forumNew topic

How to define alert escalation times in a SOC contract — what should I look for in the SLA?

LLale K***MemberCommunity member
Joined
Oct 2024
Message
253
#1

We are a 35-person fintech software company. Because of regulatory requirements and the sensitive financial data we process, we are negotiating with an outsourced SOC provider. We are close to signing a 520,000 TL annual contract, but the draft Service Level Agreement (SLA) they sent over has me seriously concerned.

The draft uses vague phrases for escalation times, like "notification will be provided within a reasonable timeframe for critical alerts" or "P1 alerts will be evaluated within 60 minutes." In a privilege escalation or data exfiltration scenario, a 60-minute evaluation window gives an attacker plenty of time to dump everything. On top of that, it says nothing about ownership once an alert reaches us, call-tree ordering, or fallback steps if our team doesn't pick up.

For those who have signed these types of contracts before, what timeframes did you lock in per alert tier? How do you firmly bind triage customer notification, and remediation action windows in the SLA?

RRecep T***New member
Job title
Field sales representative
Sector
Logistics
Organization type
a company within a holding
Joined
Aug 2026
Message
39

Doki · Backup setup · 2023

Most Helpful#2

Short answer: A solid SOC SLA cannot contain vague wording; alerts must be tiered from P1 to P4, with detection, analysis, and notification times measured in specific minutes. For a critical P1 incident, customer notification should take no more than 15 minutes, and initial triage shouldn't exceed 30 minutes.

Break the process down into three distinct phases in the contract: 1) Triage time: The gap between the alert hitting their screen and an analyst picking it up; max 15 minutes for P1. 2) Customer notification time: The window to validate the alert and reach out to your authorized personnel; for P1, require a mandatory phone call within 15 minutes max. 3) Action or escalation time: Bringing Tier 2 and Tier 3 analysts into the loop, which should happen within 30 to 45 minutes at the latest.

Another crucial element is the escalation matrix (call tree). The contract appendix should list the mobile numbers of three designated people from your team in strict order. If the first contact doesn't answer within 5 minutes, call the second, then the third.

Finally, don't forget financial penalties for SLA breaches. If agreed escalation times are breached more than twice in a single month, make sure you have a clause granting a billing discount for that month or the right to terminate the agreement penalty-free.

BBeyza B***MemberCommunity member
Joined
Aug 2024
Message
1
#3

Never accept the phrase "reasonable timeframe"; it is completely unenforceable legally. You are a fintech company and will present this contract to regulatory auditors. Insist on 24/7 phone calls for critical alerts instead of emails as the delivery mechanism.

KKader Ö***Member
Job title
Quality control inspector
Sector
Furniture manufacturing
Organization type
300-person organization
Joined
Sep 2024
Message
163

Doki · Incident response support · 2026

#4

In our contract, we locked in phone notification within 15 minutes for P1, 30 minutes for P2, and 2 hours for P3. Last year, the provider took 40 minutes to respond to two critical alerts. Thanks to the penalty clause, we deducted 25 percent off both monthly invoices, and they never missed a beat after that.

HHakan B***Expert
Job title
Human Resources Specialist
Sector
Plastic
Organization type
early-stage startup
Joined
Jan 2026
Message
409
#5

Write MTTA (Mean Time to Acknowledge) and MTTD (Mean Time to Detect) metrics directly into the contract. Sales reps usually agree but legal departments will push back. If they push back, give them a bit more leeway on the times, but don't leave a single word open-ended.

NNuri G***Member
Job title
Purchasing manager
Sector
Agriculture
Organization type
early-stage startup
Joined
Mar 2023
Message
62
#6

Make sure to add these three exact clauses to the draft agreement: 1) For P1 alerts, reaching the authorized contact by phone within 15 minutes of detection is mandatory. 2) Notifications cannot be limited to email; a record of the voice call must be kept. 3) Any 3 SLA breaches in a month will result in a deduction from the monthly service fee.

SSultan G***MemberCommunity member
Joined
Jun 2024
Message
153
#7

Even if it says 10 minutes on paper, ask how many analysts they actually have on shift. If two people are monitoring five hundred clients, it's physically impossible for them to meet those times. Question the client-to-analyst ratio per shift rather than just the response time.

ŞŞerife B***Member
Job title
System administrator
Sector
Media and publishing
Organization type
chain store
Joined
Nov 2023
Message
51

Doki · Phishing awareness training · 2025

#8

For your legal protection, it is essential to request the removal of ambiguous language from the draft contract provided to you, and to have reaction and escalation times for each alert level detailed on a minute-by-minute basis in an Annex-1 Service Level Matrix.

YYağmur O***Veteran
Job title
Front office accounting
Sector
E-commerce
Organization type
chain store
Joined
Jul 2025
Message
3
#9

Quick question, who decides these P1, P2 classifications? anyway like, if our server gets overloaded is that considered a P1, or does it only count as P1 if there's an actual attack?

edit: I wrote something wrong above, sorry about that.

KKader K***Member
Job title
Store Manager
Sector
Printing
Organization type
8-person team
Joined
Feb 2022
Message
4
#10

Exactly, and not many people know this. Trying to do this alone is the most expensive way.

GGürkan Y***Member
Job title
Store associate
Sector
Plastic
Organization type
cooperative
Joined
Jan 2023
Message
213
#11

Timely topic.

VVeli N***Expert
Job title
System administrator
Sector
Packaging
Organization type
a company within a holding
Joined
May 2022
Message
359
#12

I'd say don't rush. Don't rely on a single measure; go layer by layer.

Hope this helps.

MMustafa A***Member
Job title
Regional Manager
Sector
Paper
Organization type
cooperative
Joined
Mar 2023
Message
37
#13

Thanks, that was the answer I was looking for.

JJülide A***Member
Job title
Accounting Manager
Sector
Jewelry
Organization type
20-person company
Joined
May 2024
Message
103

Doki · Vulnerability scanning · 2026

#14

Ive been down this road let me tell you. Taking measures without an inventory leaves doors you havent seen open.

If you have questions write them; Ill answer as best I can.

VVildan G***VeteranCommunity member
Joined
Jan 2023
Message
349
#15

I partly agree, partly disagree. Payment information changes are never verified through the channel they came from.

Don't rely on a single measure; go layer by layer. Good luck with that.

İİbrahim S***MemberCommunity member
Joined
Apr 2026
Message
106
#16

noted, thanks. taking notes for two weeks yields better results than a six-month estimate.

if I were you I'd go this route.

OOrhan A***Member
Job title
QA Tester
Sector
Software
Organization type
40-person manufacturing company
Joined
Jan 2024
Message
2
#17

Let me share my experience. If it's your first time, start small; scaling comes later.

SSerkan U***Member
Job title
Site Manager
Sector
Education
Organization type
medium-sized business
Joined
May 2025
Message
312
#18

The discussion got scattered, let me summarize. If you don't write this down from the start, it leads to arguments later.

Payment information changes are never verified through the channel they came from. Correct me if I'm wrong.

YYavuzExpert
Job title
Information Security Manager
Joined
Jul 2023
Message
168
#19

I agree.

JJale S***ExpertCommunity member
Joined
Dec 2024
Message
151
#20

Thanks, this was very helpful. When making a decision, first look at what data you have on hand.

I'm also curious if anyone does it differently.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic