SOC status:Duty analyst on shift

UK Cyber Defence

Managed SOC · SOC365 · 24/7 · United Kingdom

Someone is alwayswatching. Someoneyou can name.

SOC365 is our managed security operations centre: our own platform, our own analysts, our own detection engineering, run from Duxford under ISO 27001 and ISO 9001 processes for organisations across the UK and Europe.

CREST SOCISO 27001 · ISO 9001Named duty analystPlatform built in-houseFrom £5 a device a month

01Why SOC365

Alerts are cheap. Judgement is what you are paying for.

Any tool can generate ten thousand alerts a day. SOC365 exists to turn telemetry into decisions: which signals are real, what the attacker is trying to do, and what to switch off first. It unifies cloud, endpoint, identity, network, OT and application telemetry with live threat intelligence and deception signals, and every alert you receive has been looked at by an analyst who can explain it.

Detect
Behavioural analytics · Engineered detections · Deception · Threat intelligence
Validate
Human triage before you are paged
Respond
Isolation, locking, blocking — with your approval, or pre-authorised
Report
Monthly review · Board pack · Audit evidence
Governance
ISO 27001 and ISO 9001 certified processes · CREST-accredited responders

Core capabilities

What is included

01

24/7 monitoring and triage

Always-on behavioural analytics, correlation and enrichment across endpoint, identity, cloud, network, OT and applications, validated by senior analysts before escalation.

02

Detection engineering

A structured detection lifecycle aligned with MITRE ATT&CK, built around your threat model and regulatory obligations, and reviewed every month.

03

Threat intelligence fusion

Correlation against our own holdings: dark-web monitoring, phishing domain feeds, adversary infrastructure tracking, credential leaks and deception telemetry.

04

Proactive threat hunting

Hypothesis-driven and intelligence-led hunts that reveal early intrusion activity and cut attacker dwell time.

05

Incident response

Guided containment, evidence collection, forensic analysis and coordinated recovery using CREST-aligned methods, from the analysts who saw the alert first.

06

Active adversary disruption

Deception-driven alerts, infrastructure poisoning and Pulsar-assisted endpoint control to degrade an adversary's capability while you recover.

02

DeceptionDecoyPulse

Attackers cannot tell our decoys from your servers.

SOC365 places decoy hosts, services, file shares and admin portals inside your environment, plants credentials and tokens that only an intruder would ever use, and watches them. Nothing legitimate touches a decoy, so an alert from one is close to certain — and it can trigger Pulsar isolation, blocking or rate limiting before an analyst has finished reading it.

Decoys
Hosts · Services · File shares · Admin portals
Credentials
Planted accounts and tokens that expose spraying, replay and misuse
Devices
Docker-based appliances for IT, cloud and OT/ICS with no inbound exposure
Response
Automated containment through Pulsar where you pre-authorise it

03

EmilyAISOC assistant · since 2018

The assistant that never makes the decision.

EmilyAI is the SOC assistant we built in 2018 for periods of high alert volume and complex investigations. She extracts indicators, checks historical context, cross-references our intelligence holdings, drafts structured case notes and flags the low-value alerts worth tuning out. She runs entirely inside our own environment, sees only the metadata an analyst gives her, cannot take containment actions and never operates without an analyst directing her. The analysts stay in charge; they just get more of their day back.

Does
Triage assistance · TI correlation · Case notes · Noise reduction
Does not
Contain, change client systems, deploy detections or act unsupervised
Where
Internal only — never a public tool, never raw client data
Assurance
Logged, attributable, human-in-the-loop, change-controlled

Operations

How an incident flows through SOC365

  1. Stage 01

    Detection

    Behavioural anomalies, threat-intelligence matches, deception triggers or engineered detections fire within SOC365.

  2. Stage 02

    Triage and enrichment

    Analysts validate the signal, collect context, correlate indicators and suppress false positives.

  3. Stage 03

    Investigation

    Root-cause analysis, lateral-movement tracing, evidence gathering and mapping of the attacker's objectives.

  4. Stage 04

    Containment

    Pulsar agent actions, identity locking, network isolation and protective changes, executed with your approval or under pre-agreed authority.

  5. Stage 05

    Recovery and eradication

    Guided remediation, configuration hardening and validation that the attacker's access is gone.

  6. Stage 06

    Reporting

    Clear, executive-ready reporting of cause, actions taken and what to change next.

Behind the scenes

The technology behind the service

01

Unified telemetry

Cloud, endpoint, network, identity, OT and application logs ingested and normalised for consistent analysis.

02

Behavioural analytics

Detection of anomalous actions, privilege misuse, lateral movement and early-stage intrusion activity.

03

Threat intelligence engine

Continuous correlation against phishing feeds, dark-web datasets, leak indexing and adversary infrastructure tracking.

04

DecoyPulse deception network

High-confidence alerts from adversaries touching synthetic assets, credentials and network paths.

05

Pulsar endpoint control

Remote quarantine, process termination, file removal, outbound blocking and evidence capture for rapid containment.

06

SOC365 portal

Real-time visibility, incident tracking, service metrics and downloadable forensic and compliance reports.

Intelligence holdings feeding SOC365

26m

Malicious IP addresses

620k

Malicious domains

4m+

Indicator hashes

2.6bn

Leaked account records

4.5m

Dark-web sites indexed

547k

Phishing domains

  1. Malicious IP addresses, Malicious domains, Indicator hashes, Leaked account records, Dark-web sites indexed, Phishing domains: UK Cyber Defence threat intelligence holdings

Onboarding

Live in weeks, not quarters

  1. Stage 01

    Discovery

    Architecture, risks, regulatory obligations and the operational constraints nobody wrote down.

