UTMStack

Extra SOC analysts for the hours and alerts your team can't cover

Our analysts join your existing security operations or IT security team. They cover the night and weekend shifts you can't staff, take the alert overflow and back you up on hard incidents, following your playbooks. You stay in charge of your environment, your decisions and your customers.

Security analysts watching dashboards in an operations center at night
  • Night and weekend shifts

    Analysts watch your UTMStack console while your team is off, so no alert waits until morning.

  • Overflow and backup

    When alert volume spikes or an incident needs more hands, we take the extra load and work it with you.

  • Your playbooks, your call

    We follow your escalation rules and response playbooks. You decide what we act on and what we hand back.

  • Behind your brand

    For SOC providers and MSSPs, we work under your name and your process. Your customers stay your customers.

  • Every hand-off recorded

    Each alert we work, each note and each response action is in the console, so your team picks up exactly where we left off.

What’s included

  • Night, weekend and holiday coverage, or full 24/7
  • Alert triage and investigation on your UTMStack console
  • Incident response backup, within the limits you set
  • Escalation to your team by phone, email or chat, following your runbook
  • Shift hand-off notes in each alert and incident
  • Threat hunting and threat intelligence research on request
  • Help keeping compliance evidence and reports current
  • Forensic analysis for serious incidents
  • Works with your existing endpoint detection and response (EDR) and antivirus tools
  • White-label service for SOC providers and MSSPs
  • Monthly coverage report

How we fit into your team

We agree on the hours we cover, the alerts we handle and what we may do on our own, for example blocking an address or isolating a host, and what we always escalate. During our shifts we triage and investigate in your UTMStack console, act within those limits, and leave notes so your team starts the next shift informed.

For SOC providers and MSSPs

Many of our partners run their own SOC on UTMStack. We support them, we don't compete with them: our analysts can take a partner's night shifts or overflow under the partner's brand and procedures, and the customer relationship stays with the partner.

Built on the UTMStack platform

Our analysts work in the same console your team uses, with real-time correlation, threat intelligence, automated response and compliance reporting. Every alert, incident and response action is recorded, so you can review what we did and why.

Questions buyers ask

Do you replace our security team?

No. We extend it. Most teams use us for the hours they can't staff, for alert overflow, or as backup during a serious incident, while their own analysts stay in charge.

We are an MSSP. Will you compete with us for our customers?

No. For partners we work behind your brand and follow your procedures, and your customers remain yours. Talk to us about partner terms.

What can your analysts do without asking us?

Only what we agree with you up front. Some teams let us contain threats right away, for example by isolating a host or blocking an IP address; others want every action escalated first.

How much does it cost?

It depends on the hours you need covered, the number of devices and data sources, and the services you choose. Contact us for a quote.

Can we keep our current EDR or antivirus?

Yes. UTMStack integrates with EDR and antivirus tools such as CrowdStrike, SentinelOne, Sophos and Bitdefender, and our analysts use their alerts alongside everything else.

Get a quote

Tell us about your environment. We reply within one business day with scope, timing and price.

We reply within one business day. See our privacy policy.