We are a mid-sized logistics company with about 45 servers and around 300 endpoints. Due to the recent uptick in ransomware and phishing incidents, we collected proposals from three different vendors for 24/7 outsourced security operations center (SOC) services. Our annual budget sits around the 450,000 TL to 600.000 TL range.
Reviewing the proposals, what confused us most was the Incident Response (IR) part. Two of the proposals broadly list incident detection, alert generation, and customer notification. However, if critical suspicious activity is detected or a ransomware attack kicks off in the middle of the night, whether their team actually logs into our environment and intervenes is left completely vague. Another vendor stated they charge by the hour, asking an extra 3,500 TL per hour of incident response.
For those using SOC services, how do you handle this process during a crisis? Does a baseline SOC package just raise alarms and make phone calls, or can containment actions like isolating a device from the network be included in the contract? How should we define the scope so we don't get hit with surprise invoices?