We are a 35-person fintech software company. Because of regulatory requirements and the sensitive financial data we process, we are negotiating with an outsourced SOC provider. We are close to signing a 520,000 TL annual contract, but the draft Service Level Agreement (SLA) they sent over has me seriously concerned.
The draft uses vague phrases for escalation times, like "notification will be provided within a reasonable timeframe for critical alerts" or "P1 alerts will be evaluated within 60 minutes." In a privilege escalation or data exfiltration scenario, a 60-minute evaluation window gives an attacker plenty of time to dump everything. On top of that, it says nothing about ownership once an alert reaches us, call-tree ordering, or fallback steps if our team doesn't pick up.
For those who have signed these types of contracts before, what timeframes did you lock in per alert tier? How do you firmly bind triage customer notification, and remediation action windows in the SLA?