Devices
Analysis of events from workstations and servers, correlated with information from existing protection solutions.
Monitoring, analysis and response to security events, including nights, weekends and public holidays.
Request a SOC proposalMonitoring covers the workstations, servers, firewalls and Microsoft 365 accounts included in the service, subject to supported systems and enabled integrations. We agree the contacts and response responsibilities from the outset.
Analysts investigate suspicious activity and alert the client’s IT team. Compromised devices can be isolated under the conditions agreed at activation.

Analysis of events from workstations and servers, correlated with information from existing protection solutions.
Monitoring of firewall events to identify suspicious connections and malicious activity.
Monitoring of Microsoft 365 events and suspicious sign-ins for the covered accounts and integrations.
The TRU SOC service combines local collection, correlation in the monitoring platform and AI-assisted analysis with investigation by a human team, 24/7/365.
Local agents and integrations collect the relevant events from devices and the included services. The SIEM platform brings this data together for correlation and investigation.
The AI component correlates activity and helps filter out irrelevant alerts before human analysis, so that the investigation focuses on the signals that need attention.
Analysts validate threats and coordinate the response under the agreed conditions. The designated IT team receives the relevant alerts and the information needed to respond.
SIEM stands for security information and event management. At activation, we agree the integrated sources, authorised actions and escalation contacts.
A clear process for investigating events and coordinating the response.
Access to the SOC service for a monthly operating cost, without building your own security operations centre.
The relevant systems, accounts and integrations.
Event collection, access and the notification flow.
Operation of the service and analysis of security events.
Illustrative example: on a weekend evening, a suspicious execution is detected on a monitored workstation.
Analysts correlate events and check for indicators of an incident in the systems included in the service.
The incident is escalated to the designated contacts through the agreed channels and procedure.
If the situation and the procedure require it, SOC can isolate the device. The IT team continues with remediation and recovery.
Monitoring and analysis are available 24/7/365. Permitted actions, contacts and response conditions are agreed before activation.
We start from an inventory of the systems to be monitored: workstations, servers, firewalls and Microsoft 365 accounts. We check the supported systems and the integrations required, then define the scope of the service.
Monitoring and analysis run 24/7/365 for the included systems. Before activation, we clarify the configuration, the escalation contacts and the IT team’s responsibilities.
These elements link monitoring to the company’s ability to respond to an incident. Responsibilities are agreed together with the designated IT team.
Discuss SOC coverageTwo businesses that depend on system availability chose SOC monitoring to analyse security events between penetration tests.
SOC after adopting monthly testing
Anonymised real caseA distributor in the automotive industry, with daily revenue exceeding €100,000, needed to reduce the risk of an operational interruption. Beyond the impact on revenue, management considered the possibility of some customers buying from competitors during an outage. The company chose monthly internal and external PenTest to identify vulnerabilities and remediation measures.
Not all measures could be implemented immediately. To track suspicious activity during this period, the company implemented SOC across its infrastructure, with security event monitoring and analysis 24/7/365.
Events collected from the included systems are correlated and investigated. SOC analysts validate relevant signals and alert the designated IT team with information useful for the response. Response actions follow the conditions agreed when the service is activated.
Continuous monitoring complements remediation and remains in place after the identified issues are closed. The IT team implements the necessary measures and retesting verifies the results; SOC tracks events during day-to-day operation.
Vulnerability assessment in this project24/7/365 SOC for the included systems
Anonymised real caseFor a company that sells exclusively online, system availability is essential: an interruption can stop orders and lead customers to choose other suppliers. Management chose PenTest to assess the infrastructure’s exposure and complemented this protection with SOC, to analyse activity between tests.
SOC added security monitoring 24/7/365, including nights, weekends and public holidays. Events from the systems included in the service are analysed continuously, so suspicious activity can also be investigated outside the IT team’s working hours.
The SOC service correlates signals, investigates alerts and sends relevant information to the client’s IT team. Contacts and escalation outside working hours are agreed at activation; actions such as isolating a device depend on the available integration and the agreed authorisation.
The company thus combines periodic vulnerability assessment with analysis of events during operation. The IT team implements remediation and recovery measures within the business continuity plan.
Assessing the online retailer’s infrastructureSOC tracks activity in the included systems, while PenTest findings help the company understand its exposure.
Test reports show what needs to be fixed. The IT team can track the remaining measures and the risks that need attention until they are resolved.
SOC correlates events and investigates suspicious activity in the covered systems, including outside the IT team’s working hours.
Validated alerts reach the designated contacts. The response follows the agreed authorisations, while remediation and recovery remain with the responsible IT team.
Monitoring continues after remediation. Subsequent tests reassess exposure, while backups and recovery procedures remain necessary to resume operations after an interruption.
An anonymised executive report: monitored assets, analysed events and incident status.
This is a summary for management, distinct from the technical documentation of investigations. The example retains the actual statuses: 2 incidents resolved, 7 suppressed and 1 open. “Suppressed” is an alert-triage status, not evidence that a vulnerability has been fixed. The client’s name, systems, identifiers and incident dates have been anonymised.
24/7/365 monitoring, analysis and incident escalation contribute to the security incident handling process. We agree the monitored assets, contacts and authorised actions; the company retains responsibility for recovery and for the notifications required by the applicable framework.
The service’s contribution is defined within the organisation’s security programme. Compliance also involves governance, procedures and reporting obligations, depending on applicability.
The SOC team investigates events in the included systems and contacts the designated people. Containment actions depend on the integrations and the authorisation agreed before activation.
| Activity | SOC team | Client IT team / provider |
|---|---|---|
| Detection and analysis | 24/7/365 monitoring, correlation, investigation and validation of events. | Asset inventory, collection configuration and required access. |
| Alerting and coordination | Escalation to the agreed contacts and recommendations for containment. | Available contacts and decisions concerning the affected environment. |
| Containment | May include isolating a compatible device or other authorised actions, under the service conditions. | Authorising actions and applying measures that require intervention in the infrastructure. |
| Remediation and recovery | Investigation findings and incident coordination. | Fixing the cause, restoring data and resuming operations. |
We define the contact list, integrations, severity levels and response rules in the proposal and service documentation. SOC complements the existing IT team.
The local agent collects data and can execute authorised actions sent by the platform. The data is correlated in the monitoring service, with AI-assisted analysis and triage. Analysts investigate and validate threats, and the response takes place within the technical limits and the agreed authorisation.
Yes. Monitoring and analysis of events from the included systems continue 24/7/365. At activation, we also agree the escalation contacts outside working hours.
No. SOC complements the IT team by monitoring and analysing security events 24/7/365. The internal team or the designated IT provider continues to administer the systems and carry out the necessary remediation and recovery.
SOC investigates events, alerts the designated contacts and can isolate affected devices, within the limits of the integrations and authorised actions. Remediation and recovery of systems are carried out by the designated IT team.
The client’s IT team, through the people and channels agreed at activation. We also define the contacts for escalation outside working hours, including at night, at weekends and on public holidays.
Yes. Monitoring helps detect and investigate suspicious activity, but identified vulnerabilities must be addressed through the agreed remediation measures. SOC, testing and remediation serve complementary functions.
Yes. Your provider can take part in the configuration, receive the alerts and carry out remediation. We agree responsibilities and how we work together from the outset.
You can include this solution in your offering for your clients.
Tell us what you want to protect. We will agree the right starting point together.
How to prioritise vulnerabilities after a pentest, reduce exposure until remediation and complement retesting with 24/7/365 SOC monitoring.
Read the article (in Romanian)