Услуга · Information security

SOC: incident monitoring

Security tools write events continuously, but usually there is nobody to read them: the logs are opened after an incident, not before. Monitoring turns that logic round - the suspicious is noticed while there is still time to intervene.

Round the clock
a duty shift
Correlation
of events from different systems
Procedure
who does what
Review
after an incident

What the work includes

Monitoring makes sense when there is something to monitor: first the security tools and the logs, then monitoring over them.

Discuss the scope

Sources

Connecting firewalls, antivirus, domain controllers, servers and applications.

Correlation

Correlating events from different systems. Individually they are harmless; together they form the picture of an attack.

Detection

Rules for your infrastructure plus a library of known scenarios.

Actions

Whom to wake, what to shut down, in what order and with whose authority.

Review

How they got in, what they managed to do, what to do so it does not happen again.

Reports

A regular summary of incidents and of how the picture is changing.

How it goes

Connection takes from two weeks to a month, and almost all of that time goes on fitting the rules to your specifics.

01

Survey

We establish which of the existing hardware and software writes events at all and what can be taken from it.

02

Connection

We configure log forwarding and normalisation to a single format.

03

Tuning

In the first weeks we clear out false positives, otherwise the noise devalues the whole exercise.

04

Work

Round-the-clock monitoring, alerts to a set procedure, monthly reports.

Monitoring without the authority to act is useless. At three in the morning the duty engineer sees an attack but cannot shut the server down, and there is nobody to call. A list of responsible people with phone numbers and decision-making authority is prepared along with the connection, not after the first case.

Questions and answers

The basics: logging on, antivirus centralised, the perimeter closed, copies protected. Monitoring over unprotected infrastructure only records how you are being broken into; it does not help prevent it.

Reckon from the cost of downtime and of a leak. Where IT serves office work, basic measures and good backups are usually enough. Where production would stop or client data would leak, monitoring pays for itself with the first case it prevents.

A person appointed in advance with the authority to stop systems. That is a management question, not a technical one, and it must be settled before connection. Without it every night-time alarm ends in waiting for morning.

Let us discuss monitoring

Write what is critical for you and what an hour of downtime costs. We will say honestly whether monitoring is needed or the basics come first.