SOC as a service
Someone is watching at 03:00. That someone is us. You get 24/7 detection and response from a security operations centre staffed in your time zone, with response times written into the contract rather than promised on a web page.
Four reasons this lands on someone's desk.
Logs collected, never read
Your logs are collected and nobody reads them — until something goes wrong, and by then it's too late.
Seen on Monday
An alert fired at the weekend and was seen on Monday, three days after it mattered.
Monitoring you can't staff
You have compliance obligations that require monitoring you cannot staff yourself, around the clock.
Once was enough
You have been breached once and are not prepared to find out the same way twice.
Detection that doesn't wait for Monday.
- 01Monitor continuously. Endpoints, network, cloud, identity, and your critical applications, correlated in one place.
- 02Triage every alert so your team receives incidents, not noise. Tuning is our job, not yours.
- 03Contain fast. Pre-agreed containment actions we are authorised to take immediately, so the first ten minutes are not spent waiting for approval.
- 04Hunt proactively against MITRE ATT&CK techniques and threat intelligence relevant to your sector and region.
- 05Report monthly, including what we saw, what we stopped, and what it tells you about where to invest next.
Written into the contract, not promised on a web page.
| Severity | Acknowledged within | Containment begins | Escalation |
|---|---|---|---|
| Critical | 15 minutes | 30 minutes | Named responder plus your incident contact, by phone |
| High | 1 hour | 4 hours | Named responder, by phone |
| Medium | 4 hours | Next business day | Ticket and monthly report |
The delay is rarely technical.
During an incident, the delay is rarely technical. It is a responder in another time zone waiting for your team to wake up, working through a translation layer, on a call scheduled for the following afternoon. Our responders work your hours, speak your language, and can be on site in Casablanca, Nador, Lagos, Abidjan, or Cairo when remote is not enough.
Coverage you can point to, not take on faith.
- 01Onboarding and log source integration inside 30 days, with a documented detection coverage map.
- 02A tuned detection rule set specific to your environment, reviewed quarterly.
- 03An incident response plan and playbooks, tested with your team before you need them.
- 04Monthly reporting and a quarterly review, both audit-ready.
Straight answers, before you ask.
What is monitored?
Endpoints, network, cloud, identity, and your critical applications, correlated in one place, monitored continuously.
How fast do you respond to a critical alert?
Acknowledged within 15 minutes, with containment beginning within 30 minutes, escalated to a named responder and your incident contact by phone. High and medium severity have their own stated commitments, all written into the contract.
Why does local presence matter for incident response?
During an incident, the delay is rarely technical — it is a responder in another time zone waiting for your team to wake up, working through a translation layer. Our responders work your hours, speak your language, and can be on site in Casablanca, Nador, Lagos, Abidjan, or Cairo when remote is not enough.
How long does onboarding take?
Onboarding and log source integration are completed inside 30 days, with a documented detection coverage map so you know exactly what is and is not being watched.
Do you just alert us, or actually contain incidents?
We contain fast, using pre-agreed containment actions we are authorised to take immediately, so the first ten minutes are not spent waiting for approval. Your team receives incidents, not noise — tuning every alert is our job, not yours.
Find out what your logs are already telling you.
Same NDA, same named analyst, same coverage map described above — scoped to what you're running today. No cost, no obligation.
SOC as a service.
Request received.
A named analyst will reply within one business day to scope the NDA and the log sources in view.