{"id":35052,"date":"2026-09-24T16:23:19","date_gmt":"2026-09-24T14:23:19","guid":{"rendered":"https:\/\/sits.com\/?p=35052"},"modified":"2026-09-24T16:25:28","modified_gmt":"2026-09-24T14:25:28","slug":"managed-soc-services-guide","status":"publish","type":"post","link":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/","title":{"rendered":"Managed SOC Services: 24\/7 Security Monitoring, Detection and Response"},"content":{"rendered":"<section class=\"wpb-content-wrapper\"><p>[vc_row][vc_column]<h2  class=\"h2 smx-headline \">What are Managed SOC Services?<\/h2>[vc_column_text]<\/p>\n<p class=\"FirstParagraph\"><span lang=\"EN-US\">A <strong>Security Operations Center<\/strong> is the function responsible for detecting and responding to security incidents. It combines three things: <strong>telemetry<\/strong> (logs and alerts from your systems), <strong>detection logic<\/strong> (the rules deciding what counts as suspicious), and <strong>analysts<\/strong> who investigate and decide what happens next.<\/span><\/p>\n<p>A <strong>Managed SOC<\/strong> delivers that function as an external service, covering monitoring, triage, investigation, escalation and reporting. Depending on the agreement, the provider may also take containment actions in your environment.<\/p>\n<p>Two variants are common:<\/p>\n<ul>\n<li><strong>Fully Managed<\/strong>: the provider runs detection, investigation and escalation, and you act on what is escalated to you.<\/li>\n<li><strong>Co-Managed<\/strong>: responsibilities are shared. Your team may own alert handling, or specific technologies, while the provider covers the rest.<\/li>\n<\/ul>\n<p>The right model depends on how much internal expertise, operational responsibility and day-to-day involvement your organisation wants to retain. Some companies prefer to outsource security operations almost entirely, while others use a co-managed approach to combine external expertise with internal knowledge of their environment.<\/p>\n<p>Terminology varies. SOC-as-a-Service, managed detection and response and outsourced security operations often describe overlapping offerings with different scopes, so compare the contracted scope rather than the label.[\/vc_column_text]<div class=\"smx_global_spacer size-s\"><\/div>\n<h2  class=\"h2 smx-headline \">Why companies use Managed SOC Services<\/h2>[vc_column_text]<\/p>\n<p class=\"FirstParagraph\"><span lang=\"EN-US\">The drivers are consistently operational rather than theoretical:<\/span><\/p>\n<ul>\n<li><strong>No internal 24\/7 capacity.<\/strong> Continuous coverage takes several people per analyst shift, plus holiday and sickness cover. One role cannot deliver that.<\/li>\n<li><strong>Alert volume exceeds investigation capacity.<\/strong> Teams triage the loudest alerts rather than the most significant.<\/li>\n<li><strong><a href=\"https:\/\/sits.com\/en\/blog\/managed-services-to-counter-the-shortage-of-manpower\/\">Specialist hiring is slow and competitive<\/a>.<\/strong> Detection engineering and incident investigation are narrow skill sets, and retention costs real money.<\/li>\n<li><strong>More threat activity across a wider attack surface.<\/strong> Cloud, SaaS, remote endpoints and identity systems all generate telemetry that needs correlating, and all of it is targeted.<\/li>\n<li><strong>Compliance and reporting pressure.<\/strong> NIS2 and ISO 27001 expect demonstrable monitoring, incident handling and documentation, not just intent.<\/li>\n<li><strong>Cyber insurance expectations.<\/strong> Insurers increasingly ask specific questions about detection and response at renewal.<\/li>\n<li><strong>Detection and response speed.<\/strong> Mean time to detect (MTTD) and mean time to respond (MTTR) determine how much damage an incident does.<\/li>\n<\/ul>\n<p class=\"FirstParagraph\"><span lang=\"EN-US\">Compliance cuts both ways: collecting more logs<strong> improves audit evidence<\/strong> and <strong>increases alert volume<\/strong>. Without a triage function, better visibility makes the operational problem worse.<\/span><\/p>\n<p>[\/vc_column_text][\/vc_column][\/vc_row][vc_row custom_background_class=\"gradient-up\"][vc_column]<div class=\"smx_global_spacer size-s\"><\/div>\n<h2  class=\"h2 smx-headline \">How does a Managed SOC work?<\/h2>[vc_column_text]<\/p>\n<p class=\"FirstParagraph\"><span lang=\"EN-US\">The operational flow is consistent across mature providers:<\/span><\/p>\n<p><strong>1. Log and telemetry collection<\/strong><\/p>\n<p>Sources are connected to a <strong>Security Information and Event Management<\/strong> <strong>platform <\/strong>(<a href=\"https:\/\/sits.com\/en\/cyber-defense-center\/siem\/\"><strong>SIEM<\/strong><\/a>): identity systems, <a href=\"https:\/\/sits.com\/en\/cyber-defense-center\/mxdr\/\">endpoint detection and response (EDR) or extended detection and response (XDR)<\/a> agents, firewalls, cloud platforms, email security. What you connect determines what can be detected, so it deserves more attention than it usually gets. The protocols and data sources required by a managed SOC depend on the existing infrastructure, the relevant risks, and the desired detection use cases.<\/p>\n<p><strong>2. Detection rules and use cases<\/strong><\/p>\n<p>Detection logic is configured for your environment and tuned over time. Untuned detections are the main source of false positives.<\/p>\n<p><strong>3. Alert triage<\/strong><\/p>\n<p><strong>Alerts are prioritized as they arrive<\/strong>. Many managed SOC providers use automation, machine learning or AI-assisted workflows to handle repetitive tasks and help identify known patterns more efficiently. This reduces time spent on routine alerts and allows analysts to focus on the incidents that require deeper investigation.The goal is not to replace analysis, but to keep analyst time focused on the incidents that actually need it.<\/p>\n<p><strong>4. Analyst investigation<\/strong><\/p>\n<p>Analysts work on the alerts produced by the connected services: SIEM, EDR\/XDR and, if the customer has them in place, <a href=\"https:\/\/sits.com\/en\/cyber-defense-center\/cyber-threat-intelligence\/\">threat intelligence<\/a> and phishing reporting. <strong>Most incidents<\/strong> are straightforward and are <strong>closed within around five minutes<\/strong>, once the artefacts and indicators of compromise (IoCs) have been reviewed and the sequence of events has been reconstructed. The minority that are <strong>ambiguous<\/strong> or point to a <strong>real compromise<\/strong> <strong>get the necessary time<\/strong>.<\/p>\n<p>Analysts widen the investigation around the event, correlate related activity before and after, and add external context before deciding what to escalate. If an incident develops into a confirmed compromise, the case is typically escalated to a dedicated Incident Response (IR) team for containment, forensic investigation and recovery activities.<\/p>\n<p><strong>5. Threat intelligence enrichment<\/strong><\/p>\n<p>Intelligence adds context on the actor, tooling or infrastructure involved in an alert. Anything deeper sits in separate services rather than in the SOC baseline: Cyber Threat Intelligence for dark web monitoring, attack surface management, brand protection and <a href=\"https:\/\/sits.com\/en\/blog\/nis2-dora-supply-chain\/\">supply chain risk<\/a>, and <a href=\"https:\/\/sits.com\/en\/cyber-defense-center\/threat-exposure-management\/\">Continuous Threat Exposure Management<\/a> for vulnerability and attack path analysis. CTI findings are raised as incidents and handled by the same SOC.