
Operate
AI SOC: managed detection and response
Detection and response where the machine layer examines everything and human judgment is spent on the fraction that earns it. Monitoring runs continuously. Out of hours, containment is automated and a named on-call engineer is reachable for severity-one events.
Duration
Onboarding 4–6 weeks, then continuous
Built on
ISO/IEC 27001:2022 · MITRE ATT&CK
Who this is for
CISO
Cannot fund an analyst rota and cannot accept an unwatched estate.
IT director
Is the de facto security team and is also running everything else.
Board or risk owner
Needs to know that something is watching, and what happens when it finds something.
NIS2-scoped entity
Has a 24-hour reporting obligation and no detection capability to trigger it.
Analyst hours are the hard limit, and the attacker no longer has one
A conventional security operations centre routes alerts into a queue and works them in sequence. That design has a ceiling built into it: the number of things you can examine is the number of analyst hours you can pay for. Everything beyond that ceiling is not examined — it is closed in bulk, aged out, or quietly ignored.
That was tolerable while the attacker faced a similar constraint. They no longer do. Reconnaissance runs unattended, phishing that needed a fluent writer and a week needs a prompt and four minutes, and one adversary can now generate more credible, well-targeted attempts per hour than a small team can read. The queue stopped being a workflow and became the vulnerability.
The only answer that scales is to put the same leverage on the defending side. A machine layer correlates across endpoint, identity, cloud and external signal, deduplicates, scores, and closes the overwhelming majority — with its reasoning recorded, so a closure can be inspected rather than trusted. What reaches a person has already been enriched with the context an analyst would otherwise spend twenty minutes assembling.
This changes what the human is for. Not triage, which is mechanical and better done mechanically, but judgement: is this pattern what it appears to be, does this containment action cost more than the incident, is this the second time we have seen this and therefore a problem rather than an event.
Coverage is where we will be plainer than most. Monitoring runs continuously. Out of hours, containment is automated and a named on-call engineer is reachable for severity-one events. During business hours you have the full team, with an analyst who knows your estate rather than whoever is next in the queue. Overnight and at weekends, detection and containment do not pause: the playbooks you have signed execute under authority you delegate in advance, so isolating a compromised host does not wait for someone to answer a telephone. Only severity one pages out of hours, the response target is one hour, and the severity definitions are agreed with you in writing rather than left to interpretation — because the middle of an incident is the wrong moment to discover what 'monitoring' meant. What we will not claim is a large room of people watching screens at three in the morning, because that is not what you would be buying.
How we do it
- 01
Onboarding and telemetry
2–3 weeks
Connecting the sources — endpoint, identity, cloud control plane, network, and external exposure signal. We map what you have before proposing anything new; most estates are already generating more usable telemetry than anyone is collecting.
- 02
Baseline and tuning
2–3 weeks
Learning what normal looks like in your environment. This is the work that determines whether the service is useful or exhausting, and rushing it is how organisations end up ignoring their own alerts.
- 03
Playbooks and delegated authority
1 week
What we are permitted to do without asking, and what always requires you. Written as a matrix and signed, because the moment to establish whether we may isolate a production host is not during the incident.
- 04
Monitor then enforce
2 weeks
Playbooks run in observation first, so you see what would have happened before anything happens.
- 05
Run
continuous
Detection, triage, escalation and containment, with a named point of contact and monthly reporting that shows what was closed and why, not only what was escalated.
- 06
Improve
quarterly
Every significant incident returns to the detection set and to your risk assessment. This is the loop most operations skip, and it is why their alert volumes rise while their control effectiveness drifts.
Named artefacts
What you receive
- Connected telemetry inventory, with the gaps named
- Tuned detection baseline for your environment
- Response playbooks and a signed delegated authority matrix
- Escalation path with named contacts and thresholds
- Named on-call escalation for severity-one events, responding within one hour by phone or email, with the severity definitions agreed in your service description
- Incident records, with the triage reasoning retained for closed items
- Monthly report: what was seen, what was closed and on what basis, what was escalated
- Quarterly review feeding findings back into the risk register
- Incident evidence in a form that supports a regulatory notification clock
What we need from you
- Access to the telemetry sources, and someone who can approve that access without a three-week procurement cycle.
- A signed delegated authority matrix. Without it every containment action becomes a phone call, which defeats the purpose.
- Your asset and business-criticality information. Without it we cannot rank an alert on a payroll server above one on a test box.
- A named contact on your side for escalations, and a deputy.
What changes
- 01Everything is examined, rather than the queue being worked until the day ends.
- 02Escalations arrive with context attached, so the first question is a decision rather than an investigation.
- 03Containment happens at machine speed for the actions you have pre-authorised.
- 04You can evidence detection and response to an auditor, a regulator or an insurer.
- 05Where you are NIS2-scoped, the 24-hour notification clock starts from a detection you actually have.
What it costs
On request
All prices exclude VAT.
Questions
Is it 24/7?
Monitoring is. The platform detects and contains continuously, at any hour, against actions you have pre-approved — so the first response to a severity-one event out of hours is automated and immediate, not a person waking up. Human analysis is on shift during agreed hours. Outside them, a severity-one event pages a named on-call engineer who responds within one hour, by phone or by email. Severity two and below wait for the next working day, deliberately, because an escalation path that pages for everything stops being answered. We are precise about this because the distinction only matters once, at three in the morning, and a provider who blurs it is making a promise they have not resourced.
What counts as severity one?
It is defined with you during onboarding and written into the service description, rather than left to our judgement at two in the morning. Typically: confirmed ransomware behaviour, an identity compromise with privileged access, or containment that failed to hold. Everything below it is actioned automatically where a playbook covers it and reviewed the next working morning.
What happens to the alerts the machine closes?
They are retained with the reasoning that closed them, and they are sampled in the monthly review. A closure you cannot inspect is indistinguishable from a closure that was wrong.
Will you take action on our systems?
Only the actions in the playbooks you have signed, and only within the scope you set. Everything else is escalated. The matrix is reviewed quarterly, and most clients widen it once they have seen a few months of what we actually do.
We already have a SIEM. Does this replace it?
Usually not — it sits on top of what you already collect. If your SIEM is under-tuned, the first month is largely spent fixing that, and you keep the improvement whether or not you continue with us.
What does it cost?
It depends on estate size, log volume and how much of the human response you want inside business hours, so we quote rather than publish. The continuous monitoring and the out-of-hours on-call route are part of the service rather than an upgrade. The onboarding is a fixed scope and is quoted separately from the run.

Leave with your top three risks documented
Thirty minutes with a senior practitioner. No slideware, no sales engineer.