What’s Included
Managed Solution will provide managed security incident and event management (“SIEM”) services utilizing the ConnectWise SIEM Pro platform to continuously monitor, collect logs, analyze, aggregate, and correlate security events across Client’s IT environment. The ConnectWise SOC monitors the SIEM environment 24/7 for suspicious conditions and escalates alerts to our security team.
Managed Solution’s security team, trained and familiar with Client’s unique environment and business processes, investigates escalated alerts prior to notifying Client. Services include:
-
Relevant security event logs and alerts from Client’s environment—including firewalls, intrusion detection systems, servers, endpoints, Microsoft 365, cloud and SaaS platforms, identity and access management systems, network devices, and other critical infrastructure—will be continuously collected and ingested into the SIEM platform for analysis and correlation. The Pro platform supports direct integrations and advanced ingestion methods, enabling broader coverage and richer telemetry. The SIEM platform applies advanced correlation, behavioral analytics, threat intelligence, and contextual filtering to detect indicators of compromise and generate alerts when potential threats are identified.
-
ConnectWise SOC analysts continuously monitor, review, and triage SIEM alerts at all hours. Alerts suggesting a potential or active security incident are escalated to Managed Solution’s security team for in‑depth investigation.
-
Upon receipt of an escalated SIEM alert, Consultant’s security team performs comprehensive analysis to confirm whether a security incident is occurring. This may include deep log review, cross‑source correlation, forensic analysis, and assessment of endpoint and cloud activity. If a true incident is confirmed, we will promptly notify Client and, where authorized, may take direct action to contain or mitigate the threat, including actions such as disabling compromised accounts, isolating affected endpoints, or blocking malicious network traffic.
-
Managed Solution will provide Client with periodic reports (e.g., monthly) summarizing security events observed and handled through the SIEM Pro service. Reports may include alert metrics, incident summaries and outcomes, trend analysis, and strategic recommendations for tuning detections, improving controls, and strengthening Client’s overall security posture.
-
Note: The Pro tier includes the full suite of endpoint protection and response capabilities – malware and ransomware defense, host isolation, memory threat protection, malicious behavior protection, and attack surface reduction. Microsoft 365 integration supports automated response and containment actions. All native integrations, including SaaS platforms, network devices, and IDS/network traffic, are supported directly without requiring custom connections.