Service · Cybersecurity

SOC monitoring

Events that look harmless on their own can tell the story of an attack once they are lined up. Think of an exporter in Gaziantep. On Monday morning the finance manager's account signs in from abroad. The same day a mailbox rule appears that forwards every message containing the word “bank” to an outside address. On Wednesday a European buyer receives an email announcing a new IBAN. Every clue lives in a separate system and log, and none triggers an alert by itself. Had someone seen them side by side, the account could have been locked before any money moved. That is the job of SOC monitoring. We collect identity, email, firewall, server and endpoint logs in one platform, look for suspicious patterns using detection logic adapted to how your company works, and have an analyst review each alert. When a threat is real, we carry out the steps you approved beforehand: locking an account, ending sessions, isolating a device. Few SMEs can justify an in-house security operations team, so we deliver this service fully remotely.

One log store
cloud, network, server and endpoint data together
Detections
adapted to your normal activity
Playbook
approved by you in advance
Retention
sufficient for forensic work

What the work covers in practice

Log sources differ in value. The richest ones come first; more are added gradually.

Agree the scope with the engineer who will do the work

Onboarding sources

Identity and mail (Entra ID with Microsoft 365, or Google Workspace), the firewall and VPN gateway, domain controllers, critical servers and EDR. Website and e-commerce logs can be added when relevant.

Detection logic

Logic for familiar attacker behaviour: impossible travel between sign-ins, newly created forwarding rules, accounts added to admin groups, mass deletion or encryption of files, VPN sessions at odd hours.

Alert triage

An analyst checks every alert: false positive, harmless exception or genuine incident. Only what really matters reaches you, in writing, so you are not buried in noise.

Response

Pre-approved actions such as locking an account, ending sessions, resetting a password, isolating a device or blocking an IP address. The actions we can take on our own authority are listed in writing.

Incident handling

When things turn serious: containing the damage, securing evidence, cleaning up and restoring service. If personal data is affected, we assemble the technical facts your legal adviser needs to decide on KVKK notification.

Reporting

Each month, a plain-language summary of alerts, incidents, patterns and advice, and a short video review each quarter.

How we approach the job, from first call to handover

Expect a settling-in period of several weeks, after which raw noise has been shaped into dependable early warnings.

01

Planning

We fix the log sources, coverage hours, named contacts and pre-approved actions in a short working document.

02

Connection

Log forwarding is set up, completeness is verified and the first rules go live.

03

Learning period

A tuning stretch of two to four weeks that teaches the platform your normal patterns, filters out noisy alerts and adds the exceptions you need.

04

Steady state

Continuous monitoring, playbook-driven response, monthly reporting and a quarterly rule review.

Intruders rarely strike the moment they get in. They often wait days or weeks, mapping accounts, hunting for backups and choosing their moment. That dwell time is the defender's best opportunity. A SOC is not there to guard the front door, but to make sure nobody wanders around inside unnoticed.

Frequently asked questions

The standard scope covers Monday to Friday, 09:00-18:00 Turkey time. Automated rules keep running outside those hours, so a device showing signs of ransomware is isolated automatically. Continuous human monitoring is added to the contract through the Premium plan or the 24/7 support service.

On a platform running in EU data centres. Since log entries include personal data, this is a transfer abroad under KVKK: it should appear in your privacy notice and inventory, and your lawyer should assess the legal basis. We agree the retention period with you based on your needs and legal requirements.

The law and sector rules set expectations around detecting, recording and reporting incidents, with more detail for critical infrastructure operators. SOC monitoring covers a technical part of those expectations and produces the information needed for reports to USOM or a sector SOME. It is not a compliance guarantee on its own.

EDR only sees devices. Mailbox rules, cloud sign-ins, VPN sessions and firewall logs are outside its view. An IBAN fraud like the one described above can happen without malware ever running on a device. A SOC brings those separate sources together.

Catch the attack before it does damage

Tell us which platforms, firewall and EDR you use. We will say which sources make sense to start with.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.