by Precursor
Managed SOC Services.
24/7 coverage for your security operations.
Resilien by Precursor brings UK-based monitoring, human-led investigation and agreed threat response to your existing security tools. Give your IT team specialist support around the clock without building an internal SOC.
From £900/month. Coverage, licensing and response permissions confirmed in your quote.
Human expertise.
Machine velocity.
Security tools collect and correlate signals. UK analysts investigate and direct the response, 24/7/365.
Monitor your environment
Correlate the signals across your agreed security tools.
Investigate what matters
UK analysts assess suspicious activity in context.
Respond and improve
Act under agreed procedures and refine detection.

Resilien by Precursor Security
Delivered through our CREST-accredited UK SOC.
Your security operations.
Delivered by Resilien.
Give your IT team specialist security operations support around the clock.
Managed SOC is the operational foundation. MDR is the investigation and response capability within it. One UK team, with a scope built around your organisation.
From £900/month
Your quote confirms the users, endpoints, log sources, licensing and response actions in scope before the service begins.
Get your Resilien quoteWhat’s included in Resilien?
- The core service
- 24/7 monitoring of your agreed environment, human-led investigation, detection tuning, security reporting and response through documented procedures.
- Coverage agreed with you
- Your quote sets out the SIEM and EDR integrations, log sources, retention, threat hunting and response authority. Licensing and any additional costs are confirmed before onboarding.
- Optional extensions
- Extend your coverage with vulnerability management, EdgeProtect attack surface monitoring, penetration testing or a specialist incident response retainer.
- Your team’s role
- You provide access, name escalation contacts and approve response permissions. Your IT team retains infrastructure ownership and works with us on remediation and recovery.
What is a
Managed SOC?
Outsourced 24/7 security operations: UK-based human analysts watching your SIEM, endpoint, and cloud telemetry on rotating shifts from a physical facility in Newcastle.
A managed SOC (also outsourced SOC or SOC as a Service) is a contracted 24/7 security operations centre.
Human analysts monitor your environment in shifts, correlate signals across SIEM, EDR and identity telemetry, investigate alerts, and take authorised containment actions when a threat is confirmed.
Resilien brings monitoring, investigation and agreed response into a single service scope, so you get the capability of an in-house SOC without the headcount.
The six service pillars
SIEM & log correlation
Managed EDR
Threat hunting (scoped)
Incident response
Compliance reporting
Attack surface monitoring (optional)
Standards and methodology
Methodology is aligned to the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover), MITRE ATT&CK for detection engineering, and the SOC-CMM maturity model.
Monitoring records and service reports can support your organisation’s security assurance work. The service does not, by itself, establish compliance or certification.
New to this? Our guide to what a managed SOC is explains the essentials.
Our SOC operates against the canonical frameworks UK regulators, insurers, and procurement teams reference.
Adjacent decisions UK buyers weigh alongside a Managed SOC.
MDR vs SOC vs SIEM
Plain-English comparison of the three terms procurement teams confuse most often.
See comparisonSOC as a Service
How users, endpoints, log sources and service scope shape a managed SOC quote.
See SOCaaSOutsourced SOC
Why most UK orgs land on outsourced rather than building in-house: staffing, shift coverage, tooling and ongoing management.
See outsourced SOCBest Managed SOC Providers UK
Seven UK managed SOC providers compared on SOC location, 24/7 staffing, and pricing.
See the comparisonSOC as a Service: Human analysts watching your environment 24/7.
Your IT team keeps the business running. Resilien adds dedicated security monitoring and investigation from our Newcastle SOC, including nights, weekends and public holidays. Analysts assess suspicious activity and involve your team through agreed escalation procedures.
Discuss your coverageWhat Resilien Managed
SOC Covers.
Build your Resilien coverage around your environment. Our UK analysts monitor and investigate your agreed data sources, with threat hunting and attack surface monitoring scoped to your requirements.
See connected signals, not isolated alerts
We connect agreed security log sources, including Microsoft 365, firewalls, workstations, and cloud platforms. Our cloud-native SIEM correlates events across the sources in your service scope, aligned to NCSC in-house SOC building guidance, while optional EdgeProtect continuously monitors your external attack surface for exposed services and compromised credentials.
