Managed security
SOC as a Service
Our people. Our building.
SOC as a service means somebody else runs your security operations centre: the team that collects security alerts, decides which of them mean anything, and acts on the ones that do. happier IT’s SOC is in Canada and staffed by happier IT employees. We do not resell another company’s monitoring desk, which is the ordinary arrangement in this market and rarely mentioned in a proposal.
Who it's for
The software is bought. The rota is what is missing.
Almost nobody arrives here without security tools. They arrive because nobody has the hours, or the mandate, to look at what those tools produce.
You own the consoles and nobody opens them. Endpoint software, Microsoft 365 security features, a firewall that logs. All of it is reporting into dashboards that were last signed into during the rollout. This is the normal state of an organization without a security team, not a failing.
Your IT person cannot be the rota. One person, or three, cannot cover evenings, weekends and their own holiday. Asking them to try is the reliable way to lose them, and the cover is only as good as the week they are having.
Someone asked who is watching. A client’s security schedule, an insurer’s renewal form, a public-sector procurement question. “We have antivirus” stopped being an answer that scores on those forms a while ago.
You need to be able to say where the watching happens. Healthcare, legal, credit unions, anyone with a Canadian data residency clause. Naming the country your monitoring runs in is a question we can answer in one sentence.
Four questions for any SOC
Who actually looks at an alert? Are they your employees or a subcontractor’s? Which country do they sit in? And what are they permitted to do at 3am without phoning me first?
Ask all four of every provider, including us. The answers are rarely volunteered and they change what you are buying more than any feature list does.
What's included
What a security operations centre actually does.
A SOC is not a product. It is a rota, a severity scale, a defined action for each kind of alert, and a way to reach you when it matters.
-
Log collection into one place
Endpoints, servers, identity and sign-in activity, email, cloud services, firewalls and network gear all feeding a SIEM, a security information and event management system, which is the central place security logs are gathered and compared. Six separate consoles cannot tell you a story. One can.
-
Human triage on a staffed rota
Analysts decide which alerts matter. The overwhelming majority of security alerts are noise, and the point of a SOC is that a person separates the two so your team never sees the noise or learns to ignore it.
-
Threat hunting, not only waiting
Going looking for the things that generate no alert: an account signing in from two countries an hour apart, a new mailbox forwarding rule, an administrator account created outside a change window. Alerts find the known. Hunting finds the rest.
-
Containment inside an authority you set
Isolating a device, disabling an account, blocking a sender. We agree in writing beforehand exactly what we may do without waking you and what always warrants a call, then we review that agreement every quarter.
-
Detection tuning as a standing job
Every environment has one application that behaves oddly and one scheduled task that looks alarming and is not. Untuned detection buries the single real event under a hundred false ones, so tuning is a monthly job rather than a setup step.
-
An escalation path with real names on it
Named people in order, with the hours each is reachable, in both directions. Ours to you, and yours to us. Written down, tested, and kept somewhere you can reach when your own systems are not available.
-
Reporting a board or an insurer can read
What was seen, what was acted on, what changed and what we recommend next, written for a non-technical reader. The same document works as audit evidence and as a renewal attachment.
-
A quarterly review of what is watched
Coverage drifts. You add a system, retire a server, open an office. Once a quarter we check that what we monitor still matches what you actually run, and write down anything that is deliberately out of scope.
How it works
About three weeks to onboard, most of it listening.
The temptation is to switch everything on in week one. That produces a flood of alerts nobody can act on, and a team that has learned to ignore them by week three.
-
Connect and baseline
We connect the log sources, identity, endpoints, email, cloud, network, and then watch quietly for a while to learn what normal looks like in your environment. An alert only means something relative to a baseline, and nobody can hand us yours.
-
Agree the rules of engagement
We cut the false positives, set the severity scale, and write down what we may act on unilaterally and what always warrants a phone call. You approve that document before we start acting on anything.
-
Watch, act, report
Continuous monitoring with human triage, containment inside the agreed authority, and a monthly report in plain English. Reviewed with you every quarter, alongside a check that coverage still matches what you run.
What it costs
Priced on people and monitored systems, not on data volume.
Pricing security monitoring per gigabyte or per alert punishes you for having visibility. It is a bad incentive and we have not built our pricing on it.
happier IT’s SOC service is a fixed monthly fee based on the number of people and the number of monitored systems.
