SOC Monitoring & Response SLA
This SLA applies to customers who have purchased SOC monitoring, MDR, or 24/7 monitoring services from CyberOM.
Applicability
This SLA applies only to customers who have purchased SOC/MDR/24/7 Monitoring services. For general support SLA, see Service Delivery & Support SLA.
What SOC Monitoring Includes
- 24/7 monitoring of covered endpoints and signals
- Alert triage and severity classification
- Initial investigation and context enrichment
- Escalation to customer contacts per severity
- Containment recommendations and response coordination
- Monthly reporting on detections and trends
Severity Levels & Response Targets
| Severity | Example Alerts | Initial Response | Escalation Path |
|---|---|---|---|
| Critical (P1) | Active breach, ransomware execution, confirmed data exfiltration | [INSERT TARGET] | Immediate customer notification + containment recommendation |
| High (P2) | Suspicious lateral movement, credential compromise, malware detected | [INSERT TARGET] | Customer notified within response window + remediation guidance |
| Medium (P3) | Policy violations, suspicious user behavior, failed login patterns | [INSERT TARGET] | Ticket created + customer notified per schedule |
| Low (P4) | Informational alerts, routine detections, false positive tuning | [INSERT TARGET] | Logged + included in periodic reporting |
Note: Final SLA targets will be confirmed in the service agreement. Response times above are targets and may vary based on alert volume and complexity.
What's Not Included (Exclusions)
- ✕Deep forensic investigations beyond initial triage (available as add-on)
- ✕Legal or regulatory notifications (customer responsibility)
- ✕Recovery and remediation execution (guidance provided, execution by customer)
- ✕Coverage of unmonitored assets or endpoints
- ✕Third-party vendor incident coordination
Customer Responsibilities
- Provide and maintain accurate escalation contact list
- Respond to critical/high severity notifications within agreed timeframes
- Authorize recommended containment actions when requested
- Maintain agent deployment and connectivity on covered endpoints
- Notify CyberOM of major environment changes
Incident Communications
Critical/High Severity (P1/P2)
Initial notification via phone/email to designated contacts. Follow-up updates provided at regular intervals until resolution or handover.
Medium/Low Severity (P3/P4)
Notification via ticket system or email. Included in weekly/monthly reporting.
Post-Incident Review
For significant incidents, CyberOM provides a summary report including timeline, actions taken, and recommendations.
For general support, onboarding, and service delivery information:
View Service Delivery & Support SLA →