What’s Included
Managed Solution will provide managed security incident and event management (“SIEM”) services utilizing the ConnectWise SIEM Essentials platform to continuously monitor, collect logs, analyze, aggregate, and correlate security events across Client’s IT environment. The ConnectWise SOC monitors the SIEM environment 24/7 for suspicious conditions and escalates alerts that meet defined criteria to our security team. Managed Solution’s security team, trained and familiar with Client’s environment and business processes, investigates escalated alerts prior to notifying Client.
Services include:
- Relevant security event logs and alerts from Client’s environment, including firewalls, servers, Microsoft 365, identity and access management systems, and other supported infrastructure, will be continuously collected and ingested into the SIEM platform for analysis and correlation. Log ingestion is performed using supported agents and connectors, with additional sources integrated through custom connections where applicable. The SIEM platform performs baseline correlation and behavioral analysis, enhanced by threat intelligence and contextual filtering, and generates alerts when potential threats meeting defined thresholds are detected.
- ConnectWise SOC analysts continuously review and triage SIEM alerts generated by the Essentials platform. Alerts indicative of a potential security incident are escalated to our security team for further analysis.
- Upon receiving an escalated SIEM alert, our security team conducts an investigation to determine whether a security incident is occurring. This investigation may include reviewing relevant log data, correlating events across available data sources, and validating the legitimacy of the activity. If a confirmed incident is identified, Managed Solution will promptly notify Client and, where authorized, may assist with basic containment or mitigation actions such as disabling a compromised user account or blocking a malicious IP address.
- Managed Solution will provide Client with periodic reports (e.g., monthly) summarizing security events observed and handled through the SIEM Essentials service. Reports may include alert volumes and categories, summaries of notable incidents and outcomes, and recommendations for improving Client’s security posture based on observed trends.
- Note: The following capabilities are outside the scope of the Essentials tier and are not included – host isolation, memory threat protection, malicious behavior blocking, attack surface reduction, and automated response actions for Microsoft 365. Custom connections for SaaS applications, network devices, or non-native sources beyond those identified above may require additional scoping.