<\/p>\n<p><strong>6. Escalation to the customer<\/strong><\/p>\n<p>Confirmed incidents go to your ticket system or email distribution list, with critical incidents also phoned through. False positives are closed, or the detection rules are adjusted accordingly, rather than being forwarded to you.<\/p>\n<p><strong>7. Response support<\/strong><\/p>\n<p>Where <strong>Active Responder<\/strong> is enabled, the <strong>SOC executes containment actions<\/strong> directly:<\/p>\n<ul>\n<li>isolating an endpoint<\/li>\n<li>revoking a session<\/li>\n<li>resetting a password<\/li>\n<li>blacklisting an IoC<\/li>\n<\/ul>\n<p><strong>8. Reporting and continuous improvement<\/strong><\/p>\n<p>Detections are tuned based on outcomes. Most managed SOC providers offer regular reporting, dashboards and service reviews to communicate security outcomes and improvement opportunities.[\/vc_column_text][\/vc_column][\/vc_row][vc_row custom_background_class=\"gradient-down\"][vc_column]<div class=\"smx_global_spacer size-s\"><\/div>\n<h3  class=\"h3 smx-headline \">From detection to containment: a practical Managed SOC use case<\/h3>[vc_column_text]Detections span identity, endpoint, network and cloud: suspicious sign-ins, impossible travel, privilege escalation, unusual data transfers, malicious processes. Here is one that shows <strong>why coverage hours and response rights matter<\/strong>.<\/p>\n<p>At 02:40, an EDR agent flags a process on a finance workstation attempting to delete volume shadow copies, a step attackers take before deploying ransomware so files cannot be restored locally.<\/p>\n<p>An analyst confirms it is not a scheduled backup job and prioritizes it. The investigation widens: which account launched the process, how it reached the machine, whether the same behavior appears elsewhere. Because Active Responder is enabled, the SOC isolates the workstation and blocks the associated indicator across the estate, then phones the on-call contact and files a critical incident. By the time the customer\u2019s team starts work, the host is contained and they have specific remediation steps. Rebuilding the machine, verifying backups and deciding on wider action remain their calls.<\/p>\n<p>Most alerts look nothing like this. The majority resolve as benign and get tuned out, which is what keeps the queue small enough for a 02:40 case to get proper attention.[\/vc_column_text]<div class=\"smx_global_spacer size-s\"><\/div>\n[\/vc_column][\/vc_row][vc_row][vc_column]<h2  class=\"h2 smx-headline \">How different security services work together<\/h2>[vc_column_text]<\/p>\n<p class=\"FirstParagraph\"><span lang=\"EN-US\">SOC-as-a-Service is typically built around <a href=\"https:\/\/sits.com\/en\/cyber-defense-center\/siem\/\">SIEM<\/a> and <a href=\"https:\/\/sits.com\/en\/cyber-defense-center\/mxdr\/\">EDR\/XDR<\/a> telemetry, where most detection activity takes place. In mature security operations, related functions such as threat intelligence, phishing analysis and incident response are not treated as isolated activities. Instead, they feed into the same investigation workflows, allowing security teams to correlate information across different sources and respond more effectively to potential threats Bringing these capabilities together helps reduce operational silos, improves visibility and creates a more consistent process for detection, investigation and response.<\/span><\/p>\n<ul>\n<li><strong>Phish Analytics, <\/strong>part of Phishing-as-a-Service, routes user-reported emails to the SOC, where they are analyzed, categorized and assessed for criticality on the same severity model as any other incident. The reporting user is told the outcome.<\/li>\n<li><strong><a href=\"https:\/\/sits.com\/en\/cyber-defense-center\/cyber-threat-intelligence\/\">Cyber Threat Intelligence<\/a><\/strong>\u00a0findings<strong>, <\/strong>such as leaked credentials or a newly exposed external asset, are raised as incidents, reviewed by SOC analysts and enriched before they reach you. CTI sits on top of the SOC agreement and follows the same SLA structure.<\/li>\n<li><a href=\"https:\/\/sits.com\/en\/cyber-defense-center\/csirt\/\"><strong>Incident Response<\/strong><\/a> picks up where the SOC hands over, with triage and evidence collection already completed.<\/li>\n<\/ul>\n<p>The benefit is <strong>consolidation<\/strong>: one severity model and one SLA structure instead of several, signals from different sources that can be correlated, a single reporting view in CDC Insights, and one escalation path for your team to learn rather than a console per service.<\/p>\n<p>If you only ever buy monitoring, this matters less. If you expect to add capabilities, it decides whether that means more vendors and consoles, or more coverage inside the same operation.[\/vc_column_text]<div class=\"smx_global_spacer size-s\"><\/div>\n<h2  class=\"h2 smx-headline \">What is included in Managed SOC Services?<\/h2>[vc_column_text]Core components you should expect:<\/p>\n<ul>\n<li>24\/7 or business-hours security monitoring<\/li>\n<li>Threat detection and detection use-case management<\/li>\n<li>Alert triage and prioritization<\/li>\n<li>Incident investigation and documentation<\/li>\n<li>Defined escalation workflows with severity levels<\/li>\n<li>Ongoing tuning and false-positive reduction<\/li>\n<li>Threat intelligence enrichment<\/li>\n<li>Technical and management reporting<\/li>\n<li>Actionable recommendations per incident<\/li>\n<li>Platform management for the SIEM and EDR\/XDR (depending on package)<\/li>\n<\/ul>\n<p>[\/vc_column_text][vc_column_text]<\/p>\n<p class=\"FirstParagraph\"><span lang=\"EN-US\">Commonly optional or add-on:<\/span><\/p>\n<ul>\n<li>Active response actions in your environment (Active Responder)<\/li>\n<li>Incident Response retainer and on-site forensics<\/li>\n<li>Cyber Threat Intelligence<\/li>\n<li>Continuous Threat Exposure Management (attack path simulation)<\/li>\n<li>Phishing analysis (Phish Analytics), phishing simulation and awareness training<\/li>\n<\/ul>\n<p class=\"FirstParagraph\">Managed SOC providers typically offer multiple service tiers, often varying by monitoring hours, analyst involvement and response capabilities.<\/p>\n<p>[\/vc_column_text]<div class=\"smx_global_spacer size-s\"><\/div>\n[\/vc_column][\/vc_row][vc_row][vc_column]<h2  class=\"h2 smx-headline \">Managed SOC vs MDR vs MSSP vs Managed SIEM<\/h2>[vc_column_text]These terms are often used interchangeably, but they describe different levels of security operations, monitoring and response. A Managed SOC provides a complete security operations function, while MDR focuses primarily on threat detection and response. MSSP offerings are typically centered on managing security technologies such as firewalls and gateways, whereas Managed SIEM services focus on operating and maintaining the SIEM platform itself. Although these services overlap in some areas, they differ significantly in scope, analyst involvement, response capabilities and technology ownership. The comparison below highlights the key distinctions and typical use cases for each model.