# SOC as a Service

> Your team gets bigger tonight.

SOC as a Service gives you a full analyst team watching and acting on your estate, day and night.

**Key points**

- A named analyst team, not a shared ticket queue
- Detection to alert in under 14 minutes
- Containment inside the hour, contractually

## You get the whole team, not a licence

### The analysts

A named team on shift around the clock — the certifications, the hours and the pattern recognition that no single hire can carry alone.

### The monitoring

Our platform and our detections, already tuned by every estate they have watched before yours.

### The mandate to act

Not just the alert. The account is disabled and the machine isolated while you sleep, and the write-up follows in the morning.

## What is actually watched

- **Endpoints and servers** — Workstations, servers and what runs on them, watched for the behaviour that precedes an incident rather than for file names somebody has already catalogued.
- **Identity and sign-in** — Sign-ins, privilege changes and impossible-travel patterns from your identity provider, which is where most breaches now begin and where the cheapest ones are stopped.
- **The network edge** — Firewall and VPN telemetry correlated with what the endpoints report, so a login from nowhere and a process starting somewhere become one event rather than two nobody joined up.
- **Cloud and SaaS** — Administrative activity in your cloud accounts and business applications: new keys, new roles, and consent quietly granted to an application nobody asked for.
- **Email** — Mailbox rules forwarding externally, and mail arriving at three in the morning from an account that has never written to you before. Watched here; filtered on Email and cloud files.
- **The products you already own** — Alerts from the security tools already in your rack and your tenant, folded into the same feed and answered by the same people — whoever sold them to you.

## How it runs

1. **Monitor** — Telemetry from every source lands in one correlated feed. Our screens, your sleep.
2. **Triage** — A named analyst decides what is real before you hear about it. You are not sent a queue to work through.
3. **Contain** — The affected machine or account is isolated on our authority, agreed with you in advance, so the containment does not wait for somebody to wake up and approve it.

## What you get

**A team you can name, and a record of every night** — A named lead and a named deputy, reachable without opening a ticket. Every month: what was seen, what was acted on, and what it cost you in downtime. After an incident, a written account of what happened in the order it happened — one your engineers can act on and your board can read.

---

Canonical: https://centio.bg/uslugi/soc-security-monitoring