Cybersecurity — Security Operations
SOC services for New York businesses
A log pipeline that sees identity, endpoint, email, and network in one place; alerts engineered to deserve attention; and a staffing model we describe honestly — tooling watches continuously, engineers are paged.
A SIEM-lite pipeline, sized for firms your size
Full enterprise SIEM deployments fail predictably at SMB and mid-market scale: the licensing is priced for banks, the care and feeding consumes an engineer you do not have, and the dashboard ends up watched by nobody. The failure is not the technology — it is buying visibility with no one on the other end of it.
We run a leaner model. Collect the logs that answer investigative questions, normalize them into one searchable place, retain them as long as your compliance regime requires, and alert only on what has earned an alert. The value is in the join: a sign-in from a new country, a new inbox rule, and an unusual mail forward are three ignorable events in three consoles — and one obvious story in a pipeline.
Security operations is the connective tissue of our managed cybersecurity practice: MDR brings endpoint depth, this pipeline brings breadth across everything else, and incident response depends on the logs both of them keep.
What the pipeline covers
Sources are chosen for investigative value, not volume. Each one exists to answer a question we know gets asked.
Entra ID sign-in and audit logs
Who signed in, from where, with what result — the first question in nearly every modern investigation.
Endpoint and EDR telemetry
Process, script, and network activity from the MDR agents, correlated with everything below.
Microsoft 365 and email events
Mailbox rules, forwarding changes, sharing activity, and admin actions — where BEC leaves its fingerprints.
Firewall and VPN logs
Perimeter and remote-access events from your network infrastructure, joined to the identity behind them.
Backup job results
Failed or disabled backup jobs are a security signal — attackers turn backups off before they encrypt. Tied into business continuity.
SaaS admin events
Privilege grants, configuration changes, and new integrations in the applications your business runs on.
How an alert earns its place
Alert engineering is the difference between a pipeline and a noise machine. Every alert in your environment exists on purpose.
Baseline
Two to four weeks of observing your environment’s normal before alerting turns on — what is unusual for a law firm is Tuesday for a logistics company.
Write detections
Detections map to things worth acting on: impossible travel, new mailbox forwarding, privilege escalation, backup tampering, sign-ins to dormant accounts.
Tune relentlessly
Every alert that fires is dispositioned: actioned, tuned, or retired — with a record of which and why. An alert that is always ignored is a defect, and we treat it like one.
Escalate
Alerts that cross the agreed threshold page an engineer. The paging thresholds and escalation order are documented in your agreement, not implied.
Review
Monthly: what fired, what was real, what was tuned, and what changed in your environment that the detections should follow.
The staffing model, stated plainly
A meaningful share of the market sells “24×7 SOC” backed by a white-labeled offshore alert feed or a dashboard nobody opens. We will not sell that sentence. What we operate: continuous automated monitoring of every source above, containment actions that are pre-authorized in writing so they execute without waiting for a human, and paging thresholds an engineer set deliberately — with the escalation path published to you.
If we ever staff an around-the-clock analyst floor, we will announce it as a change to the service. Until then, this page stays accurate.
Retention and evidence, decided up front
Log retention is a compliance decision, not a storage default. NYDFS Part 500 expects audit trails that can reconstruct material events; HIPAA expects activity review; SOC 2 auditors and cyber insurers both ask how far back you can look. We set retention per regime, write it into the agreement, and keep the logs searchable — because the first question after any incident is “when did this actually start?”
Monthly reporting is written for the people who will actually read it: your leadership, your auditor, your insurer, and the client whose security questionnaire asks whether anyone reviews your logs.
Good fit if
A regulator or framework requires log retention and review
A client questionnaire asked “who monitors your environment?”
Internal IT is capable but has no log discipline
A post-incident review found you could not see what happened
You own security tools whose logs nobody reads
Common questions
Do you run a staffed 24×7 SOC?
No. Our tooling monitors continuously, pre-authorized containment executes automatically, and engineers are paged when thresholds are crossed. We publish this model because the alternative — implying a staffed floor that does not exist — is how this industry earns its reputation. If that model is disqualifying for your requirements, we will say so in the first meeting.
What is the difference between a SOC and an MSSP?
A SOC is a function: the operation that watches logs and alerts and responds to them. An MSSP is a firm that runs security services, usually including that function. This page describes how Stedholm runs the SOC function inside our broader managed cybersecurity practice.
Do we need a full SIEM?
Most firms under a few hundred seats need the outcome of a SIEM — centralized logs, retention, correlation, alerting — without the enterprise licensing and care-and-feeding burden. If your regime genuinely requires capabilities beyond our pipeline, we will name which ones and why rather than stretch the definition.
Can you use the tools we already own?
Usually, and we prefer to. Microsoft 365, Entra ID, and Defender logs are first-class sources, and most business firewalls export cleanly. The assessment maps what you have before we propose anything new.
How long do you keep our logs?
As long as your regulatory and contractual obligations require — that number is set during scoping and written into the agreement. Retention is an engineering and compliance decision we make with you, not a marketing figure we advertise.
See your whole environment in one queue.
An engineer will walk through which logs you have, which are missing, and what they would reveal.