Network, logging and monitoring

Does the Applicant have a Security Operations Center (SOC) monitored 24/7?

Ransomware is deployed at three in the morning on a Sunday for a reason. This question asks whether anyone is watching then.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether security alerts are monitored around the clock, in-house or through a provider. It is asking about coverage hours and about the ability to respond, not only to observe.

Why it is underwritten

Attackers deliberately act outside business hours because the gap between detection and response is longest then. An alert raised at two on Saturday morning and read on Monday has bought nothing. Carriers price the response window because it determines how much of the estate is affected.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Monitoring arrangements are contractual and procedural, so this is attested. The telemetry that feeds them is measurable.

PlatformWhere the setting livesWhat has to be true
Provider contractCoverage hours, response service levels, and escalation pathGenuine round-the-clock coverage with a defined response time. Attested
Provider scopeWhich sources the provider monitorsIdentity, endpoint, and cloud control plane, not endpoint alone, which is a common and narrow scope
AuthorityWhat the provider can do without waiting for youAbility to isolate a device or disable an account, since observation without authority delays containment
AzureAlert routing configuration and severity thresholdsHigh-severity alerts routed to the monitored destination rather than staying in the portal
TestingWhether the escalation path has been exercisedA test alert followed through to a human response, with the elapsed time recorded
Check what the provider actually watches

Many managed detection contracts cover endpoint telemetry only. Identity-plane attacks, which is how most cloud intrusions begin, produce no endpoint alert at all. Confirming the source coverage is more important than the coverage hours.

What a defensible yes requires

  • Coverage is genuinely continuous, whether in-house or outsourced.
  • The monitored sources include identity and cloud control plane, not only endpoints.
  • The provider has authority to contain, or your escalation path reaches someone who does within minutes.
  • Response service levels are contractual and measured.
  • The escalation path has been tested end to end.

How this answer goes wrong

The contract says round-the-clock and covers endpoint alerts only, so an identity-plane intrusion produces nothing to escalate. Or coverage is real and the escalation path ends at an on-call phone that nobody has answered in eighteen months because it has never been tested.

Frequently asked

Do we need our own security operations centre?

No. An outsourced managed detection service is a normal and accepted answer for organisations of most sizes.

What if we only cover business hours?

Say so accurately. It is a common position and it affects how the carrier views your detection window. Overstating it is the thing to avoid.

What sources should be monitored?

Identity first, then endpoint, then cloud control plane, then network. Identity is where cloud intrusions start and where endpoint-only monitoring is blind.

How do we evidence response times?

Provider reporting on alert-to-response times, plus a test escalation with a recorded outcome.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture