Skip to main content
Resilien

by Precursor

Managed SOC Services.
24/7 coverage for your security operations.

Resilien by Precursor brings UK-based monitoring, human-led investigation and agreed threat response to your existing security tools. Give your IT team specialist support around the clock without building an internal SOC.

From £900/month. Coverage, licensing and response permissions confirmed in your quote.

From £900/mo
CREST-Accredited
24/7 UK-Based Analysts

Human expertise.
Machine velocity.

Security tools collect and correlate signals. UK analysts investigate and direct the response, 24/7/365.

  1. Monitor your environment

    Correlate the signals across your agreed security tools.

  2. Investigate what matters

    UK analysts assess suspicious activity in context.

  3. Respond and improve

    Act under agreed procedures and refine detection.

CREST accredited Security Operations Centre

Resilien by Precursor Security
Delivered through our CREST-accredited UK SOC.

Scroll
3,000+ Assessments DeliveredTriple-CREST Accredited24/7 UK SOC in NewcastleReports Accepted by Insurers & RegulatorsEst. 2018

Your security operations.
Delivered by Resilien.

Give your IT team specialist security operations support around the clock.

Managed SOC is the operational foundation. MDR is the investigation and response capability within it. One UK team, with a scope built around your organisation.

From £900/month

Your quote confirms the users, endpoints, log sources, licensing and response actions in scope before the service begins.

Get your Resilien quote

What’s included in Resilien?

The core service
24/7 monitoring of your agreed environment, human-led investigation, detection tuning, security reporting and response through documented procedures.
Coverage agreed with you
Your quote sets out the SIEM and EDR integrations, log sources, retention, threat hunting and response authority. Licensing and any additional costs are confirmed before onboarding.
Optional extensions
Extend your coverage with vulnerability management, EdgeProtect attack surface monitoring, penetration testing or a specialist incident response retainer.
Your team’s role
You provide access, name escalation contacts and approve response permissions. Your IT team retains infrastructure ownership and works with us on remediation and recovery.
Managed SOC, Explained

What is a
Managed SOC?

Outsourced 24/7 security operations: UK-based human analysts watching your SIEM, endpoint, and cloud telemetry on rotating shifts from a physical facility in Newcastle.

A managed SOC (also outsourced SOC or SOC as a Service) is a contracted 24/7 security operations centre.

Human analysts monitor your environment in shifts, correlate signals across SIEM, EDR and identity telemetry, investigate alerts, and take authorised containment actions when a threat is confirmed.

Resilien brings monitoring, investigation and agreed response into a single service scope, so you get the capability of an in-house SOC without the headcount.

At a Glance
Starting price
£900/mo
Fixed quote based on users, endpoints, log sources and service scope
Time to monitoring
Schedule agreed after reviewing integrations and access requirements
SIEM stack
Microsoft Sentinel and Elastic Security, with supported integrations agreed during scoping. Platform deployment, management and licensing are confirmed in your quote.
Supports your assurance work
ISO 27001 A.8.15 / A.8.16 · NIS2 Art 21(2)(b), Art 23 · DORA Art 17 · Cyber Essentials Plus · NHS DSPT · Cyber Insurance

The six service pillars

SIEM & log correlation

Microsoft Sentinel or Elastic Security, with custom log connectors

Managed EDR

Defender for Endpoint, CrowdStrike, SentinelOne, Elastic

Threat hunting (scoped)

Proactive sweeps for known TTPs aligned to MITRE ATT&CK

Incident response

Containment playbooks, evidence preservation, executive comms

Compliance reporting

ISO 27001 A.8.15/A.8.16, NIS2 Article 21/23, DORA Article 17 evidence packs

Attack surface monitoring (optional)

External asset discovery and exposure tracking, available as an additional service

Standards and methodology

Methodology is aligned to the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover), MITRE ATT&CK for detection engineering, and the SOC-CMM maturity model.

Monitoring records and service reports can support your organisation’s security assurance work. The service does not, by itself, establish compliance or certification.

New to this? Our guide to what a managed SOC is explains the essentials.

Methodology Aligned to

Our SOC operates against the canonical frameworks UK regulators, insurers, and procurement teams reference.

What We Do

SOC as a Service: Human analysts watching your environment 24/7.

Your IT team keeps the business running. Resilien adds dedicated security monitoring and investigation from our Newcastle SOC, including nights, weekends and public holidays. Analysts assess suspicious activity and involve your team through agreed escalation procedures.

