Se alla lösningsområden

SOC – staffed security monitoring

Why tools without human oversight aren't enough, the difference between SOC, MDR, and SIEM, and what you should demand from a provider.

Why tools without human oversight aren't enough

Attacks happen when no one is watching. On a Saturday night, between Christmas and New Year's, or during vacation weeks. This is not a coincidence, but a deliberate choice by the attacker.

An organization with well-configured EDR but no one to review alerts outside of office hours has purchased a log of what happened, not protection against it happening. Automatic isolation buys time, but someone must determine whether it is an attacker or a false alarm – and whether the isolation should be lifted or expanded.

SOC, MDR, and SIEM

Three terms that are often confused in proposals.

SIEM is a tool. It collects logs and triggers alerts based on rules. It does not make assessments and requires someone to manage the rules.

SOC is the function: people, processes, and tools that work together to monitor and respond.

MDR, Managed Detection and Response, is a SOC purchased as a service – usually tied to a specific detection platform rather than your existing tools.

For most small and medium-sized organizations, MDR is the practical path forward. Running your own SOC requires staffing levels that few businesses with fewer than a few hundred employees can justify.

Five questions for the provider

Are they authorized to act, or just to call? A SOC that detects a threat but has to wait for your approval at three in the morning loses the very time the service is meant to save. Demand a clear mandate for isolation and account suspension.

What happens after the alert? Ask whether investigation, remediation, and reporting are included, or if you are expected to take over once they have made the call.

What does the escalation process look like? Who do they call at three in the morning, what happens if no one answers, and how long is the contact list?

Which languages and time zones? Incidents are handled less effectively across language barriers than you might think, especially when business stakeholders need to be involved.

What is covered? Endpoints, identities, cloud, network – or just the first one? Many attacks now originate in the identity layer.

For MSPs

Night staffing is difficult to build and hard to maintain. Few MSPs below a certain size can manage 24/7 scheduling without burning out their technicians.

That is why the SOC layer is usually purchased and repackaged into the customer agreement. It gives you a service to sell without needing to recruit analysts, and the customer gets protection that would otherwise be out of reach.

Make sure the alerts land in your ticketing system. A SOC that emails a support address that no one monitors on the weekend recreates the exact problem the service was meant to solve.

We go through how this layer relates to other parts of your security during IT security.

An alert at three in the morning is only worth something if someone reads it. We help you get the staffing in place.

Frequently asked questions about SOC

What does SOC stand for?
Security Operations Center. A staffed function that monitors security alerts, assesses what has happened, and takes action.

What is the difference between SOC and MDR?
SOC is the function. MDR is that same function purchased as a service, usually tied to a specific detection platform.

Do we need a SOC if we have EDR?
If no one on your team can act on an alert at night, yes. EDR detects and can isolate, but someone must assess what actually happened and what needs to be done next.

Can we build our own SOC?
Technically, yes. However, 24/7 staffing requires eight to ten analysts, which few organizations with fewer than a few hundred employees can justify.

Does a SOC replace our IT department?
No. A SOC handles security incidents, not operations, tickets, or user support.

What is most important to require in the agreement?
A mandate to act. A SOC that has to wait for your approval at night loses the time the service is meant to save.

Can an MSP resell this?
Yes, that is the most common model. You package the layer in the customer agreement without having to recruit analysts.

Produkter inom området

Nordlo

Nordlo builds scalable IT delivery with MSP Nordics

37% more efficient service management through standardised processes and automation
Läs mer
Läs mer
With the right platform and clear processes, we can scale our delivery without increasing administration at the same rate.
Nordlo

Want to hear more?

We are happy to tell you more about how we have adapted and tailored long-term solutions for our customers.