Solutions /MONITORING & RESPONSE · SOC

Managed SOC.
Monitoring 24/7/365.

Monitoring, analysis and response to security events, including nights, weekends and public holidays.

Request a SOC proposal

Coverage for
your infrastructure.

Monitoring covers the workstations, servers, firewalls and Microsoft 365 accounts included in the service, subject to supported systems and enabled integrations. We agree the contacts and response responsibilities from the outset.

Analysts investigate suspicious activity and alert the client’s IT team. Compromised devices can be isolated under the conditions agreed at activation.

Illustrative image of a security operations centre, from a TRU presentation
01

Devices

Analysis of events from workstations and servers, correlated with information from existing protection solutions.

02

Network

Monitoring of firewall events to identify suspicious connections and malicious activity.

03

Cloud

Monitoring of Microsoft 365 events and suspicious sign-ins for the covered accounts and integrations.

HOW WE USE AI

From collected events
to validated alerts.

The TRU SOC service combines local collection, correlation in the monitoring platform and AI-assisted analysis with investigation by a human team, 24/7/365.

01

Collection from your infrastructure

Local agents and integrations collect the relevant events from devices and the included services. The SIEM platform brings this data together for correlation and investigation.

02

AI-assisted correlation and triage

The AI component correlates activity and helps filter out irrelevant alerts before human analysis, so that the investigation focuses on the signals that need attention.

03

Human investigation

Analysts validate threats and coordinate the response under the agreed conditions. The designated IT team receives the relevant alerts and the information needed to respond.

SIEM stands for security information and event management. At activation, we agree the integrated sources, authorised actions and escalation contacts.

FROM ALERT TO RESPONSE

Events analysed.
Actions coordinated.

A clear process for investigating events and coordinating the response.

Analysis and validation
Events are correlated, and specialists investigate the signals that indicate a threat.
Notification and escalation
The client’s IT team receives alerts through the agreed channels and procedure, including for escalations outside working hours.
Incident response
SOC can isolate affected devices under the agreed conditions. The designated IT team carries out the necessary remediation and recovery.

Access to the SOC service for a monthly operating cost, without building your own security operations centre.

HOW WE WORK

From context
to a concrete plan.

  1. 01

    We take inventory

    The relevant systems, accounts and integrations.

  2. 02

    We configure

    Event collection, access and the notification flow.

  3. 03

    We monitor

    Operation of the service and analysis of security events.

INCLUDING OUTSIDE WORKING HOURS

An incident won’t wait
for your team to get back to the office.

Illustrative example: on a weekend evening, a suspicious execution is detected on a monitored workstation.

01

SOC investigates

Analysts correlate events and check for indicators of an incident in the systems included in the service.

02

The IT team is alerted

The incident is escalated to the designated contacts through the agreed channels and procedure.

03

The incident is contained

If the situation and the procedure require it, SOC can isolate the device. The IT team continues with remediation and recovery.

Monitoring and analysis are available 24/7/365. Permitted actions, contacts and response conditions are agreed before activation.

SERVICE ACTIVATION

Coverage and responsibilities agreed from the outset.

We start from an inventory of the systems to be monitored: workstations, servers, firewalls and Microsoft 365 accounts. We check the supported systems and the integrations required, then define the scope of the service.

Monitoring and analysis run 24/7/365 for the included systems. Before activation, we clarify the configuration, the escalation contacts and the IT team’s responsibilities.

  • Included systems: what is monitored and through which integrations.
  • Escalation contacts: who receives alerts and who can make decisions, including at night, at weekends and on public holidays.
  • Permitted actions: under what conditions a device can be isolated and who continues remediation and recovery.
  • Coverage updates: how changes to the infrastructure and to contact persons are communicated.

These elements link monitoring to the company’s ability to respond to an incident. Responsibilities are agreed together with the designated IT team.

Discuss SOC coverage
FROM CLIENT PROJECTS

Why they added
SOC monitoring.

Two businesses that depend on system availability chose SOC monitoring to analyse security events between penetration tests.

Automotive industry distributor

Monitoring during the remediation period

SOC after adopting monthly testing

Anonymised real case

A distributor in the automotive industry, with daily revenue exceeding €100,000, needed to reduce the risk of an operational interruption. Beyond the impact on revenue, management considered the possibility of some customers buying from competitors during an outage. The company chose monthly internal and external PenTest to identify vulnerabilities and remediation measures.

Not all measures could be implemented immediately. To track suspicious activity during this period, the company implemented SOC across its infrastructure, with security event monitoring and analysis 24/7/365.

Events collected from the included systems are correlated and investigated. SOC analysts validate relevant signals and alert the designated IT team with information useful for the response. Response actions follow the conditions agreed when the service is activated.

Continuous monitoring complements remediation and remains in place after the identified issues are closed. The IT team implements the necessary measures and retesting verifies the results; SOC tracks events during day-to-day operation.

Vulnerability assessment in this project
Online retail company

Alerts investigated outside working hours too

24/7/365 SOC for the included systems

Anonymised real case

For a company that sells exclusively online, system availability is essential: an interruption can stop orders and lead customers to choose other suppliers. Management chose PenTest to assess the infrastructure’s exposure and complemented this protection with SOC, to analyse activity between tests.

