24/7 SIEM monitoring and notification
Use case development and tuning
Runbook development and maintenance
Deep dive analytics
Incident handling
Use case advanced tuning
Threat hunting
*Requires customer to provide SIEM or purchase a Lumen Managed SIEM Service.
Today’s organizations need 24/7 SIEM monitoring to detect suspicious incidents and intruders in their network; however, the required resources and effort to perform this in-house are cost prohibitive for most organizations. With Lumen Virtual SOC, our security expert team augments your threat and response strategy and provides 24/7 SIEM monitoring to help you improve your security posture and align with regulatory compliance requirements without the financial burden of insourced SOC units.
Lumen provides 24/7 SIEM monitoring and incident handling leveraging your SIEM platform. The service features include:
Virtual SOC is offered in three package options, with pricing based on maximum number of monthly incidents and packaged selected by the customer. Standard features vary based on the package selected.
Lumen Virtual SOC is available in three packages:
During the transition phase, Lumen security experts will work with you to collect the information required to develop the run book and identify critical use cases. Our security team will log in daily to your SIEM platform and monitor security events. Once an incident is identified, the SOC analyst classifies, triages and analyzes the event to validate if it is a false positive. True events are prioritized and notified to customers. Our SOC experts analyze logs to isolate incidents and provide deep-dive analytic analysis (trends analysis, threats, ticket mining, and lessons learned) and remediation recommendations that will enhance your response. Lumen can also offer proactive threat hunting (exclusive for the Premium package), where the expert reviews your system based on current trends outside of established use cases to discover anomalies related to current events.