<br \/>\nUnderstanding these differences helps organizations choose the model that best matches their internal capabilities, response requirements and security objectives.[\/vc_column_text][vc_raw_html]JTNDc3R5bGUlM0UlMjAlMEElMjAlMjB0YWJsZS50aHJlYXQtaW5mby10YWJsZSUyMCU3QiUwQSUyMCUyMCUyMCUyMGJvcmRlci1jb2xsYXBzZSUzQSUyMGNvbGxhcHNlJTNCJTBBJTIwJTIwJTIwJTIwd2lkdGglM0ElMjAxMDAlMjUlM0IlMEElMjAlMjAlMjAlMjBmb250LWZhbWlseSUzQSUyMHNhbnMtc2VyaWYlM0IlMEElMjAlMjAlN0QlMEElMEElMjAlMjB0YWJsZS50aHJlYXQtaW5mby10YWJsZSUyMHRoJTJDJTBBJTIwJTIwdGFibGUudGhyZWF0LWluZm8tdGFibGUlMjB0ZCUyMCU3QiUwQSUyMCUyMCUyMCUyMGJvcmRlciUzQSUyMDJweCUyMHNvbGlkJTIwJTIzZmZmZmZmMzMlM0IlMEElMjAlMjAlMjAlMjBwYWRkaW5nJTNBJTIwMjBweCUzQiUwQSUyMCUyMCUyMCUyMGNvbG9yJTNBJTIwJTIzZmZmZmZmJTNCJTBBJTIwJTIwJTIwJTIwdmVydGljYWwtYWxpZ24lM0ElMjB0b3AlM0IlMEElMjAlMjAlN0QlMEElMEElMjAlMjB0YWJsZS50aHJlYXQtaW5mby10YWJsZSUyMHRoZWFkJTIwdGglMjAlN0IlMEElMjAlMjAlMjAlMjBiYWNrZ3JvdW5kLWNvbG9yJTNBJTIwJTIzZGVkYzAwJTNCJTBBJTIwJTIwJTIwJTIwY29sb3IlM0ElMjAlMjMwMDAwMDAlM0IlMEElMjAlMjAlMjAlMjBmb250LXdlaWdodCUzQSUyMGJvbGQlM0IlMEElMjAlMjAlMjAlMjB0ZXh0LWFsaWduJTNBJTIwbGVmdCUzQiUwQSUyMCUyMCU3RCUwQSUwQSUyMCUyMHRhYmxlLnRocmVhdC1pbmZvLXRhYmxlJTIwdGJvZHklMjB0ZCUyMCU3QiUwQSUyMCUyMCUyMCUyMGJhY2tncm91bmQtY29sb3IlM0ElMjAlMjMwYzJmNDglM0IlMEElMjAlMjAlN0QlMEElM0MlMkZzdHlsZSUzRSUwQSUwQSUzQ3RhYmxlJTIwY2xhc3MlM0QlMjJ0aHJlYXQtaW5mby10YWJsZSUyMiUzRSUwQSUyMCUyMCUzQ3RoZWFkJTNFJTBBJTIwJTIwJTIwJTIwJTNDdHIlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0aCUzRSUyMCUzQyUyRnRoJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGglM0VNYW5hZ2VkJTIwU09DJTNDJTJGdGglM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0aCUzRU1EUiUzQyUyRnRoJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGglM0VNU1NQJTNDJTJGdGglM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0aCUzRU1hbmFnZWQlMjBTSUVNJTNDJTJGdGglM0UlMEElMjAlMjAlMjAlMjAlM0MlMkZ0ciUzRSUwQSUyMCUyMCUzQyUyRnRoZWFkJTNFJTBBJTIwJTIwJTNDdGJvZHklM0UlMEElMjAlMjAlMjAlMjAlM0N0ciUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFUHJpbWFyeSUyMGZvY3VzJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRUZ1bGwlMjBzZWN1cml0eSUyMG9wZXJhdGlvbnMlMjBmdW5jdGlvbiUzQyUyRnRkJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VEZXRlY3Rpb24lMjBhbmQlMjByZXNwb25zZSUyQyUyMHVzdWFsbHklMjBlbmRwb2ludCUyMGFuZCUyMGlkZW50aXR5JTIwbGVkJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRU1hbmFnaW5nJTIwc2VjdXJpdHklMjBkZXZpY2VzJTIwYW5kJTIwc2VydmljZXMlM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFT3BlcmF0aW5nJTIwb25lJTIwcGxhdGZvcm0lM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUzQyUyRnRyJTNFJTBBJTIwJTIwJTIwJTIwJTNDdHIlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRUFuYWx5c3QlMjBpbnZlc3RpZ2F0aW9uJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRUNlbnRyYWwlMjB0byUyMHRoZSUyMHNlcnZpY2UlM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFQ2VudHJhbCUyMHRvJTIwdGhlJTIwc2VydmljZSUzQyUyRnRkJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VPZnRlbiUyMGxpbWl0ZWQlM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFTm90JTIwaW5jbHVkZWQlM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUzQyUyRnRyJTNFJTBBJTIwJTIwJTIwJTIwJTNDdHIlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRVJlc3BvbnNlJTIwaW52b2x2ZW1lbnQlM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFRXNjYWxhdGlvbiUyQyUyMHdpdGglMjBhY3RpdmUlMjBjb250YWlubWVudCUyMGFzJTIwYW4lMjBvcHRpb24lM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFVHlwaWNhbGx5JTIwY29yZSUyMHRvJTIwdGhlJTIwb2ZmZXJpbmclM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFUmFyZWx5JTIwaW5jbHVkZWQlM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFTm90JTIwaW5jbHVkZWQlM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUzQyUyRnRyJTNFJTBBJTIwJTIwJTIwJTIwJTNDdHIlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRVRlY2hub2xvZ3klM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFTXVsdGlwbGUlMjBTSUVNJTJDJTIwRURSJTIwYW5kJTIwWERSJTIwcGxhdGZvcm1zJTJDJTIwb2Z0ZW4lMjB5b3VycyUzQyUyRnRkJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VVc3VhbGx5JTIwdGhlJTIwdmVuZG9yJUUyJTgwJTk5cyUyMG93biUyMHBsYXRmb3JtJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRVZlbmRvci1zZWxlY3RlZCUyMGVzdGF0ZSUzQyUyRnRkJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VUaGUlMjBTSUVNJTIwb25seSUzQyUyRnRkJTNFJTBBJTIwJTIwJTIwJTIwJTNDJTJGdHIlM0UlMEElMjAlMjAlMjAlMjAlM0N0ciUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFQmVzdCUyMGZpdCUzQyUyRnRkJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VPcmdhbml6YXRpb25zJTIwd2FudGluZyUyMGFuJTIwb3BlcmF0aW9uYWwlMjBzZWN1cml0eSUyMGZ1bmN0aW9uJTIwd2l0aG91dCUyMGJ1aWxkaW5nJTIwb25lJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRVRlYW1zJTIwd2FudGluZyUyMGRldGVjdGlvbiUyMGFuZCUyMHJlc3BvbnNlJTIwZGVwdGglMjBvbiUyMGVuZHBvaW50cyUyMGFuZCUyMGlkZW50aXR5JTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRU9yZ2FuaXphdGlvbnMlMjBvdXRzb3VyY2luZyUyMGRldmljZSUyMG9wZXJhdGlvbnMlM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFT3JnYW5pemF0aW9ucyUyMHdpdGglMjBhJTIwU0lFTSUyMGJ1dCUyMG5vJTIwY2FwYWNpdHklMjB0byUyMHJ1biUyMGl0JTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlM0MlMkZ0ciUzRSUwQSUyMCUyMCUzQyUyRnRib2R5JTNFJTBBJTNDJTJGdGFibGUlM0U=[\/vc_raw_html]<div class=\"smx_global_spacer size-s\"><\/div>\n[\/vc_column][\/vc_row][vc_row custom_background_class=\"gradient-up\"][vc_column]<h2  class=\"h2 smx-headline \">When does a business need Managed SOC Services?<\/h2>[vc_column_text]The typical triggers:<\/p>\n<ul>\n<li>Nobody owns monitoring at nights, weekends or holidays.<\/li>\n<li>The IT or security team is consistently behind on alert investigation.<\/li>\n<li>The organization is growing internationally or by acquisition, adding environments faster than visibility.<\/li>\n<li>Infrastructure has become cloud, hybrid or distributed, and existing tooling gives a partial picture.<\/li>\n<li>Regulatory or contractual requirements have tightened.<\/li>\n<li>There has been a breach, a near miss, or an incident that took too long to understand.<\/li>\n<li>Leadership or the board wants security reporting the team cannot currently produce.<\/li>\n<\/ul>\n<p>If several of these points apply to your company, you may want to consider whether you need a <strong>24\/7 Security Operations Center <\/strong>to reliably detect and respond to security incidents even at night, on weekends and on holidays.[\/vc_column_text]<div class=\"smx_global_spacer size-s\"><\/div>\n<h2  class=\"h2 smx-headline \">Benefits of Managed SOC Services<\/h2>[vc_column_text]<\/p>\n<p class=\"FirstParagraph\"><b><span lang=\"EN-US\">Security outcomes<\/span><\/b><\/p>\n<ul>\n<li>Faster detection and response, measured through MTTD and MTTR<\/li>\n<li>Reduced alert fatigue, as false positives are closed or tuned out rather than forwarded<\/li>\n<li>Access to analysts who investigate incidents daily across many environments<\/li>\n<li>Better coordination when an incident escalates, particularly where SOC and Incident Response sit with the same provider, since triage and evidence collection are already done before the IR team engages<\/li>\n<\/ul>\n<p><strong>Business outcomes<\/strong><\/p>\n<ul>\n<li>Predictable operating cost instead of hiring, tooling and 24\/7 staffing investment<\/li>\n<li>Stronger compliance readiness through consistent logging, documentation and reporting<\/li>\n<li>Reporting your management team can actually use<\/li>\n<li>Internal specialists freed from alert queues for architecture, hardening and risk work<\/li>\n<\/ul>\n<p>In SOC-as-a-Service, the <a href=\"https:\/\/sits.com\/en\/digital-challenges\/our-cyber-defense-approach\/\">SITS Cyber Defense Center<\/a> reports that under <strong>10% of incidents require the customer to be involved<\/strong>. Across the full service, where phishing reports and cyber threat intelligence findings add a high volume of cases that are resolved without customer action, that figure falls to around <strong>3.5%<\/strong>. Read numbers like these as an <strong>indicator of triage quality<\/strong> rather than a guarantee: they depend heavily on your estate, your service mix and tuning maturity.