Skip to content

SOC and monitoring

SOC and monitoring: protected at night too

Your office closes at six, your IT keeps running. With a managed SIEM and a SOC that is staffed day and night, analysts assess what is happening on your systems and step in when something is not right. Afterwards, you read what was done.

How it works

From scattered signals to one clear picture

Your devices, servers, firewall and Microsoft 365 give off signals all day long: who signs in where, which program starts, which traffic leaves the network. On their own they say very little. A SIEM collects them in one place and connects the dots. In the SOC, security analysts look at what comes out of that, 24 hours a day, 7 days a week. They tell the normal from the unusual and take action when needed. You do not get a flood of alerts, only what matters, explained in plain language.

  • Signals from devices, servers, network and Microsoft 365 in one place
  • Assessed by analysts, at night and at weekends too
  • A suspicious device or account isolated straight away, even outside office hours
  • Log files stored centrally for NIS2, ISO 27001 and audits
An Infodatek Group engineer wearing glasses at his desk, behind his screen.

At a glance

SIEM
The system that collects, stores and connects the signals from your entire environment.
SOC
The team of analysts who assess those signals day and night and step in when needed.
Follow-up
Our own team, who know your environment, handle the next steps and talk them through with you.

Two kinds of monitoring

Monitoring your systems and monitoring your security

When people hear monitoring, they often think of whether everything is running: is the server reachable, is the disk filling up, did the backup succeed. That kind of monitoring is part of proactive management, and we do it for every environment we manage. It lets us fix a lot before you notice anything.

Security monitoring looks at something else: behaviour. A sign-in from an unexpected country, a forwarding rule that suddenly sends all email outside, a program behaving oddly on a laptop. That takes people who can interpret signals, and that is what the SOC is for. The two complement each other: one keeps your systems healthy, the other keeps them secure.

What the SOC does

What happens when the SOC spots something

Not every signal is an incident. The analysts first assess what is going on. If it is normal behaviour, that is the end of it. If something is not right, clear steps follow.

  • Taking the device off the network, so the rest of your environment carries on undisturbed
  • Blocking a suspicious sign-in or locking an account
  • Recording what happened and which steps were taken
  • Handing over to our own team for recovery and follow-up
  • A report in plain language, so you know what was going on

Microsoft 365

Day and night visibility of your Microsoft 365 accounts

A lot of work now happens in the cloud, and there it is all about identities: who is signed in, and are they allowed to be. That is why we also monitor your Microsoft 365 environment. The SOC watches for sign-ins that do not match someone's usual pattern, forwarding rules nobody consciously created and accounts that behave differently from normal.

If the SOC sees something like that, it can lock the account straight away. Our team then helps the employee get back to work securely, and together we check that everything is in order.

Demonstrable

Log files that help you with NIS2 and audits

NIS2 and ISO 27001 call for insight into what happens in your environment and how you deal with incidents. The SIEM collects and stores the log files centrally, so you have that information when an auditor or customer asks for it. And after an incident, the SOC report is already there.

In Digital Care Managed Operations, this day and night monitoring can be added as MDR, and it comes as standard in the Elite edition. You can also take the SOC and SIEM on their own, as a managed service.

Who it is for

Who benefits most from round-the-clock monitoring

A SOC is not just for large companies. These are organisations where it fits well.

Healthcare and social care

Care carries on day and night, and so do the systems. With monitoring outside office hours and centrally stored log files, you are better aligned with NEN 7510 and NIS2, without your own staff having to keep watch at night.

Shift work

In logistics and manufacturing, the night is often just working time. The SOC watches devices, servers and network while the night shift carries on, and our team handles the follow-up with people who know your environment.

SMEs without a security team

Setting up your own SOC is neither feasible nor necessary for an SME. You get monitoring by analysts who are available day and night, with a report you can read without specialist knowledge.

Businesses with their own IT department

Your IT staff handle the daily work during the day. The SOC also keeps watch in the evenings, at night and at weekends and hands over what happened, so your own team does not have to be on call all the time.

Organisations under NIS2

Detection and an approach to incidents are among the measures NIS2 asks for. With a SIEM and a SOC you have both in place, and you can show how you have set it up.

Frequently asked questions

Frequently asked questions about SOC and monitoring

What is the difference between a SIEM and a SOC?

A SIEM is technology: it collects the signals and log files from your devices, servers, network and Microsoft 365, stores them and looks for connections. The SOC is people: security analysts who assess what the SIEM flags and decide whether action is needed. Together they make sure you are not just collecting data, but that something is actually done with it.

Will we be receiving alerts every night?

No, and that is the whole idea. The analysts filter out normal behaviour, so you only hear about what matters. If they step in, you receive a report of what happened and what was done. On top of that, the regular reporting shows how things stand in general, in language you can follow without technical knowledge.

Which systems do you connect to the SIEM?

As a starting point, your devices and servers, your network and your Microsoft 365 environment, because that is where most activity happens. Together we look at whether anything else should be added, such as the firewall at a second location. We record which sources are connected, so you know exactly what is being monitored.

Do we need our own IT department to work with this?

No. The SOC steps in itself where needed, and our own team handles the follow-up: restoring, checking and adjusting something in your environment where necessary. If you do have an IT department, we work with them and agree who picks up what. That way it fits in with the way you work today.

Is this also part of Digital Care?

Yes. In Digital Care Managed Operations, with a fixed price per employee per month, you can add day and night monitoring as MDR, managed detection and response. It comes as standard in the Elite edition. Because management and monitoring then sit with the same team, we can see more quickly whether an alert is linked to a recent change in your environment.

Wondering what Infodatek can do for you?

A thirty-minute call with one of our specialists. Your environment, your questions. An honest conversation.

An Infodatek Group colleague picking up the handset of a desk phone.