Managed Security & SOC

SOC as-a-Service

24/7 managed Security Operations Center that detects and responds to threats before they become crises

We provide a fully managed SOC service covering security event monitoring, threat detection, and immediate response, powered by SIEM, UEBA, and advanced threat intelligence — without the cost of building an in-house SOC.

What's included

  • 24/7 monitoring of endpoint, network, identity, and cloud telemetry through a centralized SIEM.
  • Detection use-case engineering mapped to the MITRE ATT&CK framework for adversary tactic and technique coverage.
  • Alert triage, investigation, and severity-based escalation, with a named analyst owning each case.
  • Threat intelligence enrichment and proactive threat hunting for indicators that signature-based rules miss.
  • A defined SLA with mean-time-to-detect (MTTD) and mean-time-to-respond (MTTR) targets, plus scheduled management reporting.
  • Integration with your existing stack (EDR, firewalls, IAM, cloud) with no costly in-house SOC to build.

Methodology & standards

01

Onboarding and baselining: inventory log sources, connect them to the SIEM, and define critical assets and monitoring scope against the Detect and Respond functions of the NIST CSF.

02

Detection engineering: build correlation content and use-cases mapped to MITRE ATT&CK, with UEBA behavioral baselining for anomaly detection.

03

Continuous operations: 24/7 monitoring, alert triage, and investigation driven by standard playbooks and agreed escalation tiers.

04

Threat hunting and intelligence: regular hunt cycles and indicator enrichment that feed back into rule tuning to cut false positives.

05

Measure and improve: periodic review of MTTD, MTTR, and ATT&CK coverage, with a governance report for executive management.

Deliverables

  • A live monitoring dashboard for alert status, open incidents, and coverage.
  • A monthly security operations report covering MTTD, MTTR, alert volume, and false-positive rate.
  • A documented incident log with timeline, containment actions, and recommendations for each confirmed incident.
  • A MITRE ATT&CK detection-coverage matrix showing covered techniques and gaps.
  • Auditable, documented playbooks for recurring incident types.
  • A quarterly board report in risk language with a monitoring-maturity improvement plan.

Regulatory controls it satisfies

SAMA Cyber Security Framework (CSF)
Covers continuous monitoring, security event management, and threat detection for institutions regulated by the Saudi Central Bank.
NCA Essential Cybersecurity Controls (ECC)
Supports the Event Logs and Monitoring Management domain, including continuous log collection and analysis.
NCA Critical Systems Cybersecurity Controls (CSCC)
Enhanced monitoring and extended log retention for critical systems where they apply.
NIST Cybersecurity Framework (CSF)
Operationalizes the Detect and Respond functions around the clock.
ISO/IEC 27001
Supports logging, monitoring, and information security event management controls.

Typical timeline

Onboarding and log-source integration typically takes two to four weeks to reach effective monitoring, followed by continuous 24/7 operations under a renewable annual subscription.

Common questions

Do we need to replace our existing security tools?

No. We integrate with your current SIEM, EDR, and firewalls where possible, and recommend additions only where there is a genuine coverage gap.

Where are our logs and data stored?

Logs are processed and retained in line with Saudi data-residency expectations and PDPL obligations, with strict access controls and full tenant separation.