Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
Detect, investigate, respond

Security Operations

The SOC side of the Fabric: SIEM, SOAR, sandboxing, email security, deception, network detection and response, and external attack-surface intelligence, the tooling that turns firewall logs into an actual investigation.

Where to start

Firewalls generate evidence; this section is what turns that evidence into an investigation. SIEM for correlation, SOAR for the response playbooks, sandboxing for files no signature has seen, plus email security, deception, network detection and external attack-surface intelligence.

The honest constraint on everything here is people. A SIEM nobody watches is an expensive log archive, and an EDR console nobody opens is not a control. Before sizing any of these, settle who is going to look at the output at three in the morning, and if the answer is nobody, buy it as a managed service instead. DynaScale runs a 24/7 SOC precisely because most organisations cannot staff one.

Sizing here is driven by peak, not average. A SIEM must not drop events during the incident that made you buy it, which is exactly when every device in the estate is logging hard. We size from a real log sample rather than a device count.

Decide these first

Who watches this, and when?

The most important question in this section and the one most often skipped. Twenty-four-hour coverage requires roughly five full-time analysts. If you do not have them, a managed service is the honest answer rather than a smaller appliance.

What is your PEAK events per second?

Not the average. Measure during a busy period with inspection logging enabled, because that is the load that matters and it is frequently an order of magnitude above the daily mean.

Do you have documented incident response to automate?

SOAR automates a process; it does not invent one. If your response is tribal knowledge, documenting it is the work to do first, and it is work we can help with before you buy the tool.

Can samples and logs leave your premises?

For regulated data this is usually settled for you, and it rules out cloud sandboxing and hosted analysis before capacity is discussed.

Browse security operations