Does the Applicant have a Security Operations Center (SOC) monitored 24/7?
Ransomware is deployed at three in the morning on a Sunday for a reason. This question asks whether anyone is watching then.
What the carrier is actually asking
The carrier is asking whether security alerts are monitored around the clock, in-house or through a provider. It is asking about coverage hours and about the ability to respond, not only to observe.
Why it is underwritten
Attackers deliberately act outside business hours because the gap between detection and response is longest then. An alert raised at two on Saturday morning and read on Monday has bought nothing. Carriers price the response window because it determines how much of the estate is affected.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Monitoring arrangements are contractual and procedural, so this is attested. The telemetry that feeds them is measurable.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Provider contract | Coverage hours, response service levels, and escalation path | Genuine round-the-clock coverage with a defined response time. Attested |
| Provider scope | Which sources the provider monitors | Identity, endpoint, and cloud control plane, not endpoint alone, which is a common and narrow scope |
| Authority | What the provider can do without waiting for you | Ability to isolate a device or disable an account, since observation without authority delays containment |
| Azure | Alert routing configuration and severity thresholds | High-severity alerts routed to the monitored destination rather than staying in the portal |
| Testing | Whether the escalation path has been exercised | A test alert followed through to a human response, with the elapsed time recorded |
Many managed detection contracts cover endpoint telemetry only. Identity-plane attacks, which is how most cloud intrusions begin, produce no endpoint alert at all. Confirming the source coverage is more important than the coverage hours.
What a defensible yes requires
- Coverage is genuinely continuous, whether in-house or outsourced.
- The monitored sources include identity and cloud control plane, not only endpoints.
- The provider has authority to contain, or your escalation path reaches someone who does within minutes.
- Response service levels are contractual and measured.
- The escalation path has been tested end to end.
How this answer goes wrong
The contract says round-the-clock and covers endpoint alerts only, so an identity-plane intrusion produces nothing to escalate. Or coverage is real and the escalation path ends at an on-call phone that nobody has answered in eighteen months because it has never been tested.
Frequently asked
Do we need our own security operations centre?
No. An outsourced managed detection service is a normal and accepted answer for organisations of most sizes.
What if we only cover business hours?
Say so accurately. It is a common position and it affects how the carrier views your detection window. Overstating it is the thing to avoid.
What sources should be monitored?
Identity first, then endpoint, then cloud control plane, then network. Identity is where cloud intrusions start and where endpoint-only monitoring is blind.
How do we evidence response times?
Provider reporting on alert-to-response times, plus a test escalation with a recorded outcome.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture