Your office closes at six, your IT keeps running. With a managed SIEM and a SOC that is staffed day and night, analysts assess what is happening on your systems and step in when something is not right. Afterwards, you read what was done.
Your devices, servers, firewall and Microsoft 365 give off signals all day long: who signs in where, which program starts, which traffic leaves the network. On their own they say very little. A SIEM collects them in one place and connects the dots. In the SOC, security analysts look at what comes out of that, 24 hours a day, 7 days a week. They tell the normal from the unusual and take action when needed. You do not get a flood of alerts, only what matters, explained in plain language.
Signals from devices, servers, network and Microsoft 365 in one place
Assessed by analysts, at night and at weekends too
A suspicious device or account isolated straight away, even outside office hours
Log files stored centrally for NIS2, ISO 27001 and audits
At a glance
SIEM
The system that collects, stores and connects the signals from your entire environment.
SOC
The team of analysts who assess those signals day and night and step in when needed.
Follow-up
Our own team, who know your environment, handle the next steps and talk them through with you.
Two kinds of monitoring
Monitoring your systems and monitoring your security
When people hear monitoring, they often think of whether everything is running: is the server reachable, is the disk filling up, did the backup succeed. That kind of monitoring is part of proactive management, and we do it for every environment we manage. It lets us fix a lot before you notice anything.
Security monitoring looks at something else: behaviour. A sign-in from an unexpected country, a forwarding rule that suddenly sends all email outside, a program behaving oddly on a laptop. That takes people who can interpret signals, and that is what the SOC is for. The two complement each other: one keeps your systems healthy, the other keeps them secure.
What the SOC does
What happens when the SOC spots something
Not every signal is an incident. The analysts first assess what is going on. If it is normal behaviour, that is the end of it. If something is not right, clear steps follow.
Taking the device off the network, so the rest of your environment carries on undisturbed
Blocking a suspicious sign-in or locking an account
Recording what happened and which steps were taken
Handing over to our own team for recovery and follow-up
A report in plain language, so you know what was going on
Microsoft 365
Day and night visibility of your Microsoft 365 accounts
A lot of work now happens in the cloud, and there it is all about identities: who is signed in, and are they allowed to be. That is why we also monitor your Microsoft 365 environment. The SOC watches for sign-ins that do not match someone's usual pattern, forwarding rules nobody consciously created and accounts that behave differently from normal.
If the SOC sees something like that, it can lock the account straight away. Our team then helps the employee get back to work securely, and together we check that everything is in order.
Demonstrable
Log files that help you with NIS2 and audits
NIS2 and ISO 27001 call for insight into what happens in your environment and how you deal with incidents. The SIEM collects and stores the log files centrally, so you have that information when an auditor or customer asks for it. And after an incident, the SOC report is already there.
In Digital Care Managed Operations, this day and night monitoring can be added as MDR, and it comes as standard in the Elite edition. You can also take the SOC and SIEM on their own, as a managed service.
Who it is for
Who benefits most from round-the-clock monitoring
A SOC is not just for large companies. These are organisations where it fits well.
Healthcare and social care
Care carries on day and night, and so do the systems. With monitoring outside office hours and centrally stored log files, you are better aligned with NEN 7510 and NIS2, without your own staff having to keep watch at night.
Shift work
In logistics and manufacturing, the night is often just working time. The SOC watches devices, servers and network while the night shift carries on, and our team handles the follow-up with people who know your environment.
SMEs without a security team
Setting up your own SOC is neither feasible nor necessary for an SME. You get monitoring by analysts who are available day and night, with a report you can read without specialist knowledge.
Businesses with their own IT department
Your IT staff handle the daily work during the day. The SOC also keeps watch in the evenings, at night and at weekends and hands over what happened, so your own team does not have to be on call all the time.
Organisations under NIS2
Detection and an approach to incidents are among the measures NIS2 asks for. With a SIEM and a SOC you have both in place, and you can show how you have set it up.
Frequently asked questions
Frequently asked questions about SOC and monitoring
What is the difference between a SIEM and a SOC?
A SIEM is technology: it collects the signals and log files from your devices, servers, network and Microsoft 365, stores them and looks for connections. The SOC is people: security analysts who assess what the SIEM flags and decide whether action is needed. Together they make sure you are not just collecting data, but that something is actually done with it.
Will we be receiving alerts every night?
No, and that is the whole idea. The analysts filter out normal behaviour, so you only hear about what matters. If they step in, you receive a report of what happened and what was done. On top of that, the regular reporting shows how things stand in general, in language you can follow without technical knowledge.
Which systems do you connect to the SIEM?
As a starting point, your devices and servers, your network and your Microsoft 365 environment, because that is where most activity happens. Together we look at whether anything else should be added, such as the firewall at a second location. We record which sources are connected, so you know exactly what is being monitored.
Do we need our own IT department to work with this?
No. The SOC steps in itself where needed, and our own team handles the follow-up: restoring, checking and adjusting something in your environment where necessary. If you do have an IT department, we work with them and agree who picks up what. That way it fits in with the way you work today.
Is this also part of Digital Care?
Yes. In Digital Care Managed Operations, with a fixed price per employee per month, you can add day and night monitoring as MDR, managed detection and response. It comes as standard in the Elite edition. Because management and monitoring then sit with the same team, we can see more quickly whether an alert is linked to a recent change in your environment.
Necessary cookies make the site work. Statistics and marketing are only switched on if you want them, and you can change your choice at any time. Read our privacy policy