[\/vc_column_text][\/vc_column][\/vc_row][vc_row custom_background_class=\"gradient-down\"][vc_column]<div class=\"smx_global_spacer size-s\"><\/div>\n<h3  class=\"h2 smx-headline \">Limitations and Considerations of a Managed SOC<\/h3>[vc_column_text]A Managed SOC is a detection and response capability. It is not complete protection, and it does not remove your security responsibilities. Outcomes depend on:<\/p>\n<ul>\n<li><strong>Onboarding quality:<\/strong>\u00a0Detection is only as good as the data connected and the use cases configured.<\/li>\n<li><strong>Relevant data sources:<\/strong>\u00a0A SOC cannot detect activity in systems it cannot see.<\/li>\n<li><strong>Clear responsibilities:<\/strong>\u00a0Ambiguity about who isolates a device, notifies whom and documents the incident costs time exactly when time matters.<\/li>\n<li><strong>Working escalation paths:<\/strong>\u00a0Contact lists go stale, and untested escalation fails under pressure.<\/li>\n<li><strong>Continuous tuning:<\/strong>\u00a0Environments change, so detections need maintenance.<\/li>\n<li><strong>Internal cooperation:<\/strong>\u00a0System owners need to be reachable for context and remediation.<\/li>\n<li><strong>Integration with incident response:<\/strong>\u00a0Detection and escalation are not the same as full incident handling, forensics and recovery.<\/li>\n<\/ul>\n<p>The <strong>fully managed model<\/strong> also carries a real trade-off: less day-to-day internal ownership of security operations. Some organizations accept that deliberately, others prefer a <strong>co-managed split<\/strong> to retain internal knowledge.[\/vc_column_text]<div class=\"smx_global_spacer size-s\"><\/div>\n[\/vc_column][\/vc_row][vc_row][vc_column]<h3  class=\"h2 smx-headline \">SOC responsibilities of providers and customers<\/h3>[vc_column_text]A successful Managed SOC operates as a partnership between the provider and the customer. While the <a href=\"https:\/\/sits.com\/en\/cyber-defense-center\/security-operations-center\/\">SOC handles monitoring, investigation and escalation<\/a>, customers remain responsible for remediation, governance and maintaining the operational information needed for effective response. Understanding these responsibilities upfront helps avoid delays during security incidents and ensures the service delivers maximum value.[\/vc_column_text][vc_raw_html]JTNDc3R5bGUlM0UlMjAlMEElMjAlMjB0YWJsZS50aHJlYXQtaW5mby10YWJsZSUyMCU3QiUwQSUyMCUyMCUyMCUyMGJvcmRlci1jb2xsYXBzZSUzQSUyMGNvbGxhcHNlJTNCJTBBJTIwJTIwJTIwJTIwd2lkdGglM0ElMjAxMDAlMjUlM0IlMEElMjAlMjAlMjAlMjBmb250LWZhbWlseSUzQSUyMHNhbnMtc2VyaWYlM0IlMEElMjAlMjAlN0QlMEElMEElMjAlMjB0YWJsZS50aHJlYXQtaW5mby10YWJsZSUyMHRoJTJDJTBBJTIwJTIwdGFibGUudGhyZWF0LWluZm8tdGFibGUlMjB0ZCUyMCU3QiUwQSUyMCUyMCUyMCUyMGJvcmRlciUzQSUyMDJweCUyMHNvbGlkJTIwJTIzZmZmZmZmMzMlM0IlMEElMjAlMjAlMjAlMjBwYWRkaW5nJTNBJTIwMjBweCUzQiUwQSUyMCUyMCUyMCUyMGNvbG9yJTNBJTIwJTIzZmZmZmZmJTNCJTBBJTIwJTIwJTIwJTIwdmVydGljYWwtYWxpZ24lM0ElMjB0b3AlM0IlMEElMjAlMjAlN0QlMEElMEElMjAlMjB0YWJsZS50aHJlYXQtaW5mby10YWJsZSUyMHRoZWFkJTIwdGglMjAlN0IlMEElMjAlMjAlMjAlMjBiYWNrZ3JvdW5kLWNvbG9yJTNBJTIwJTIzZGVkYzAwJTNCJTBBJTIwJTIwJTIwJTIwY29sb3IlM0ElMjAlMjMwMDAwMDAlM0IlMEElMjAlMjAlMjAlMjBmb250LXdlaWdodCUzQSUyMGJvbGQlM0IlMEElMjAlMjAlMjAlMjB0ZXh0LWFsaWduJTNBJTIwbGVmdCUzQiUwQSUyMCUyMCU3RCUwQSUwQSUyMCUyMHRhYmxlLnRocmVhdC1pbmZvLXRhYmxlJTIwdGJvZHklMjB0ZCUyMCU3QiUwQSUyMCUyMCUyMCUyMGJhY2tncm91bmQtY29sb3IlM0ElMjAlMjMwYzJmNDglM0IlMEElMjAlMjAlN0QlMEElM0MlMkZzdHlsZSUzRSUwQSUwQSUzQ3RhYmxlJTIwY2xhc3MlM0QlMjJ0aHJlYXQtaW5mby10YWJsZSUyMiUzRSUwQSUyMCUyMCUzQ3RoZWFkJTNFJTBBJTIwJTIwJTIwJTIwJTNDdHIlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0aCUzRUFyZWElM0MlMkZ0aCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RoJTNFTWFuYWdlZCUyMFNPQyUyMFByb3ZpZGVyJTNDJTJGdGglM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0aCUzRUN1c3RvbWVyJTNDJTJGdGglM0UlMEElMjAlMjAlMjAlMjAlM0MlMkZ0ciUzRSUwQSUyMCUyMCUzQyUyRnRoZWFkJTNFJTBBJTIwJTIwJTNDdGJvZHklM0UlMEElMjAlMjAlMjAlMjAlM0N0ciUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFTW9uaXRvcmluZyUyMGFuZCUyMGRldGVjdGlvbiUzQyUyRnRkJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VDb250aW51b3VzJTIwbW9uaXRvcmluZyUyQyUyMGRldGVjdGlvbiUyMHVzZSUyMGNhc2VzJTJDJTIwdHVuaW5nJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRUVuc3VyZSUyMGFncmVlZCUyMGxvZyUyMHNvdXJjZXMlMjBzdGF5JTIwY29ubmVjdGVkJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlM0MlMkZ0ciUzRSUwQSUyMCUyMCUyMCUyMCUzQ3RyJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VUcmlhZ2UlMjBhbmQlMjBpbnZlc3RpZ2F0aW9uJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRVRpZXJlZCUyMGFuYWx5c2lzJTJDJTIwc2V2ZXJpdHklMjBhc3Nlc3NtZW50JTJDJTIwZG9jdW1lbnRhdGlvbiUzQyUyRnRkJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VQcm92aWRlJTIwYnVzaW5lc3MlMjBjb250ZXh0JTIwd2hlbiUyMGFza2VkJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlM0MlMkZ0ciUzRSUwQSUyMCUyMCUyMCUyMCUzQ3RyJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VFc2NhbGF0aW9uJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRU5vdGlmeSUyMHBlciUyMHNldmVyaXR5JTJDJTIwcGhvbmUlMjBmb3IlMjBjcml0aWNhbCUyQyUyMGZvbGxvdyUyMHVwJTIwb24lMjBvcGVuJTIwaW5jaWRlbnRzJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRUtlZXAlMjBjb250YWN0JTIwYW5kJTIwdGlja2V0JTIwZGV0YWlscyUyMGN1cnJlbnQlM0IlMjB3aGl0ZWxpc3QlMjBTT0MlMjBlbWFpbCUzQiUyMHJlc3BvbmQlMjB3aXRoaW4lMjBhZ3JlZWQlMjB0aW1lZnJhbWVzJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlM0MlMkZ0ciUzRSUwQSUyMCUyMCUyMCUyMCUzQ3RyJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VBY3RpdmUlMjByZXNwb25zZSUzQyUyRnRkJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VFeGVjdXRlJTIwYWdyZWVkJTIwY29udGFpbm1lbnQlMjBhY3Rpb25zJTIwdmlhJTIwU09BUiUzQyUyRnRkJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VQcm92aWRlJTIwYW5kJTIwbWFpbnRhaW4lMjBBUEklMjBjcmVkZW50aWFscyUyMGFuZCUyMHBlcm1pc3Npb25zJTNCJTIwb3duJTIwdGhlJTIwZGVjaXNpb24lMjB0byUyMGdyYW50JTIwdGhlbSUzQyUyRnRkJTNFJTBBJTIwJTIwJTIwJTIwJTNDJTJGdHIlM0UlMEElMjAlMjAlMjAlMjAlM0N0ciUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFUmVtZWRpYXRpb24lM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFUmVjb21tZW5kJTIwc3BlY2lmaWMlMjBtaXRpZ2F0aW9uJTIwc3RlcHMlM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFSW1wbGVtZW50JTIwcmVtZWRpYXRpb24lMjBpbiUyMHRoZSUyMGVudmlyb25tZW50JTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlM0MlMkZ0ciUzRSUwQSUyMCUyMCUyMCUyMCUzQ3RyJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VSZXBvcnRpbmclM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUzQ3RkJTNFV2Vla2x5JTJGbW9udGhseSUyMHJlcG9ydHMlMkMlMjBwb3J0YWwlMjBzdGF0aXN0aWNzJTJDJTIwcXVhcnRlcmx5JTIwcmV2aWV3cyUzQyUyRnRkJTNFJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTNDdGQlM0VSZXZpZXclMjByZXBvcnRzJTIwYW5kJTIwYWN0JTIwb24lMjByZWNvbW1lbmRhdGlvbnMlM0MlMkZ0ZCUzRSUwQSUyMCUyMCUyMCUyMCUzQyUyRnRyJTNFJTBBJTIwJTIwJTIwJTIwJTNDdHIlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRUdvdmVybmFuY2UlMkMlMjBwb2xpY3klMkMlMjByaXNrJTIwb3duZXJzaGlwJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRUlucHV0JTIwYW5kJTIwYWR2aWNlJTNDJTJGdGQlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlM0N0ZCUzRVJldGFpbmVkJTIwaW50ZXJuYWxseSUzQyUyRnRkJTNFJTBBJTIwJTIwJTIwJTIwJTNDJTJGdHIlM0UlMEElMjAlMjAlM0MlMkZ0Ym9keSUzRSUwQSUzQyUyRnRhYmxlJTNF[\/vc_raw_html]<div