Managed EDR
We deploy and manage Endpoint Detection & Response agents (Microsoft Defender, SentinelOne, CrowdStrike) to stop ransomware at the process level. Analysts investigate suspicious endpoint activity and take authorised action under your response plan.
Threat hunting, scoped to your needs
We apply our Offensive Security roots (CREST) to plan hunts around relevant techniques in the MITRE ATT&CK Enterprise matrix, surfacing enablers of compromise that automated tools miss: dormant lateral movement paths, misconfigured Conditional Access policies, and overprivileged service accounts waiting to be exploited. Our analysts are trained against the SANS threat hunting roadmap.
Priority investigation for critical alerts
Critical alerts are prioritised for human investigation. Your service agreement sets investigation targets and notification arrangements, so your team knows how and when it will be contacted.
EdgeProtect ASM (Optional)
Continuous monitoring of your external attack surface: exposed services, vulnerable software versions, subdomain takeover risks, and compromised credentials on dark web markets. Findings feed directly into SOC detection rules for closed-loop protection.
See what happened and what happens next
Monthly service review calls, audit-ready event logs with agreed retention, and documented SLA performance. Supports evidence for ISO 27001 A.8.16, NIS2 continuous monitoring, and DORA operational resilience requirements.
Advantage of Precursor SOC
An in-house SOC requires people, technology and ongoing management. Resilien provides an agreed managed service around your environment. See the full managed SOC cost breakdown.
Access a UK analyst team without recruiting and managing your own SOC rota. Compare costs against the coverage and tooling included in your quote.
Your onboarding plan separates first telemetry, live monitoring and baseline tuning.
We manage the agreed security tooling. Your quote confirms licensing, integrations and ongoing costs; your team retains ownership of its infrastructure.
Controls
The Precursor Advantage.
A physical UK facility with dedicated analysts, combined with offensive security integration that strengthens your defences every day.
See the SOC.
Visit our analyst floor in Newcastle. See the screens, meet the team, and watch a live threat hunt in progress. We run tours for procurement teams, CISOs, and board members. No sales pitch. Just evidence.
Book a SOC TourThe Closed-Loop Advantage.
Our penetration testers use live SOC threat intelligence to test your defences against active attack patterns. This continuous loop between offensive and defensive operations means your security posture strengthens every single day.
We work with your existing stack.
Keep supported SIEM, EDR and cloud platforms. We confirm connectors, access and licensing requirements before onboarding.
Microsoft Sentinel
Microsoft Defender
CrowdStrike Falcon
SentinelOne
Elastic Security
Azure / Entra ID
AWS CloudTrail
Cloudflare
Resilien Managed SOC Pricing
Resilien starts from £900/month. We scope your users, endpoints, log sources and response requirements in a free 30-minute call, then confirm a fixed monthly quote including licensing and service options.
Fully Managed SOC
Turnkey Operations24/7 monitoring, investigation and agreed response across your in-scope endpoints, identities, cloud and network. Your quote confirms integrations, reporting and service options.
Hybrid Cloud SOC
Targeted CoverageTargeted monitoring for specific assets (AWS/Azure environment, OT/IoT networks) or specific compliance requirements such as PCI-DSS or NIS2.
Getting Started with Resilien
Four stages from scoping to live monitoring, with dates agreed around your integrations and access requirements.
Scoping & Contract
30-minute scoping call to assess your log sources, user count, and existing tooling. Fixed monthly price confirmed before work begins.
Connector Deployment
Lightweight agents and API integrations deployed to your Microsoft 365, Azure, firewall, and EDR platform. Deployment dates are agreed in your onboarding plan.
Baseline & Tuning
We establish normal activity and tune Resilien detection rules to reduce false positives. Coverage is refined as telemetry comes online.
24/7 Monitoring Live
Full 24/7/365 monitoring active. Monthly service review calls, quarterly threat reviews, and continuous detection engineering.
Your Resilien Service Specification
Your proposal documents the capabilities below for your agreed environment. Service options and response permissions are confirmed before onboarding.
Your Resilien service is delivered through Precursor’s CREST-accredited SOC. Your quote confirms threat intelligence, hunting, reporting and response commitments for your environment.
Strengthen Defences.
Test What You Protect.