Three things move it:
- How many log sources. Identity and endpoints are the baseline. Firewalls, servers, industrial systems and line-of-business applications each add coverage and cost.
- How much authority you give us. Letting us contain automatically at agreed severities is faster and cheaper than routing every action through an approval.
- Your evidence obligations. Regulated sectors need longer retention and more formal reporting, and both are real costs.
It is materially cheaper alongside managed IT, because the analyst looking at your alert already has your documentation and your ticket history open.
Staffed hours, in writing
Software runs continuously almost everywhere, so “24/7 monitoring” on a website usually describes a server rather than a person. Ask for staffed analyst hours instead, and ask for them in the contract.
happier IT’s staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific. Time from a critical detection to a person looking at it: minutes, not hours.
Why us for this
Ours is in Canada, and the analysts are on our payroll.
This is the one thing about happier IT that is genuinely hard for a provider of our size to copy. Running your own security operations centre is expensive. It means employing enough analysts to cover a rota without exhausting them, keeping their skills current, and carrying that cost whether or not anything happens this month.
Most of the market makes the other choice: licence a monitoring platform, put a logo on the portal, and subcontract the watching, often to a desk in another country and another time zone. That is a legitimate business model and it can work perfectly well. It is also almost never stated plainly, and it changes what happens next when something fires at 2am.
The practical difference is small and it matters. The person who picks up your alert already knows your environment, can see the ticket you raised last Tuesday, and can phone you directly, rather than raising a case with a provider, who raises a case with you. Data stays in Canada. Our security team holds Certified Ethical Hacker credentials alongside our Microsoft, Cisco, VMware, CompTIA and Red Hat certifications; the full list is on our awards and certifications page.
Go deeper
- What is a SOC? The plain definition, without the mystique.
- What is a SIEM? Where the logs actually go.
- Managed security services (MSSP) How the whole service fits together.
Questions
What people ask before they sign anything.
What is a SOC?
A SOC is a security operations centre: the team and the process that watch security alerts, decide which ones matter, and respond. It is people first and technology second. A SOC needs a rota so somebody is always responsible, a severity scale so alerts are ranked consistently, a written action for each kind of alert, and a way to reach you. Buying a monitoring platform without those four things gives you a dashboard, not a SOC.
What is the difference between a SOC and a SIEM?
A SIEM is software; a SOC is people. SIEM stands for security information and event management: the system that collects logs from your endpoints, servers, identity platform, email and network, and correlates them so a single event can be seen across all of them. The SOC is the team that reads what it produces and acts. A SIEM without a SOC is an expensive log archive, which is a common and disappointing purchase.
Do we need a SOC if we already have EDR?
EDR, endpoint detection and response, the security software on your laptops and servers that watches behaviour rather than matching known files, produces alerts. A SOC is the part that reads them. If somebody in your organization genuinely reviews that console daily, knows what normal looks like, and is available outside office hours, you may not need us. In most organizations under 200 people nobody is, and that is a staffing reality rather than a criticism. See managed EDR for the two combined.
Is your SOC actually yours?
Yes. It is happier IT’s own facility in Canada, and the analysts are happier IT employees rather than a partner’s staff working under our name. We volunteer this because much of the market does the opposite and does not say so. If you are comparing providers, ask each one the same question and ask for the answer in writing, it is not a rude question and any honest provider will answer it directly.
What can you do without calling us first?
Exactly what you wrote down during onboarding, and nothing beyond it. Most clients authorise us to isolate a single device from the network and to disable one user account at high severity, because both are quickly reversible and both stop a problem spreading. Actions with wider consequences, taking a server offline, blocking a whole supplier domain, forcing a company-wide password reset, usually require a call. You can change that authority at any point, and we review it with you every quarter.
Is our data stored in Canada?
Yes, for the monitoring we run. Where a third-party product already in your environment stores its own data somewhere else, we will name the product and where it stores things rather than implying we control it. If you have a residency clause in a client contract or a public-sector agreement, send it to us and we will tell you plainly whether we meet it.
What does SOC as a service cost in Canada?
When you compare quotes, watch for two things. First, whether pricing is based on data volume, which means your bill rises every time you add visibility. Second, what the number includes at the response end, some quotes cover alerting only, and containment is a separate engagement bought at the worst possible moment.
Related
Where to go next.
Go deeper
What the SOC watches
Related services
Want to know what this would look like for you?
A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.