class=\"smx_global_spacer size-s\"><\/div>\n[\/vc_column][\/vc_row][vc_row custom_background_class=\"gradient-up\"][vc_column]<h2  class=\"h2 smx-headline \">How to choose a Managed SOC provider<\/h2>[vc_column_text]A Managed SOC is more than a monitoring service. The quality of investigations, response processes, reporting and governance can significantly influence the security outcomes you achieve. When assessing potential providers, evaluate the following areas carefully:<\/p>\n<ul>\n<li><strong>Scope of service<\/strong>: what is included versus billed as an add-on<\/li>\n<li><strong>Analyst expertise<\/strong>: tier structure, certifications, escalation depth<\/li>\n<li><strong>Technology flexibility<\/strong>: whether they support your existing SIEM and EDR\/XDR or require their own<\/li>\n<li><strong>SLAs and escalation paths<\/strong>: severity definitions, notification windows, and when the clock starts<\/li>\n<li><strong>Reporting quality<\/strong>: technical, management and compliance-ready output<\/li>\n<li><strong>Compliance experience<\/strong>: relevant to your framework and sector<\/li>\n<li><strong>Geographic and language coverage<\/strong>: where analysts and data sit, and whether you can reach someone in your own language during an incident<\/li>\n<li><strong>Integration with existing tools<\/strong>: ticketing, identity, cloud, email<\/li>\n<li><strong>Incident response capability<\/strong>: whether IR is available and how it connects to the SOC<\/li>\n<li><strong>Transparency of responsibilities<\/strong>: a provider that cannot state clearly what stays with you is a risk<\/li>\n<\/ul>\n<p>On SLAs, press any provider on two details: whether the <strong>response clock<\/strong> starts when the case is received or when an analyst opens it, and whether the <strong>targets are averages or per-incident commitments<\/strong>. Providers structure service levels differently, with varying priorities, coverage models and response targets. Faster response times may also be offered as an additional service.<\/p>\n<p>Where security data lives deserve a specific question, and it is usually reduced to hosting location. <strong>Jurisdiction matters more than infrastructure<\/strong>: a server in Frankfurt operated by an entity subject to non-European law does not give you the control that the same workload under sole European jurisdiction does. Ask where the analysts who can see your data sit, which law governs access requests, and whether on-premises or EU private cloud deployment is genuinely available. Some providers also offer fully sovereign deployment models for organizations with strict security, compliance or data residency requirements.<\/p>\n<p>Technology stacks also vary between providers. Some support a broad range of SIEM, EDR and XDR platforms, while others standardize on a smaller set of technologies. Organizations should understand which platforms are supported, how data sources are integrated and whether existing security investments can be retained as part of the service.<\/p>\n<p>To select the right managed SOC provider, you should carefully evaluate its scope of services, technological flexibility and incident response capabilities. A Managed SOC RFP Checklist helps you systematically identify relevant requirements and better compare proposals. Equally important are clearly defined Managed SOC SLAs and a transparent understanding of pricing, so that response times, escalation procedures and potential additional costs are clear before signing the contract.[\/vc_column_text]<div class=\"smx_global_spacer size-s\"><\/div>\n<h2  class=\"h2 smx-headline \">Managed SOC Implementation: What to expect<\/h2>[vc_column_text]<\/p>\n<p class=\"FirstParagraph\"><span lang=\"EN-US\">Implementing a Managed SOC is typically a structured process that combines technical integration, operational planning and security tuning. The exact scope depends on the organization's environment and requirements, but the onboarding journey usually includes the following stages:<\/span><\/p>\n<ol>\n<li><strong>Discovery and scoping<\/strong>: environment, business priorities, risk profile, compliance drivers<\/li>\n<li><strong>Log source identification<\/strong>: which systems matter most, and in what order<\/li>\n<li><strong>Tool integration<\/strong>: connecting the SIEM, EDR\/XDR and other sources so events reach the SOC\u2019s SOAR platform<\/li>\n<li><strong>Detection use-case setup<\/strong>: configuring and correlating detections<\/li>\n<li><strong>Escalation path definition<\/strong>: contacts, severity mapping, communication channels<\/li>\n<li><strong>Playbook creation<\/strong>: agreed workflows for common scenarios such as phishing, ransomware and account compromise<\/li>\n<li><strong>Testing and tuning<\/strong>: baselining and reducing false positives<\/li>\n<li><strong>Reporting setup<\/strong>: dashboards, cadence, review meetings<\/li>\n<li><strong>Continuous improvement<\/strong>: ongoing tuning and quarterly reviews<\/li>\n<\/ol>\n<p>The onboarding time depends on how many sources are included and how quickly the necessary access is provided. For predefined use cases, technical implementation takes an average of four to six days. Full operational readiness is achieved within approximately two to three weeks.[\/vc_column_text][\/vc_column][\/vc_row][vc_row custom_background_class=\"gradient-down\"][vc_column]<div class=\"smx_global_spacer size-s\"><\/div>\n<h2  class=\"h2 smx-headline \">Managed-SOC Pricing: What factors influence the cost?<\/h2>[vc_column_text]<\/p>\n<p class=\"FirstParagraph\"><span lang=\"EN-US\">Cost is driven by scope and environment, not by a single list price. The main variables:<\/span><\/p>\n<ul>\n<li>Number of monitored assets, users and endpoints<\/li>\n<li>Number and type of log sources<\/li>\n<li>Log and data volume ingested<\/li>\n<li>Required service hours, whether business hours or 24\/7\/365<\/li>\n<li>Technology stack, and whether platform management is included<\/li>\n<li>Compliance and reporting requirements<\/li>\n<li><a href=\"https:\/\/sits.com\/en\/cyber-defense-center\/csirt\/\">Incident response<\/a>\u00a0scope, including whether a retainer is in place<\/li>\n<li>Level of customization in detections and playbooks<\/li>\n<li>Add-on services such as <a href=\"https:\/\/sits.com\/en\/cyber-defense-center\/cyber-threat-intelligence\/\">threat intelligence<\/a>, exposure management or phishing services<\/li>\n<\/ul>\n<p class=\"FirstParagraph\"><span lang=\"EN-US\">The most common budgeting mistake is comparing a managed service price against internal salary cost alone. A <strong>realistic internal comparison<\/strong> includes <strong>multiple analysts per shift<\/strong>, <strong>tooling licenses<\/strong> and <strong>maintenance, detection engineering, playbook development, incident documentation <\/strong>and <strong>audit support<\/strong>.