Your SOC detects threats. Our penetration testers validate whether those defences hold. We feed pentest findings directly back into SOC detection rules, building custom alerts for your specific attack surface. This is the closed-loop advantage.
Explore Penetration TestingPenetration Testing
Validate your SOC detections with manual exploitation by CREST-accredited testers.
Red Team Operations
Full-scope adversarial simulation to test your SOC team under realistic attack conditions.
EdgeProtect ASM
Optional external attack surface monitoring, scoped alongside your Resilien service.
Configuration Reviews
Harden the infrastructure your SOC monitors with expert configuration assessment.
SIEM vs MDR vs XDR vs SOC
Four overlapping terms that buyers often treat as interchangeable. The distinction matters, because each has a different scope, cost envelope, and operational role. For the full five-way breakdown including EDR, see our MDR vs SOC vs SIEM vs EDR vs XDR buyer's guide.
| Dimension | SIEM | MDR | XDR | SOC |
|---|---|---|---|---|
| Primary focus | Log collection, correlation, alerting | Outsourced investigation and threat response | Integrated detection across endpoint, email, cloud, identity | People, process, and tools combined for monitor→alert→respond |
| What it is | A platform | A service | A platform | A capability (people + tech + process) |
| Action vs alert | Capabilities depend on configuration and integrations | Investigate and respond within agreed permissions | Alert + automated/semi-automated response | Full operational loop, end-to-end |
| Coverage scope | Any log source you connect | Agreed endpoint, identity, network and cloud sources | Vendor ecosystem (single-stack) | Agreed sources and integrations |
| Cost factors | Licensing, ingestion and retention | Coverage, integrations and response scope | Vendor licensing and deployment scope | Resilien from £900/month; in-house costs depend on staffing and tooling |
| Ideal for | Teams that want visibility but retain response | Orgs needing outsourced 24/7 response | Single-vendor-committed estates | Orgs that want the full managed capability without building it |
Precursor's Managed SOC includes SIEM (Microsoft Sentinel or Elastic), MDR-grade endpoint monitoring, and XDR-style cross-layer correlation within one CREST-accredited UK service, so you don't have to stitch the categories together yourself. For the investigation and response capability, see our managed detection and response service.
Deciding between detection technologies? These side-by-side comparisons explain the differences and where each fits.
Plain-English definitions of the concepts behind this service, from our security glossary.
Build Your Resilien Managed SOC Service.
Tell us about your environment and the support your team needs. We will contact you to discuss coverage, licensing and response permissions, then prepare your Resilien quote.
Resilien Managed SOC: Common Questions
Pricing, onboarding, coverage, and compliance.
Resilien is Precursor Security's managed security service, bringing together 24/7 UK-based monitoring, human-led investigation and agreed threat response. Precursor Security operates the service from its CREST-accredited Security Operations Centre in Newcastle. Resilien is the service brand, and Precursor is your security provider.
Managed SOC describes the broader security operations capability: monitoring, SIEM management, detection tuning and reporting. Managed detection and response (MDR) focuses on investigating and responding to threats. Resilien brings these capabilities together through one UK-based team, with coverage agreed around your environment and existing security tools.
From £900/month. Your quote confirms the users, endpoints, log sources, licensing and response actions in scope before the service begins. We also confirm the depth and frequency of threat hunting, log retention, reporting and any optional services. Analysts investigate confirmed threats and take containment actions under your agreed response procedures. Specialist forensics, recovery and incident response retainers are scoped separately where required.
A managed SOC is an outsourced 24/7 security operations centre: an external team of analysts who monitor your environment, investigate alerts, and contain threats on your behalf, without you building the capability in-house.
- Correlates agreed SIEM, endpoint, identity, cloud and network telemetry.
- Human analysts investigate around the clock and respond under agreed procedures.
- Delivered as a monthly service (from £900/month with Precursor), so you do not need to recruit and manage a SOC rota; tooling and licensing are agreed in your quote.
- Resilien combines 24/7 monitoring and human investigation with agreed integrations, threat hunting and response scope from one UK team.
Precursor's managed SOC runs from a physical, CREST-accredited facility in Newcastle with UK-based, DBS-checked analysts, and includes managed EDR alongside SIEM monitoring.
