

Same NDA, same named analyst, same coverage map described above — scoped to what you're running today. No cost, no obligation.

Talk to the analyst who would watch your environment →

SOC as a service.

Mutual NDA signed first. Findings stay yours.

One business day. From a named analyst, not a salesperson.

Request received.

A named analyst will reply within one business day to scope the NDA and the log sources in view.