Documentation

Managed SOC · Guides

Alert handling & escalation

Configure severities, escalation contacts, response authorizations, and notification channels so the SOC acts the way your team expects.

How the SOC handles a case — and how fast you hear about it — depends on the severity, your escalation contacts, and the response authorizations you set. This guide covers all three.

Severity levels

SeverityMeaningTypical handling
CriticalActive compromise or imminent business impactImmediate response + phone escalation
HighConfirmed malicious activity, contained scopeRapid investigation + notification
MediumSuspicious activity needing validationInvestigated in queue, summarized
Low / InfoPolicy or hygiene findingsLogged, included in reporting

Severity is set by the analyst during triage, not by the raw rule — the same detection can be Critical in one context and Low in another.

Escalation contacts

Set your contacts in Portal → SOC → Escalation. Provide an ordered list so the SOC knows who to reach and in what order, including an after-hours path.

Warning

Critical escalations use phone first. If your after-hours number is wrong or unmonitored, response slows down. Verify contacts quarterly.

Response authorizations

Decide, per action, whether the SOC may act autonomously or must get approval first. Configure these in Portal → SOC → Response policy.

  • Isolate endpoint — cut a device off the network while preserving it for investigation.
  • Disable identity — suspend a compromised account and revoke sessions.
  • Block indicator — push a domain/IP/hash block to your controls.

Pre-authorizing containment for Critical cases is the single biggest lever on "time to contain." Many teams pre-authorize endpoint isolation and identity disable, and require approval for anything that could disrupt production.

Notification channels

Route case notifications to the channels your team already uses:

  • Email and SMS to escalation contacts
  • A shared inbox or ticketing system
  • Chat (via webhooks into Slack or Teams)
  • Your SIEM/SOAR via the Managed SOC API

Reviewing outcomes

Every closed case records what happened, what was done, and why — evidence, chain of custody, and the investigation timeline are held in multi-tenant SIEM case management rather than in an analyst's notes. Monthly reviews summarize trends, tuning changes, and recommendations. Request an ad-hoc incident report anytime from a case in the Portal.

Need a hand with Managed SOC?Talk to our team →