Critical alerts are prioritised for human investigation, 24/7/365. Investigation targets and escalation arrangements are documented in your service agreement.
- On confirmation, analysts contain the threat and isolate affected endpoints where authorised by your response plan, then preserve available evidence. Actions outside those permissions require your approval.
- Your named contacts receive notifications and investigation updates according to the agreed severity and escalation plan.
- Severity is handled in tiers: Critical (malware execution, active intrusion, data exfiltration) receives priority investigation; High (lateral movement, credential abuse) is prioritised ahead of routine monitoring.
Specific containment timelines are agreed in writing during scoping, based on your environment and service tier.
An MSSP manages a broad set of outsourced security products (firewalls, antivirus, VPNs); a managed SOC is specifically the 24/7 detection-and-response function, run by analysts who hunt and contain threats.
- MSSP is breadth: device and policy management across many tools, often with limited real-time human threat analysis.
- Managed SOC is depth: continuous monitoring, correlation, threat hunting, and human-led incident response focused on stopping attacks.
- A managed SOC can sit inside an MSSP relationship, but the SOC is the part that actually detects and responds to live threats.
A SIEM is the technology that collects and correlates security logs; a SOC is the people and process that use it. Investigation and response still need assigned people and procedures.
- SIEM: the platform (Microsoft Sentinel, Elastic) that ingests logs and raises alerts from correlation rules.
- SOC: the analyst team that tunes those rules, investigates the alerts 24/7, and responds to confirmed threats.
- A managed SOC includes SIEM management, so you get the platform, the tuning, and the human response as one service.
Resilien starts from £900/month. We review your users, endpoints, security tools and monitoring requirements, then provide a fixed quote showing coverage, licensing and service options.
Managed SOC describes the broader security operations function, including monitoring, SIEM management, detection tuning and reporting. MDR focuses on investigating and responding to threats across the telemetry in scope. Resilien brings these capabilities together.
- Resilien MDR can cover endpoints, identity, network and cloud telemetry, depending on the agreed integrations.
- Human involvement: our UK analysts investigate suspicious activity and respond under agreed procedures across both capabilities.
- Reporting output: monitoring records, investigation reports and agreed exports can support your wider assurance work; the service does not establish compliance on its own.
In practice the categories overlap. Precursor's managed SOC includes managed EDR alongside SIEM monitoring, so it covers both.
An in-house SOC requires staffing, shift cover, security tools, training and management. Resilien gives you access to a managed operation without recruiting your own SOC team. Compare the complete agreed service scope and licensing costs with the internal capability you would otherwise need to build.
We agree an onboarding schedule after reviewing your integrations and access requirements. Your plan distinguishes first telemetry connected, 24/7 monitoring live and baseline tuning complete; detection tuning continues as your environment changes.
Internal IT and a managed SOC do different jobs: IT keeps systems running; a SOC is trained and staffed specifically to detect and stop attackers, around the clock.
- Your IT team keeps infrastructure and business services running. Resilien adds dedicated monitoring and investigation capacity.
- Maintaining an internal 24/7 rota requires staffing, holiday cover, training and management.
- Specialist SIEM, EDR and detection-engineering support complements the skills already in your team.
- Analysts investigate suspicious activity and use agreed escalation procedures to give your team clear next steps.
- Monitoring and reporting can support your security assurance needs; check the requirements of your own insurance policy.
Most organisations keep internal IT for administration and outsource threat detection to a specialist SOC.
Yes. Our Security Operations Centre is staffed 24/7/365 from our physical UK facility in Newcastle. We monitor your environment around the clock, including weekends and public holidays. Every analyst is UK-based. We do not use follow-the-sun offshore models.
We specialise in Microsoft Sentinel and Elastic. We review additional log sources and connector requirements during scoping. For organisations without an existing SIEM, we can deploy and manage the platform as part of the service.
Critical alerts are prioritised for human investigation around the clock. Your service agreement sets investigation targets, notification arrangements and response permissions. Authorised containment follows your response plan; actions outside those permissions require your approval.
Yes. Precursor Security operates a physical UK-based Security Operations Centre in Newcastle. We do not use a follow-the-sun model with offshore analysts. Every analyst is UK-based and DBS-checked, operating through our CREST-accredited SOC, with no offshoring of work.