Detection
Threats detected, around the clock.
Our contracted security operations centre (SOC) monitors your systems 24 hours a day, 7 days a week. A SOC is a team of analysts who watch security events and investigate suspicious activity.
The SOC collects security events from your devices, identities, email and cloud services. It investigates each suspicious event and escalates confirmed threats.
- Managed detection and response on laptops and supported servers
- Detection of suspicious sign-ins and privilege changes
- Email and Microsoft 365 threat detection
- Cloud security events and audit logs
- Collection and correlation of security logs (SIEM)
Monitoring by plan
- Foundation Standard
- Monitoring of devices, identities and Microsoft 365, with agreed containment actions.
- Assured Enhanced
- Adds more log sources and detections tuned to your critical systems.
- Sentinel Advanced
- Adds custom detection engineering and the widest monitoring of your estate.
What 24/7 monitoring includes
Every plan includes 24/7 SOC monitoring and investigation. The SOC can take agreed containment actions, for example to isolate a compromised device.
Standard plans do not include unlimited 24/7 incident command, forensic investigation or production engineering. Your service agreement states which containment actions the SOC can take and who responds to critical escalations. If you need guaranteed specialist mobilisation, we offer enhanced incident response retainers.