Skip to content

Field note / security monitoring

Baseline hygiene finds drift on a schedule. Monitoring means someone is watching right now.

Security monitoring and incident response is named on the pricing page as its own written decision - deliberately kept separate from the Plus baseline. It sits above configuration hygiene and is qualified on its own, the same way backup and disaster recovery is.

Why it sits above the baseline

The Plus baseline and a monitoring lane answer different questions.

The Plus reference band's security-baseline routine finds configuration drift on a fixed review cadence - a snapshot, checked periodically. Security monitoring and incident response asks a different question: if something goes wrong between two scheduled reviews, who sees it, and what happens in the next few minutes. Bundling the two under one name would blur a scheduled check with a standing watch, and this site avoids exactly that kind of unqualified promise elsewhere.

Review what the Plus baseline actually covers →

Where it comes up

An alerting tool already exists

A licensed platform is already installed somewhere in the environment, generating alerts that may or may not be reviewed.

Included pattern
Confirming what the existing tool actually watches and where its alerts go today.
Required inputs
Which platform is in place, who currently receives alerts, and how often they are actually reviewed.
Explicit exclusions
Assuming a licensed tool already equals a staffed response.

Where it comes up

No alerting exists yet

Nothing is currently watching identity sign-ins or endpoint behaviour for signs of compromise.

Included pattern
Naming a realistic starting scope - identity sign-ins, endpoint detections, or both - before promising broad coverage.
Required inputs
The systems and accounts that matter most if compromised.
Explicit exclusions
A commitment to monitor everything from day one.

Where it comes up

A suspected incident, right now

Something has already happened and the facts are still unclear.

Included pattern
A defined first-response sequence and a named decision owner while facts are still incomplete.
Required inputs
What was observed, when, and by whom.
Explicit exclusions
A guaranteed containment time or recovery outcome.

Where it comes up

After the incident closes

The immediate event is over and the question turns to what it means going forward.

Included pattern
A written record of what happened, what changed, and what the review recommends next.
Required inputs
Willingness to document the event honestly, including gaps found.
Explicit exclusions
A promise that the same gap cannot recur elsewhere.

Boundary table

Four questions that belong to qualification, not the public offer.

QuestionWhy the public bands cannot answer itWhere it gets answered
What counts as "watched"?Coverage depends entirely on which systems, accounts, and signal sources are actually in scope.Written into the service boundary record.
Who is on the hook when an alert fires outside business hours?Coverage hours and after-hours ownership are a separate qualification variable, not an assumed default.Confirmed alongside the after-hours coverage decision.
What does "incident response" actually deliver?Containment authority, communication ownership, and technical depth vary by incident and are never generic.Named in the written agreement.
How is severity decided?A triage standard has to fit the tools and accounts actually in place - there is no universal severity scale.Set during scoping, not assumed from a marketing page.

What not to promise yet

Keep the offer honest until the environment is qualified.

  • A 24/7 security operations centre or continuous human monitoring
  • A guaranteed detection or containment time
  • A guarantee against ransomware, data theft, or business email compromise
  • Compliance with a specific cyber-insurance or regulatory monitoring requirement
  • Coverage for a system nobody has named yet

A qualified monitoring lane is a genuine, sellable service. An implied one - assumed because a tool exists somewhere - is a liability with someone else's name on it.

Read the plain answer on managed SOC claims →

Related decision

Device monitoring and security monitoring are not the same job.

RMM and endpoint monitoring watch device health and patch state. Security monitoring watches for signs of compromise. Some tooling overlaps; the ownership and response do not.

Compare device monitoring and RMM

Bring what already watches something, even informally.

Name the tool, the account, or the alert nobody has looked at in months. That is enough for an initial fit review.

Discuss a security monitoring lane