<\/span><\/p>\n<p>As an illustration, 24\/7 SOC coverage typically starts around \u20ac3,700 to \u20ac7,500 per month for organizations up to 500 employees, \u20ac7,500 to \u20ac12,000 for 500 to 2,000 employees, and \u20ac12,000 and upward above that. Where you land inside a band depends on log sources, data volume, the technology in scope and the level of response included. Managed SOC Pricing sets out the full picture, including what sits inside the price and what is billed separately.[\/vc_column_text]<div class=\"smx_global_spacer size-s\"><\/div>\n<h2  class=\"h2 smx-headline \">Managed SOC Services and Compliance<\/h2>[vc_column_text]<\/p>\n<p class=\"FirstParagraph\"><span lang=\"EN-US\">Managed SOC Services support compliance work in five practical ways: <strong>continuous monitoring, consistent logging, documented incident detection and handling, traceable evidence, and regular reporting<\/strong>. In an audit, the useful output is not the claim that you monitor. It is documentation showing <strong>what was detected, when, what was done and by whom<\/strong>.<\/span><\/p>\n<p>To be clear about the boundary: A SOC produces evidence and capability. It does not grant certification, guarantee an audit outcome or by itself make an organization compliant. Governance, policies, risk management, training and management accountability stay with you.<\/p>\n<p>A managed SOC can support NIS2 readiness by enabling continuous monitoring, documented incident response processes, and traceable evidence. A managed SOC also contributes to consistent monitoring and documentation of security-related events in the context of ISO 27001. Managed SOC services may also be relevant for Cyber Insurance, as insurers increasingly require robust detection and response processes.[\/vc_column_text]<div class=\"smx_global_spacer size-s\"><\/div>\n[\/vc_column][\/vc_row][vc_row][vc_column]<h2  class=\"h2 smx-headline \">How SITS delivers Managed SOC services<\/h2>[vc_column_text]While the principles of a managed SOC are broadly similar across providers, the delivery model, technologies and level of operational support can vary significantly. SITS delivers Managed SOC Services through its <strong><a href=\"https:\/\/sits.com\/en\/cyber-defense-center\/\">Cyber Defense Center<\/a>, combining threat detection, investigation, response support and governance into a single service model<\/strong>.[\/vc_column_text]<h3  class=\"h3 smx-headline \">European SOC Operations<\/h3>[vc_column_text]The <a href=\"https:\/\/sits.com\/en\/digital-challenges\/our-cyber-defense-approach\/\">SITS Cyber Defense Center<\/a> is operated by a European company with <strong>SOC analysts located in Germany and Denmark<\/strong>. For organizations with strict sovereignty requirements, detection capabilities can be deployed either on-premises or within the <strong>SITS Secure Private Cloud<\/strong>.[\/vc_column_text]<h3  class=\"h3 smx-headline \">Supported Technology Platforms<\/h3>[vc_column_text]SITS primarily delivers services on IBM QRadar, Elastic Security and <a href=\"https:\/\/sits.com\/en\/microsoft-services\/threat-protection\/\">Microsoft Sentinel<\/a>. EDR\/XDR capabilities are supported through Elastic Defend and Microsoft Defender, while security operations are orchestrated through the in-house SOAR platform IntellAgent. Additional platforms can also be supported where organizations have existing technology investments or specific preferences.[\/vc_column_text]<h3  class=\"h3 smx-headline \">Active Response Capabilities<\/h3>[vc_column_text]Depending on the service package, SITS can support <strong>active response measures<\/strong> that help <strong>contain threats before they escalate with Active Responder<\/strong>. These actions may include endpoint isolation, session revocation, password resets and the blocking of malicious indicators across the environment[\/vc_column_text]<h3  class=\"h3 smx-headline \">Integration with Incident Response<\/h3>[vc_column_text]Managed SOC Services are closely integrated with the <a href=\"https:\/\/sits.com\/en\/cyber-defense-center\/csirt\/\">SITS Incident Response service<\/a>. If an incident <strong>outgrows the SOC<\/strong>, it is <strong>handed over to the Incident Response team<\/strong>, ensuring a seamless transition from detection and investigation to containment, forensic analysis and recovery support. This reduces handover effort and helps organizations respond more effectively during major security incidents.[\/vc_column_text]<h3  class=\"h3 smx-headline \">Reporting and Governance<\/h3>[vc_column_text]Effective SOC operations are not just about detecting threats. They also depend on <strong>clear reporting, transparent communication and well-defined escalation processes<\/strong> that ensure incidents are tracked through to resolution. Customers receive regular reporting, operational reviews and governance support to track security performance, identify trends and continuously improve detection and response processes.<\/p>\n<p>SITS offers Bronze, Silver and Gold service tiers to support different operational requirements. Bronze is designed for organizations that want a managed SIEM or EDR\/XDR platform while retaining responsibility for alert handling. Silver adds 8\/5 detection and response capabilities, while Gold extends coverage to 24\/7\/365.<\/p>\n<p><strong>Unanswered incidents will be followed up automatically<\/strong>: critical incidents every 8 hours, high-severity incidents every 24 hours, and medium-severity or informational incidents every 7 days. After three follow-ups, critical incidents are escalated internally at SITS, while lower-severity tickets are closed. That process relies on customer-side contacts being available and able to respond within agreed timeframes.<\/p>\n<p>Ultimately, the goal at SITS is not simply to deliver alerts, but to <strong>help organizations improve their security posture through better visibility, faster response and more informed decision-making<\/strong>.[\/vc_column_text]<div class=\"smx_global_spacer size-s\"><\/div>\n<h3  class=\"h3 smx-headline \">Which approach fits your security strategy?<\/h3>[vc_column_text]<\/p>\n<div>\n<p>Most companies aren't looking for a SOC. They're looking for greater transparency, faster response times and enhanced security.<\/p>\n<p>Together, we'll explore the best way to achieve this goal within your organization.<\/p>\n<\/div>\n<p>[\/vc_column_text]<div class=\"btn-wrapper \">\n    <div class=\"btn btn--inverted btn--green\">\n        <a href=\"https:\/\/sits.com\/en\/request-consultation\/\" class=\"btn-text\" title=\"Request a Managed SOC consultation\">\n            Request a Managed SOC consultation        <\/a>\n        <div><\/div>\n    <\/div> \n<\/div><div class=\"smx_global_spacer size-m\"><\/div>\n<div class=\"accordion_section\">\n    <div class=\"accordion_head\">\n        <div class=\"accordion_icon\">\n                    <\/div>\n        <h3 class=\"h3 smx-headline\">\n        Frequently Asked Questions about Managed SOC Services    <\/h3>\n    <div class=\"subheadline\">\n            <\/div>\n<\/div>\n<div class=\"accordion_wrapper\">\n                    <button class=\"accordion\">What is the difference between Managed SOC and MDR?