Discuss your coverage
Internal IT Monitoring
Coverage depends on staffing and shift patterns
Security work competes with operational priorities
Hunting capacity depends on available skills and time
Dedicated SOC Operations
24/7/365 analyst coverage from UK facility
Analysts from our CREST-accredited SOC
Critical alert escalation via your preferred communication method
Capabilities

What Resilien Managed
SOC Covers.

Build your Resilien coverage around your environment. Our UK analysts monitor and investigate your agreed data sources, with threat hunting and attack surface monitoring scoped to your requirements.

Centralized Visibility

See connected signals, not isolated alerts

We connect agreed security log sources, including Microsoft 365, firewalls, workstations, and cloud platforms. Our cloud-native SIEM correlates events across the sources in your service scope, aligned to NCSC in-house SOC building guidance, while optional EdgeProtect continuously monitors your external attack surface for exposed services and compromised credentials.

Endpoint Defence

Managed EDR

We deploy and manage Endpoint Detection & Response agents (Microsoft Defender, SentinelOne, CrowdStrike) to stop ransomware at the process level. Analysts investigate suspicious endpoint activity and take authorised action under your response plan.

Active Pursuit

Threat hunting, scoped to your needs

We apply our Offensive Security roots (CREST) to plan hunts around relevant techniques in the MITRE ATT&CK Enterprise matrix, surfacing enablers of compromise that automated tools miss: dormant lateral movement paths, misconfigured Conditional Access policies, and overprivileged service accounts waiting to be exploited. Our analysts are trained against the SANS threat hunting roadmap.

Human Triage

Priority investigation for critical alerts

Critical alerts are prioritised for human investigation. Your service agreement sets investigation targets and notification arrangements, so your team knows how and when it will be contacted.

Attack Surface

EdgeProtect ASM (Optional)

Continuous monitoring of your external attack surface: exposed services, vulnerable software versions, subdomain takeover risks, and compromised credentials on dark web markets. Findings feed directly into SOC detection rules for closed-loop protection.

Audit Ready

See what happened and what happens next

Monthly service review calls, audit-ready event logs with agreed retention, and documented SLA performance. Supports evidence for ISO 27001 A.8.16, NIS2 continuous monitoring, and DORA operational resilience requirements.

Executive Summary

Advantage of Precursor SOC

An in-house SOC requires people, technology and ongoing management. Resilien provides an agreed managed service around your environment. See the full managed SOC cost breakdown.

Advantage
Specialist support

Access a UK analyst team without recruiting and managing your own SOC rota. Compare costs against the coverage and tooling included in your quote.

Advantage
Agreedschedule
Time to Operational

Your onboarding plan separates first telemetry, live monitoring and baseline tuning.

Advantage
Managed
Security tooling

We manage the agreed security tooling. Your quote confirms licensing, integrations and ongoing costs; your team retains ownership of its infrastructure.

Mapped
Controls
ISO 27001Annex A.8.16
NIS2Art 21(2)(b)
DORAArticle 10
GDPRArticle 32
Physical & Logical Security

The Precursor Advantage.

A physical UK facility with dedicated analysts, combined with offensive security integration that strengthens your defences every day.

Newcastle, United Kingdom

See the SOC.

Visit our analyst floor in Newcastle. See the screens, meet the team, and watch a live threat hunt in progress. We run tours for procurement teams, CISOs, and board members. No sales pitch. Just evidence.

Book a SOC Tour
Offensive & Defensive Synergy

The Closed-Loop Advantage.

Our penetration testers use live SOC threat intelligence to test your defences against active attack patterns. This continuous loop between offensive and defensive operations means your security posture strengthens every single day.

Red Team
Blue Team
Technology & Integrations

We work with your existing stack.

Keep supported SIEM, EDR and cloud platforms. We confirm connectors, access and licensing requirements before onboarding.

SIEM

Microsoft Sentinel

EDR

Microsoft Defender

EDR

CrowdStrike Falcon

EDR

SentinelOne

SIEM

Elastic Security

Cloud & Identity

Azure / Entra ID

Cloud

AWS CloudTrail

Network

Cloudflare

Pricing

Resilien Managed SOC Pricing

Resilien starts from £900/month. We scope your users, endpoints, log sources and response requirements in a free 30-minute call, then confirm a fixed monthly quote including licensing and service options.

