Managed Security: ConnectWise SIEM

What’s Included

Managed Solution will provide managed security incident and event management (“SIEM”) services utilizing ConnectWise SIEM platforms to continuously monitor, collect logs, analyze, aggregate, and correlate security events across Client’s IT infrastructure. ConnectWise SOC monitors for suspicious conditions 24/7 and escalates alerts to our security team. Managed Solution’s security team, who is trained and familiar with Client’s unique environment and business processes, investigates escalated alerts prior to notifying Client.

Services include:

  • Relevant security event logs and alerts from Client’s environment, including logs from firewalls, intrusion detection systems, servers, cloud services, identity and access management systems, and other critical infrastructure will be continuously collected and fed into the SIEM platform for analysis and correlation. The SIEM platform, augmented by the ConnectWise
  • SOC’s expertise, will analyze incoming data for patterns or indicators of security incidents and generate alerts when potential threats meeting defined criteria are detected.
  • ConnectWise SOC analysts will review and triage SIEM alerts at all hours. Alerts indicative of a possible security incident will be escalated to our security team for further investigation.
  • Upon receiving an escalated SIEM alert, Managed Solution’s security team will perform in-depth analysis to confirm whether a security incident is occurring, which may include reviewing detailed log data, correlating events across multiple sources, and assessing the legitimacy of the threat. If a true incident is confirmed, we will promptly notify Client and may take direct action to contain or mitigate the threat (e.g., disabling a compromised user account or blocking a malicious IP address at the firewall).
  • Managed Solution will provide Client with periodic reports (e.g., monthly) summarizing security events observed and handled through the SIEM service, including alert volume and type statistics, details on notable incidents and their outcomes, and recommended changes to Client’s security controls or practices based on observed trends.