<\/button>\n                <div class=\"panel\">\n                    <p>MDR (Managed Detection and Response) usually focuses on detection and response within the provider\u2019s own technology stack, often endpoint and identity-led. A Managed SOC covers a broader operations function across multiple data sources, including reporting, tuning and compliance support.<\/p>\n                <\/div>\n                            <button class=\"accordion\">Is SOC-as-a-Service the same as Managed SOC?<\/button>\n                <div class=\"panel\">\n                    <p>In practice the terms are used interchangeably, and SITS delivers its offering as SOC-as-a-Service. What differs between vendors is scope, so check whether response actions, platform management and incident response are included rather than trusting the label.<\/p>\n                <\/div>\n                            <button class=\"accordion\">What is included in Managed SOC Services?<\/button>\n                <div class=\"panel\">\n                    <p>At minimum: 24\/7 or business-hours monitoring, detection, triage, investigation, escalation, tuning and reporting. Active response, incident response, threat intelligence and exposure management are commonly add-ons. <\/p>\n                <\/div>\n                            <button class=\"accordion\">How much do Managed SOC Services cost?<\/button>\n                <div class=\"panel\">\n                    <p>Pricing depends on monitored assets, log volume, service hours, technology stack and level of response. Compare it against the full internal cost of 24\/7 coverage, meaning several analysts per shift, tooling, detection engineering and documentation, not a single salary.<\/p>\n                <\/div>\n                            <button class=\"accordion\">Can a Managed SOC replace an internal security team?<\/button>\n                <div class=\"panel\">\n                    <p>No. It replaces the need to build and staff a 24\/7 monitoring function, but remediation, system context, risk decisions, policy and governance stay with you. Most organizations end up with a smaller internal team doing higher-value work.<\/p>\n                <\/div>\n                            <button class=\"accordion\">How long does Managed SOC onboarding take?<\/button>\n                <div class=\"panel\">\n                    <p>Technical integration is quick where predefined use cases apply: SITS reports 4\u20136 days on average, with full operational readiness in roughly two to three weeks. Complex or multi-source environments take longer.<\/p>\n                <\/div>\n                            <button class=\"accordion\">Does a Managed SOC include incident response?<\/button>\n                <div class=\"panel\">\n                    <p>Not automatically. At SITS, monitoring, detection and escalation sit in SOC-as-a-Service, while full Incident Response, including forensics, containment leadership and recovery support, is an add-on with its own 24\/7 emergency number and SLA.<\/p>\n                <\/div>\n                            <button class=\"accordion\">What tools does a Managed SOC need?<\/button>\n                <div class=\"panel\">\n                    <p>A SIEM for correlation and an EDR or XDR agent for endpoint visibility are the foundation, supported by identity, network, cloud and email telemetry. SITS delivers primarily on IBM QRadar, Elastic Security and Microsoft Sentinel, with Elastic Defend and Microsoft Defender on the endpoint.<\/p>\n                <\/div>\n                            <button class=\"accordion\">Is Managed SOC suitable for mid-sized companies?<\/button>\n                <div class=\"panel\">\n                    <p>Yes. The cost of 24\/7 internal coverage does not scale down, so mid-sized organizations reach the limits of an internal rota sooner, and packages that separate platform management from alert handling make it possible to start narrow and expand. <\/p>\n                <\/div>\n                            <button class=\"accordion\">How does Managed SOC support compliance?<\/button>\n                <div class=\"panel\">\n                    <p>Through continuous monitoring, consistent logging, documented incident handling and reporting that works as audit evidence. It supports readiness; it does not deliver certification or guarantee audit outcomes on its own.<\/p>\n                <\/div>\n            <\/div>\n<div class=\"accordion_footer\">\n    <\/div>\n<\/div>[\/vc_column][\/vc_row]<\/p>\n<\/section>","protected":false},"excerpt":{"rendered":"<p>[vc_row][vc_column][vc_column_text] A Security Operations Center is the function responsible for detecting and responding to security incidents. It combines three things: telemetry (logs and alerts from your systems), detection logic (the rules deciding what counts as suspicious), and analysts who investigate and decide what happens next. A Managed SOC delivers that function as an external service, [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":35045,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[420],"tags":[],"class_list":["post-35052","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-defense"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Managed SOC Services: 24\/7 Monitoring &amp; Response | SITS<\/title>\n<meta name=\"description\" content=\"What Managed SOC Services include, how they work, what they cost and how to choose a provider. A practical guide for security and IT leaders.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Managed SOC Services: 24\/7 Monitoring &amp; Response | SITS\" \/>\n<meta property=\"og:description\" content=\"What Managed SOC Services include, how they work, what they cost and how to choose a provider. A practical guide for security and IT leaders.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/\" \/>\n<meta property=\"og:site_name\" content=\"SITS\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-24T14:23:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-24T14:25:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sits.com\/wp-content\/uploads\/2026\/09\/Beitragsbild-Managed-SOC.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"1787\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Charlotte Olscha\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Charlotte Olscha\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"21 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/\"},\"author\":{\"name\":\"Charlotte Olscha\",\"@id\":\"https:\/\/sits.com\/en\/#\/schema\/person\/a096e5a6430c2d0f74c324b7c9f47102\"},\"headline\":\"Managed SOC Services: 24\/7 Security Monitoring, Detection and Response\",\"datePublished\":\"2026-09-24T14:23:19+00:00\",\"dateModified\":\"2026-09-24T14:25:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/\"},\"wordCount\":5194,\"publisher\":{\"@id\":\"https:\/\/sits.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/sits.com\/wp-content\/uploads\/2026\/09\/Beitragsbild-Managed-SOC.jpg\",\"articleSection\":[\"Cyber Defense\"],\"inLanguage\":\"en-GB\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/\",\"url\":\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/\",\"name\":\"Managed SOC Services: 24\/7 Monitoring & Response | SITS\",\"isPartOf\":{\"@id\":\"https:\/\/sits.