In this guide
What a SOC is, in one paragraph
A Security Operations Centre is a team whose job is to watch the alerts your security systems produce, investigate the ones that look real, and start the response when something is confirmed. The tools (Defender, Entra ID, your firewall, your backup) generate signals around the clock. The SOC supplies judgement, continuity and urgency. Without one, an alert at 11pm on Saturday is read at 9am on Monday, which in a ransomware incident is the difference between one laptop and the whole business.
Large organisations run their own. Small businesses cannot, which is why SOC services exist: a shared team watching many businesses' tenants, with procedures agreed in advance for each.
Monitoring, investigation, escalation: how the pieces fit
- Monitoring. Alerts from your Microsoft 365 tenant (Defender for Business or Endpoint, Defender for Office 365, Entra ID sign-in and identity protection) and, where included, other systems flow to the SOC platform continuously. [TO CONFIRM: the exact sources our service monitors and the licences it requires.]
- Triage. Most alerts are noise: a director logging in from a hotel, a known admin tool, a false positive. An analyst confirms and closes these without waking anyone. The value of a good SOC is as much in what it does not escalate as in what it does.
- Investigation. For anything that looks real, the analyst builds the picture: which account, which device, what happened before and after, is it spreading.
- Escalation and response. Confirmed incidents go to your nominated contacts and our engineers under an agreed procedure. Some containment actions are pre-authorised so they happen immediately; others wait for your decision. [TO CONFIRM: which actions the SOC may take directly, such as isolating a device, revoking sessions, disabling an account or resetting a password; response-time commitments; escalation contacts and hours.]
- Recovery and lessons. Engineers restore, close the gap that let it in, and write up what happened.
Not sure which of these applies to your business? Ask an engineer.
Book a Discovery CallAn illustrative overnight incident
This scenario is illustrative, not a customer story.
02:10, Wednesday. A member of staff's password, reused from a breached shopping site, is tried against Microsoft 365 by an automated attacker. MFA blocks the sign-in, but the attacker sends a burst of push notifications hoping the user approves one half-asleep. Entra ID raises a risky sign-in alert.
02:14. The SOC sees the alert: sign-in attempts from an unfamiliar country, multiple MFA denials, then one approval. That last detail changes everything: the attacker is in.
02:20. Under the pre-agreed procedure [TO CONFIRM], the analyst revokes the account's sessions and forces a password reset, cutting the attacker's access. A check of the mailbox finds a newly created rule forwarding invoices to an external address, created at 02:16. It is removed and the address noted.
02:35. The incident is escalated to the on-call engineer and the client's nominated contact by the agreed channel, with what happened and what was done.
08:30. The user re-registers MFA with a phishing-resistant method. The engineer reviews sign-in logs, confirms nothing else was touched, checks whether any invoices were sent during the window, and adds the attacker's infrastructure to block lists. A short write-up goes to the client.
The point is not that the attack was stopped. It is that the forwarding rule was found at 02:20 rather than when a customer rang three weeks later to ask why their payment had not arrived.
What a SOC does not do
- It does not prevent attacks. Prevention is configuration: MFA, patching, email protection, device management. The SOC catches what gets past them.
- It does not replace backups. If ransomware runs, restoration is a backup job. The SOC's role is to make the blast radius one device rather than all of them.
- It does not see what it is not connected to. A SOC watching Microsoft 365 does not see an on-premises server or a SaaS app unless those are fed in.
- It does not guarantee anything. Any provider promising no breach is selling something else. What a SOC changes is time to detection and time to response.
- It is not a substitute for people knowing what to do. Staff still need to know how to report a suspicious email and what happens next.
Want a second opinion before you buy licences?
We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.
Does a business your size need one?
Signs that point to yes:
- You hold client, financial or personal data that would hurt to lose or leak.
- Staff work outside office hours or across time zones, so attacks have cover.
- An insurer or customer asks about detection and response, or your renewal price depends on it.
- You have already had an account compromise, a near miss or an invoice fraud attempt.
- You have Business Premium or the Defender Suite and nobody reads what they report.
Signs that you can wait: a very small team, no sensitive data, and a provider who reviews alerts every working day. Even then, the gap between Friday evening and Monday morning is the risk to weigh.
Cost depends on the number of users and devices and what is monitored. It is a monthly per-user or per-device fee on top of managed support. [TO CONFIRM: our pricing model.] Compare it with the cost of a single business-hours-only incident that ran for a weekend.
Our 24/7/365 SOC service
Our SOC service monitors clients' Microsoft 365 tenants around the clock, triages and investigates alerts, and escalates confirmed incidents under a procedure agreed with each client at onboarding. It is included in our managed security offering and can be added to an existing managed service. [TO CONFIRM: eligibility, prerequisites (Business Premium, Defender Suite), included response actions, and any service commitments.]
For the prevention side, see Is your Microsoft 365 actually secure? and the Microsoft 365 licensing and security guide, which explains the licence that gives the SOC something to watch.
Want a second opinion before you buy licences?
We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.
Frequently asked questions
What does SOC stand for?
Security Operations Centre: the team and tooling that monitor security alerts, investigate them and coordinate the response.
Is a SOC the same as antivirus or Defender?
No. Defender and other tools detect and raise alerts. The SOC is the people who read, investigate and act on them. One without the other is either noise nobody hears or a team with nothing to watch.
What is MDR?
Managed Detection and Response: the industry name for a SOC service that includes taking response actions, not just alerting. Ask any provider exactly which actions are included.
Does the SOC fix the problem or just tell us?
It depends on the service agreement. Some containment actions are usually pre-authorised so they happen immediately; broader remediation is an engineering task that follows. Our service scope is [TO CONFIRM].
Can a small business afford a SOC?
Shared SOC services price per user or device, which puts them within reach of businesses that could never staff their own. Whether it is worth it depends on the data you hold and the cost of a slow response.
Do we need Business Premium for SOC monitoring?
The SOC watches the signals your licence produces. Business Premium (Defender for Business, Entra ID P1) gives it the essentials; the Defender Suite adds richer data and longer history. [TO CONFIRM: our prerequisites.]
Discuss your security coverage
Tell us what you have and who is watching it today. We will explain what a SOC would add for a business your size, what it would cost, and whether you need it yet.
- What your current tools report and who sees it out of hours.
- What our SOC would monitor and how escalation would work for you.
- The prerequisites and the cost.
- An honest view if you do not need it yet.
What has changed on this page
- 10 September 2026Page published. Service commitments marked for confirmation.