  2. Stage 02

    Integration

    Telemetry sources connected, Pulsar deployed, ingestion quality validated.

  3. Stage 03

    Detection tuning

    Use cases, MITRE mappings and environment-specific playbooks built for you.

  4. Stage 04

    Go-live

    Full shift coverage begins, with immediate monitoring, triage and response.

  5. Stage 05

    Continuous improvement

    Monthly service reviews and exposure analysis mature your posture from there.

Regulated sectors

Built for environments where downtime has consequences

  1. _01Frameworks we align toISO 27001, NIST CSF, DORA, NIS2, HIPAA, FCA guidance and the maritime ISPS code, with sector-specific frameworks on request.Compliance
  2. _02Financial servicesEvidence for FCA operational resilience and DORA ICT risk management expectations.FCA · DORA
  3. _03Healthcare and life sciencesClinical systems, patient data and medical devices monitored without disrupting care.Safety
  4. _04Maritime, energy and OTVessel, port and industrial environments watched with deception devices that need no inbound exposure.OT/ICS
  5. _05Legal, government and SaaSConfidentiality, citizen data and multi-tenant platforms, with reporting written for auditors.Assurance

Estimate

What SOC365 would cost you

SOC365 is priced per device per month, and the rate falls as the number of devices rises. Enter roughly how many devices you would want watched and the estimate builds; a short discovery confirms the count and turns it into a fixed monthly price.

Count the workstations, laptops, servers and virtual machines you want watched. We confirm the number at discovery.

Rate by device count

  1. 10 to 50 devices£12 per device a month
  2. 51 to 150 devicesyour band£10 per device a month
  3. 151 to 500 devices£8 per device a month
  4. 501 to 1,500 devices£6 per device a month
  5. 1,501+ devices£5 per device a month

Add to the estate

Entra ID, Duo, Okta or similar: sign-ins, MFA events, risky-user signals and privilege changes watched alongside the endpoints.

£100 a month

Microsoft 365 or Google Workspace: mailbox rules, sharing, admin activity and the audit log that most intrusions now touch first.

£250 a month

Perimeter and internal firewalls, IPS and IDS appliances, with their logs correlated against the rest of the estate.

£100 each a month

One decoy on your external network and one inside it. Nothing legitimate touches them, so an alert from either is close to certain.

£250 a month

Incident response retainers

Contract-backed help, before you need it

SOC365 is priced per device per month — between £5 and £12 + VAT a device, depending on how many we monitor; the estimate above shows how it adds up. If you are not a SOC365 client, an Incident Response Retainer gives you guaranteed response times, pre-agreed terms and a block of hours with our Disrupt team, so the worst day is not also the day you negotiate a contract.

Essentials

£2,500per year

For smaller organisations or those beginning their incident-readiness journey.

  • 10 incident response hours
  • P1 response within 8 hours · P2 within 24 hours
  • 24/7 emergency contact routes
  • Pre-authorised onboarding and NDAs
  • Limited forensic acquisition and analysis support

Standard

Recommended

£7,500per year

The option most organisations choose.

  • 30 incident response hours
  • P1 response within 4 hours · P2 within 12 hours
  • Priority access to Disrupt team specialists
  • Proactive onboarding workshop
  • Annual tabletop exercise
  • Standard forensic support · light SOC365 and intelligence integration

Enhanced

from £15,000per year

For regulated, multi-site or high-risk organisations, including group and MSSP arrangements.

  • 60+ incident response hours
  • P1 response within 2 hours · P2 within 4 hours
  • Quarterly readiness reviews
  • Two tabletop exercises a year
  • Extended forensics support
  • Custom escalation paths and communications plans
  • Full SOC365 and threat intelligence integration

Prices exclude VAT. Retainer hours can be used for triage, containment, investigation, forensics, recovery guidance and post-incident work, including tabletop exercises and readiness reviews. Retainers can be tailored for regulated or multi-entity organisations.

Questions

What boards and IT managers ask us

What does SOC365 cost?

Between £5 and £12 + VAT per device per month, depending on the number of devices we monitor: the more there are, the lower the rate. A short discovery confirms the device count and the price before anything is signed.

Do we need to replace our existing tools?

Rarely. SOC365 ingests telemetry from most EDR, identity and cloud platforms. Where a tool is missing, our own endpoint agent, Pulsar, fills the gap.

What happens at 3 a.m.?

The same thing that happens at 3 p.m. An analyst validates the alert, contains what you have pre-authorised us to contain, and calls the person on your escalation list for anything else.

How do you report to the board?

Monthly: what we saw, what we did, what changed in your exposure, and what we recommend. Written for people who do not want to read a SIEM dashboard, with the evidence attached for those who do.

Can you help with DORA, NIS2 or the FCA?

Yes. SOC365 produces the monitoring, detection and incident evidence those regimes expect, and our consulting team runs the gap assessments and exercises around it.

Can we call you during an incident without a retainer?

Yes, and we will always do our best to help. Response times, priority and commercial terms are far clearer and faster with a retainer agreed in advance.

What if an incident uses more than our retainer hours?

We keep going at pre-agreed overage rates, then review the retainer level with you afterwards so it matches your actual risk.

Do you work with insurers and regulators?

Yes. Our reporting is written to be used directly with cyber insurers, regulators, auditors and legal counsel, and we can support notification and disclosure workflows.

How should we compare you with other providers?

Ask everyone the same questions and score the answers. We publish a free checklist of twenty questions to ask a SOC provider, with what a good answer looks like beside each one, and we are happy to be scored against it in the first meeting.

Start a conversation

See SOC365 handle a real attack.

A thirty-minute technical briefing with the SOC lead, using an anonymised incident from last month.