Fully Managed SOC

Turnkey Operations

24/7 monitoring, investigation and agreed response across your in-scope endpoints, identities, cloud and network. Your quote confirms integrations, reporting and service options.

From £900/month

Hybrid Cloud SOC

Targeted Coverage

Targeted monitoring for specific assets (AWS/Azure environment, OT/IoT networks) or specific compliance requirements such as PCI-DSS or NIS2.

Scoped to requirements
Analysts from our CREST-accredited SOC
Monthly service review calls
EdgeProtect ASM (optional)
Agreed log retention
Discuss your coverage
A fixed monthly quote showing coverage, licensing and service options.
Engagement Pipeline

Getting Started with Resilien

Four stages from scoping to live monitoring, with dates agreed around your integrations and access requirements.

Step 01

Scoping & Contract

30-minute scoping call to assess your log sources, user count, and existing tooling. Fixed monthly price confirmed before work begins.

OutputScoped proposal
Step 02

Connector Deployment

Lightweight agents and API integrations deployed to your Microsoft 365, Azure, firewall, and EDR platform. Deployment dates are agreed in your onboarding plan.

OutputLog Ingestion Active
Step 03

Baseline & Tuning

We establish normal activity and tune Resilien detection rules to reduce false positives. Coverage is refined as telemetry comes online.

OutputDetection Rules Tuned
Step 04

24/7 Monitoring Live

Full 24/7/365 monitoring active. Monthly service review calls, quarterly threat reviews, and continuous detection engineering.

OutputSOC Operational
Deliverables

Your Resilien Service Specification

Your proposal documents the capabilities below for your agreed environment. Service options and response permissions are confirmed before onboarding.

24/7/365 human-led threat monitoring from our Newcastle SOC facility
Critical alert triage via your preferred communication method
Monthly service review call with threat landscape summary and SLA metrics
Threat review schedule and analyst support agreed during scoping
Managed EDR deployment and ongoing agent management
EdgeProtect attack surface monitoring available as optional addition
Log retention and audit-ready export agreed in your scope
Incident response support with documented containment procedures
Analyst access and investigation updates through a secure portal

Your Resilien service is delivered through Precursor’s CREST-accredited SOC. Your quote confirms threat intelligence, hunting, reporting and response commitments for your environment.

How they differ

SIEM vs MDR vs XDR vs SOC

Four overlapping terms that buyers often treat as interchangeable. The distinction matters, because each has a different scope, cost envelope, and operational role. For the full five-way breakdown including EDR, see our MDR vs SOC vs SIEM vs EDR vs XDR buyer's guide.

DimensionSIEMMDRXDRSOC
Primary focusLog collection, correlation, alertingOutsourced investigation and threat responseIntegrated detection across endpoint, email, cloud, identityPeople, process, and tools combined for monitor→alert→respond
What it isA platformA serviceA platformA capability (people + tech + process)
Action vs alertCapabilities depend on configuration and integrationsInvestigate and respond within agreed permissionsAlert + automated/semi-automated responseFull operational loop, end-to-end
Coverage scopeAny log source you connectAgreed endpoint, identity, network and cloud sourcesVendor ecosystem (single-stack)Agreed sources and integrations
Cost factorsLicensing, ingestion and retentionCoverage, integrations and response scopeVendor licensing and deployment scopeResilien from £900/month; in-house costs depend on staffing and tooling
Ideal forTeams that want visibility but retain responseOrgs needing outsourced 24/7 responseSingle-vendor-committed estatesOrgs that want the full managed capability without building it

Precursor's Managed SOC includes SIEM (Microsoft Sentinel or Elastic), MDR-grade endpoint monitoring, and XDR-style cross-layer correlation within one CREST-accredited UK service, so you don't have to stitch the categories together yourself. For the investigation and response capability, see our managed detection and response service.

Compare detection tools

Deciding between detection technologies? These side-by-side comparisons explain the differences and where each fits.

Related security terms

Plain-English definitions of the concepts behind this service, from our security glossary.

Managed SOC

Build Your Resilien Managed SOC Service.

Tell us about your environment and the support your team needs. We will contact you to discuss coverage, licensing and response permissions, then prepare your Resilien quote.

CREST Accredited
UK-Based Analysts
From £900/month

Resilien Managed SOC: Common Questions

Pricing, onboarding, coverage, and compliance.