Emergency incident response: [email protected]

SIEM & SOC

Built a SOC supporting 900 enterprises.
Now we help you decide on yours.

The principals of GRC & Security established, operated and grew a Security Operations Centre to 900 enterprise customers until its acquisition. That experience now goes into advising organizations on what to log, which SIEM to run, how to staff or source a SOC, and how to build AI into SOC procedures so that analysts spend their time on the events that need judgement.

Logging requirements and central log management

Most logging gaps surface during an incident or an audit, when it is too late to collect what was missed. We help you work out which systems must log, what each must record, how long records must be kept and who needs access to them. We then design central log management around a central log facility (CLF) that collects from every source your standards and investigations depend on.

SIEM options, needs and alignment

A SIEM is only as useful as the requirements it was chosen against. We define yours before any product is considered: data volumes, retention, detection coverage, reporting obligations, integration with the tools you already run and the people who will operate it. We then assess the options, including what you already own, and align the chosen platform to those requirements. As with our GRC and security software procurement work, our advice on tool selection is vendor-neutral.

SOC strategy

Whether to build a SOC, fix the one you have, bring it in-house or hand it to a provider is a decision about cost, staffing, coverage and control. We set the options against your requirements and help you choose.

  • Establish

    Scope, staffing, tooling, processes and metrics for a new SOC.

  • Improve

    Review detection coverage, escalation paths, shift model and reporting in an existing SOC.

  • Internalize

    Plan the transition from an outsourced service to your own team.

  • Outsource

    Define the service you need, evaluate candidate partners and set the terms that you will hold them to.

AI in SOC operations

If you run your own SOC, the volume of logs and alerts is the constraint that drives everything else, and most of that volume is routine. AI can take on much of it: normalizing and enriching logs as they are ingested, grouping related alerts, suppressing known noise, scoring what remains and drafting the first assessment of an event so that an analyst starts from a summary instead of raw records. Done well, this leaves analysts with the events that need judgement and more time to spend on them. Done carelessly, it suppresses what it should have escalated, and nobody notices until the incident review. We help you design the pipeline, determine which decisions AI may make alone and which require an analyst, and put the oversight, testing and records in place so that you can show how automated triage behaves and correct it when it drifts. It is the same governance discipline we apply to AI anywhere else in an organization.

Contact us

Talk to us about where your logging, SIEM or SOC stands today.