Frequently Asked Questions

Everything you want to know

Transparency is the foundation of trust. Below you'll find answers to the questions we hear most often from security and IT managers.

The service

What does SOC Continu do exactly?

What is the difference between SOC Continu and an MSSP?

+

A traditional MSSP (Managed Security Service Provider) delivers a fully outsourced SOC — including its own tooling, its own processes and its own reporting formats. That means your in-house knowledge and established procedures are largely pushed aside.

We work differently. SOC Continu is not a replacement for your SOC or IT security team. We are the extension: we plug into your SIEM, follow your playbooks and escalate through your agreed channels. Your team stays in the lead — we only take over staffing outside business hours.

Can you work with our existing SIEM?

+

Yes. We work with the customer's SIEM — not the other way around. We obtain read access to your existing environment and receive alerts exactly the way your own analysts would. There is no migration, no additional license and no need to replace tooling.

We have experience with widely used platforms including:

  • Microsoft Sentinel
  • Splunk
  • IBM QRadar
  • Elastic SIEM
  • Wazuh
  • And other EDR/XDR/MDR environments

Have a less common platform? Get in touch — in most cases integration is still possible.

What do you do and what do you not do?

+

What we do:

  • Continuous monitoring of incoming security alerts from your SIEM/EDR/XDR
  • Triage: determining the severity and impact of each incident
  • Classification according to your taxonomy (low, medium, high, critical)
  • Escalation of urgent situations through agreed channels (SMS, phone, secure chat)
  • Logging and reporting of all actions and findings

What we do not do:

  • Remediation of systems — that remains your responsibility
  • Replacing your CISO or in-house security strategy
  • Running penetration tests or vulnerability scans
  • Modifying your SIEM configuration or detection rules
  • Acting on your systems on our own without your instruction

When are you active?

+

By default we provide coverage outside regular business hours:

  • Monday through Friday: 18:00 – 08:00
  • Weekends: Friday evening 18:00 through Monday morning 08:00 (continuous coverage)
  • National public holidays: full coverage

The times are fully adjustable based on your situation and schedules. Do you run shifts or have non-standard business hours? We arrange that in consultation.

Collaboration & onboarding

How does the collaboration work in practice?

How quickly can you be operational?

+

After signing the agreement and the data processing agreement, we start onboarding. The onboarding process typically consists of four steps:

  • Intake: mapping your environment, playbooks and escalation contacts
  • Technical integration: setting up read access to your SIEM via a service account or API
  • Acceptance test: we simulate an alert and verify the full chain
  • Go-live: coverage starts according to the agreed times

Depending on the complexity of your environment, a lead time of 1 to 3 weeks is realistic.

What if there is a P1 incident in the middle of the night?

+

In the event of a critical incident (P1), we escalate immediately through the channels you have defined — typically a combination of SMS, phone and secure chat. We follow your escalation matrix: we call the primary contact first, and the backup if there's no answer.

The analyst documents all actions in real time and consults with your on-call staff about next steps. We never act on our own for critical decisions — control always remains with your organization.

Before the engagement starts, we jointly draw up an escalation plan, so this process is fully documented and there is no doubt about who does what.

Do you need our playbooks and procedures?

+

Yes, and that is exactly the strength of our model. We work within your procedures — not alongside or above them. Your existing playbooks, escalation rules and communication protocols remain in the lead.

Don't have a complete set of playbooks yet? No problem. During onboarding we help you with a baseline set that covers the most common incident types, and we build on it during the engagement based on your environment.

How does the handover work at the start and end of business hours?

+

Every shift includes a structured handover. At the start of our shift we log in to your environment and check the current status. At the end of our shift we deliver a concise shift report: what came in, how it was assessed, which actions were taken and what the current state is.

That way your day team starts every morning with a complete picture — with no gaps in the information handover.

Security & compliance

How do you safeguard security and privacy?

How do you protect our data and environment?

+

We take the security of your environment as seriously as you do. Our baseline measures:

  • Read access only: we never write to your source systems, unless explicitly agreed
  • MFA mandatory on all systems used to access your environment
  • Encrypted connections (TLS 1.2 or higher) for all communication in transit
  • Role-based access: only the analyst on duty has access
  • Our own activities are logged so it is always demonstrable who did what
  • Confidentiality agreements with everyone involved

All arrangements are recorded in a data processing agreement in accordance with the GDPR.

Do you comply with NIS2, BIO or other regulations?

+

Our service is explicitly designed to help organizations meet the monitoring requirements of:

  • NIS2: continuous monitoring and escalation obligations outside business hours
  • BIO (Dutch Government Information Security Baseline): for government organizations
  • DORA: for financial institutions that need to demonstrate operational resilience
  • GDPR: all processing activities are recorded in a data processing agreement

We are currently preparing for ISO 27001 certification. In the meantime we offer full transparency through audits and documentation on request.

What if you miss an incident?

+

No SOC — internal or external — can guarantee that every incident is always picked up immediately. We are open and honest about the reality of alert monitoring: detection quality is closely tied to the quality of the detection rules in your SIEM.

What we do guarantee: all incoming alerts are assessed within the agreed SLA times, and all actions are documented so it's always demonstrable what was done.

Our liability is contractually defined in our SLA and service agreement. We recommend discussing these with your legal advisor before the engagement starts.

Costs & contracts

What does it cost and how does the contract work?

What does the service cost?

+

Our rates are monthly and fully tailored — based on the size of your environment, the number of sources to be monitored and the desired coverage hours.

As an indication: our service starts from €7,000 per month for a standard after-hours package. Enterprise environments with extensive coverage are priced based on a custom quote.

We also offer a trial period: start with a scoped pilot to experience how the collaboration works in practice, before you enter into a longer agreement.

What is the minimum contract term?

+

As a default we use a minimum term of 3 months, including the onboarding period. After the initial period, agreements can be terminated monthly with a one-month notice period.

For organizations that want longer-term certainty, we also offer annual contracts at a more favorable rate.

Can we also end the engagement if we're not satisfied?

+

Absolutely. We don't want customers who stay with us because it's contractually hard to leave. After the initial 3-month period you can cancel monthly.

When the engagement ends, we ensure a careful handover: all documentation, work logs and incident reports are transferred to you, and all access to your systems is revoked immediately and confirmed in writing.

Is your question not listed?

Get in touch directly. We'll answer all your questions in a no-obligation 30-minute conversation.