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/sits.com\/wp-content\/uploads\/2026\/09\/Beitragsbild-Managed-SOC.jpg\",\"datePublished\":\"2026-09-24T14:23:19+00:00\",\"dateModified\":\"2026-09-24T14:25:28+00:00\",\"description\":\"What Managed SOC Services include, how they work, what they cost and how to choose a provider. A practical guide for security and IT leaders.\",\"breadcrumb\":{\"@id\":\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#primaryimage\",\"url\":\"https:\/\/sits.com\/wp-content\/uploads\/2026\/09\/Beitragsbild-Managed-SOC.jpg\",\"contentUrl\":\"https:\/\/sits.com\/wp-content\/uploads\/2026\/09\/Beitragsbild-Managed-SOC.jpg\",\"width\":1000,\"height\":1787},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Startseite\",\"item\":\"https:\/\/sits.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Managed SOC Services: 24\/7 Security Monitoring, Detection and Response\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/sits.com\/en\/#website\",\"url\":\"https:\/\/sits.com\/en\/\",\"name\":\"SITS\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/sits.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/sits.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/sits.com\/en\/#organization\",\"name\":\"SITS\",\"url\":\"https:\/\/sits.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/sits.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/sits.com\/wp-content\/uploads\/2024\/04\/sits-logo-new.svg\",\"contentUrl\":\"https:\/\/sits.com\/wp-content\/uploads\/2024\/04\/sits-logo-new.svg\",\"width\":557,\"height\":322,\"caption\":\"SITS\"},\"image\":{\"@id\":\"https:\/\/sits.com\/en\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/sits.com\/en\/#\/schema\/person\/a096e5a6430c2d0f74c324b7c9f47102\",\"name\":\"Charlotte Olscha\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/sits.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/c268c10d74bec8f11f59ba984aa26b6d1b8b5a99a5b95547c4db1b486e6a1538?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/c268c10d74bec8f11f59ba984aa26b6d1b8b5a99a5b95547c4db1b486e6a1538?s=96&d=mm&r=g\",\"caption\":\"Charlotte Olscha\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Managed SOC Services: 24\/7 Monitoring & Response | SITS","description":"What Managed SOC Services include, how they work, what they cost and how to choose a provider. A practical guide for security and IT leaders.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/","og_locale":"en_GB","og_type":"article","og_title":"Managed SOC Services: 24\/7 Monitoring & Response | SITS","og_description":"What Managed SOC Services include, how they work, what they cost and how to choose a provider. A practical guide for security and IT leaders.","og_url":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/","og_site_name":"SITS","article_published_time":"2026-09-24T14:23:19+00:00","article_modified_time":"2026-09-24T14:25:28+00:00","og_image":[{"width":1000,"height":1787,"url":"https:\/\/sits.com\/wp-content\/uploads\/2026\/09\/Beitragsbild-Managed-SOC.jpg","type":"image\/jpeg"}],"author":"Charlotte Olscha","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Charlotte Olscha","Estimated reading time":"21 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#article","isPartOf":{"@id":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/"},"author":{"name":"Charlotte Olscha","@id":"https:\/\/sits.com\/en\/#\/schema\/person\/a096e5a6430c2d0f74c324b7c9f47102"},"headline":"Managed SOC Services: 24\/7 Security Monitoring, Detection and Response","datePublished":"2026-09-24T14:23:19+00:00","dateModified":"2026-09-24T14:25:28+00:00","mainEntityOfPage":{"@id":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/"},"wordCount":5194,"publisher":{"@id":"https:\/\/sits.com\/en\/#organization"},"image":{"@id":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#primaryimage"},"thumbnailUrl":"https:\/\/sits.com\/wp-content\/uploads\/2026\/09\/Beitragsbild-Managed-SOC.jpg","articleSection":["Cyber Defense"],"inLanguage":"en-GB"},{"@type":"WebPage","@id":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/","url":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/","name":"Managed SOC Services: 24\/7 Monitoring & Response | SITS","isPartOf":{"@id":"https:\/\/sits.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#primaryimage"},"image":{"@id":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#primaryimage"},"thumbnailUrl":"https:\/\/sits.com\/wp-content\/uploads\/2026\/09\/Beitragsbild-Managed-SOC.jpg","datePublished":"2026-09-24T14:23:19+00:00","dateModified":"2026-09-24T14:25:28+00:00","description":"What Managed SOC Services include, how they work, what they cost and how to choose a provider. A practical guide for security and IT leaders.","breadcrumb":{"@id":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#primaryimage","url":"https:\/\/sits.com\/wp-content\/uploads\/2026\/09\/Beitragsbild-Managed-SOC.jpg","contentUrl":"https:\/\/sits.com\/wp-content\/uploads\/2026\/09\/Beitragsbild-Managed-SOC.jpg","width":1000,"height":1787},{"@type":"BreadcrumbList","@id":"https:\/\/sits.com\/en\/blog\/managed-soc-services-guide\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/sits.com\/en\/"},{"@type":"ListItem","position":2,"name":"Managed SOC Services: 24\/7 Security Monitoring, Detection and Response"}]},{"@type":"WebSite","@id":"https:\/\/sits.com\/en\/#website","url":"https:\/\/sits.com\/en\/","name":"SITS","description":"","publisher":{"@id":"https:\/\/sits.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sits.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/sits.com\/en\/#organization","name":"SITS","url":"https:\/\/sits.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/sits.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/sits.com\/wp-content\/uploads\/2024\/04\/sits-logo-new.svg","contentUrl":"https:\/\/sits.com\/wp-content\/uploads\/2024\/04\/sits-logo-new.svg","width":557,"height":322,"caption":"SITS"},"image":{"@id":"https:\/\/sits.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/sits.com\/en\/#\/schema\/person\/a096e5a6430c2d0f74c324b7c9f47102","name":"Charlotte Olscha","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/sits.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/c268c10d74bec8f11f59ba984aa26b6d1b8b5a99a5b95547c4db1b486e6a1538?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c268c10d74bec8f11f59ba984aa26b6d1b8b5a99a5b95547c4db1b486e6a1538?s=96&d=mm&r=g","caption":"Charlotte Olscha"}}]}},"_links":{"self":[{"href":"https:\/\/sits.com\/en\/wp-json\/wp\/v2\/posts\/35052","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sits.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sits.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sits.com\/en\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/sits.com\/en\/wp-json\/wp\/v2\/comments?post=35052"}],"version-history":[{"count":16,"href":"https:\/\/sits.com\/en\/wp-json\/wp\/v2\/posts\/35052\/revisions"}],"predecessor-version":[{"id":35261,"href":"https:\/\/sits.com\/en\/wp-json\/wp\/v2\/posts\/35052\/revisions\/35261"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sits.com\/en\/wp-json\/wp\/v2\/media\/35045"}],"wp:attachment":[{"href":"https:\/\/sits.com\/en\/wp-json\/wp\/v2\/media?parent=35052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sits.com\/en\/wp-json\/wp\/v2\/categories?post=35052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sits.com\/en\/wp-json\/wp\/v2\/tags?post=35052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}