Response time needs a precise definition
Providers may measure time from alert creation, platform ingestion, analyst acknowledgement, investigation start or customer notification. Those are different milestones. A meaningful service description explains the starting event, severity level, coverage hours and exceptions.
What alert triage should accomplish
- Validate whether an alert represents suspicious or expected activity
- Add identity, endpoint, email, cloud and network context
- Assign a clear severity based on business impact
- Escalate confirmed or high-risk activity through agreed channels
- Document findings, recommended actions and response taken
Questions for a SOC-as-a-Service provider
- Is monitoring staffed 24/7 or only alert forwarding?
- Which events receive human investigation?
- How are critical, high, medium and low severity events defined?
- What are the acknowledgement, investigation and notification targets?
- Can analysts isolate endpoints, disable accounts or block indicators?
- How are false positives tuned and recurring issues reviewed?
- What reporting shows service performance and unresolved risk?
Small businesses need clear ownership
A small business may not have an internal security team available after hours. The contract should therefore make responsibilities explicit: what the provider investigates, what it can contain, who the customer calls and what happens when a primary contact does not answer.
Related: SOC monitoring, MDR vs SIEM vs SOC, and Managed SOC services.
Need guidance specific to your environment?
Start with a focused review of your current controls, monitoring coverage and response responsibilities.