SOC added security monitoring 24/7/365, including nights, weekends and public holidays. Events from the systems included in the service are analysed continuously, so suspicious activity can also be investigated outside the IT team’s working hours.

The SOC service correlates signals, investigates alerts and sends relevant information to the client’s IT team. Contacts and escalation outside working hours are agreed at activation; actions such as isolating a device depend on the available integration and the agreed authorisation.

The company thus combines periodic vulnerability assessment with analysis of events during operation. The IT team implements remediation and recovery measures within the business continuity plan.

Assessing the online retailer’s infrastructure
DURING OPERATION

Continuous monitoring.
Coordinated response.

SOC tracks activity in the included systems, while PenTest findings help the company understand its exposure.

You know the open issues.

Test reports show what needs to be fixed. The IT team can track the remaining measures and the risks that need attention until they are resolved.

You get 24/7/365 analysis.

SOC correlates events and investigates suspicious activity in the covered systems, including outside the IT team’s working hours.

You coordinate the response.

Validated alerts reach the designated contacts. The response follows the agreed authorisations, while remediation and recovery remain with the responsible IT team.

Monitoring continues after remediation. Subsequent tests reassess exposure, while backups and recovery procedures remain necessary to resume operations after an interruption.

VISIBILITY FOR MANAGEMENT

A summary of SOC activity.

An anonymised executive report: monitored assets, analysed events and incident status.

SOC executive report

SOC executive report — page 1
Open PDF ↗
Report preview

This is a summary for management, distinct from the technical documentation of investigations. The example retains the actual statuses: 2 incidents resolved, 7 suppressed and 1 open. “Suppressed” is an alert-triage status, not evidence that a vulnerability has been fixed. The client’s name, systems, identifiers and incident dates have been anonymised.

NIS2 MEASURES

Detect and document incidents.

24/7/365 monitoring, analysis and incident escalation contribute to the security incident handling process. We agree the monitored assets, contacts and authorised actions; the company retains responsibility for recovery and for the notifications required by the applicable framework.

The service’s contribution is defined within the organisation’s security programme. Compliance also involves governance, procedures and reporting obligations, depending on applicability.

INCIDENT RESPONSE

Who does what, before and after an alert.

The SOC team investigates events in the included systems and contacts the designated people. Containment actions depend on the integrations and the authorisation agreed before activation.

ActivitySOC teamClient IT team / provider
Detection and analysis24/7/365 monitoring, correlation, investigation and validation of events.Asset inventory, collection configuration and required access.
Alerting and coordinationEscalation to the agreed contacts and recommendations for containment.Available contacts and decisions concerning the affected environment.
ContainmentMay include isolating a compatible device or other authorised actions, under the service conditions.Authorising actions and applying measures that require intervention in the infrastructure.
Remediation and recoveryInvestigation findings and incident coordination.Fixing the cause, restoring data and resuming operations.

We define the contact list, integrations, severity levels and response rules in the proposal and service documentation. SOC complements the existing IT team.

FREQUENTLY ASKED QUESTIONS

The details that
matter when choosing.

What do the local agent, AI and the SOC team do?

The local agent collects data and can execute authorised actions sent by the platform. The data is correlated in the monitoring service, with AI-assisted analysis and triage. Analysts investigate and validate threats, and the response takes place within the technical limits and the agreed authorisation.

Does the service also run at weekends and on public holidays?

Yes. Monitoring and analysis of events from the included systems continue 24/7/365. At activation, we also agree the escalation contacts outside working hours.

Does SOC replace the internal IT team?

No. SOC complements the IT team by monitoring and analysing security events 24/7/365. The internal team or the designated IT provider continues to administer the systems and carry out the necessary remediation and recovery.

Does SOC respond to an incident or only send an alert?

SOC investigates events, alerts the designated contacts and can isolate affected devices, within the limits of the integrations and authorised actions. Remediation and recovery of systems are carried out by the designated IT team.

Who receives the alerts, including at weekends?

The client’s IT team, through the people and channels agreed at activation. We also define the contacts for escalation outside working hours, including at night, at weekends and on public holidays.

If I have SOC, do I still need to fix vulnerabilities?

Yes. Monitoring helps detect and investigate suspicious activity, but identified vulnerabilities must be addressed through the agreed remediation measures. SOC, testing and remediation serve complementary functions.

Can I use SOC if I work with an external IT service provider?

Yes. Your provider can take part in the configuration, receive the alerts and carry out remediation. We agree responsibilities and how we work together from the outset.

Do you provide IT services?

You can include this solution in your offering for your clients.

Partner programme
NEXT STEP

Security starts with a conversation.

Tell us what you want to protect. We will agree the right starting point together.

Request a SOC proposal
PRACTICAL GUIDE

What to do after a pentest if you can’t fix all vulnerabilities straight away

How to prioritise vulnerabilities after a pentest, reduce exposure until remediation and complement retesting with 24/7/365 SOC monitoring.

Read the article (in Romanian)