SOC Services

    SOC Monitoring & Response SLA

    This SLA applies to customers who have purchased SOC monitoring, MDR, or 24/7 monitoring services from CyberOM.

    Applicability

    This SLA applies only to customers who have purchased SOC/MDR/24/7 Monitoring services. For general support SLA, see Service Delivery & Support SLA.

    What SOC Monitoring Includes

    • 24/7 monitoring of covered endpoints and signals
    • Alert triage and severity classification
    • Initial investigation and context enrichment
    • Escalation to customer contacts per severity
    • Containment recommendations and response coordination
    • Monthly reporting on detections and trends

    Severity Levels & Response Targets

    SeverityExample AlertsInitial ResponseEscalation Path
    Critical (P1)Active breach, ransomware execution, confirmed data exfiltration[INSERT TARGET]Immediate customer notification + containment recommendation
    High (P2)Suspicious lateral movement, credential compromise, malware detected[INSERT TARGET]Customer notified within response window + remediation guidance
    Medium (P3)Policy violations, suspicious user behavior, failed login patterns[INSERT TARGET]Ticket created + customer notified per schedule
    Low (P4)Informational alerts, routine detections, false positive tuning[INSERT TARGET]Logged + included in periodic reporting

    Note: Final SLA targets will be confirmed in the service agreement. Response times above are targets and may vary based on alert volume and complexity.

    What's Not Included (Exclusions)

    • ✕Deep forensic investigations beyond initial triage (available as add-on)
    • ✕Legal or regulatory notifications (customer responsibility)
    • ✕Recovery and remediation execution (guidance provided, execution by customer)
    • ✕Coverage of unmonitored assets or endpoints
    • ✕Third-party vendor incident coordination

    Customer Responsibilities

    • Provide and maintain accurate escalation contact list
    • Respond to critical/high severity notifications within agreed timeframes
    • Authorize recommended containment actions when requested
    • Maintain agent deployment and connectivity on covered endpoints
    • Notify CyberOM of major environment changes

    Incident Communications

    Critical/High Severity (P1/P2)

    Initial notification via phone/email to designated contacts. Follow-up updates provided at regular intervals until resolution or handover.

    Medium/Low Severity (P3/P4)

    Notification via ticket system or email. Included in weekly/monthly reporting.

    Post-Incident Review

    For significant incidents, CyberOM provides a summary report including timeline, actions taken, and recommendations.

    For general support, onboarding, and service delivery information:

    View Service Delivery & Support SLA →