Back to Blog
Guides

Does Your SOC Produce Audit Evidence or Actually Stop the Attack

Two providers can both sell you a 24/7 SOC. One documents the attack, the other stops it. Here is how to tell which one you are paying for before something goes wrong.

By Mark Sullivan Aug 31, 2026 1 views
managed socincident responseransomwarenorth texas
Share:

Two security companies can sell you what looks like the same product. Both use the phrase "24/7 security operations center." Both show you a dashboard with a map of the world and red lines flying across it. Both quote a monthly number that lands somewhere between your accounting software and your commercial insurance. And on the day something actually goes wrong, one of them writes you a very thorough report and the other one stops the attack.

A security operations center, usually shortened to SOC, is a team of people whose entire job is to watch what happens on your computers and network and respond when something looks wrong. That is the definition every provider agrees on. The disagreement, and it is the one that costs businesses real money, is on the meaning of the word "respond." For some providers, responding means telling you. For others, it means acting. Those are two different products sold under one name, and almost nothing in a sales conversation makes the difference obvious.

The Two Jobs a Security Operations Center Can Do

The first job is producing evidence. A regulated business, a defense contractor, a medical billing company, a firm working through a client security questionnaire, needs to prove that it monitors its systems. It needs logs that go back a year, a report showing who looked at what and when, and an auditor to sign off. A SOC built for this job is very good at collection and documentation. If your problem is that a customer will not sign a contract until you can demonstrate monitoring, this is a genuinely useful product and you should buy it.

The second job is stopping an attack while it is happening. That means a human being with authority looks at an alert at two in the morning, decides it is real, and takes an action that interrupts the attacker before the damage spreads. Isolating a laptop from the network. Disabling an account that is being used to move through your file server. Blocking a connection to an outside server. Killing a process that is starting to encrypt files. The evidence still gets collected, but collection is not the point. Interruption is the point.

Most businesses assume they are buying the second one. Most businesses, when we go through their contract with them, discover they bought the first one. That is not because anyone lied. It is because the two products use identical vocabulary, and the buyer did not know there were two products.

Why the Difference Only Shows Up at Two in the Morning

Ransomware is software that locks up your files and demands payment to unlock them. What most owners do not know is how compressed the timeline has become. The gap between an attacker getting a foothold and files starting to encrypt is frequently measured in hours now, and the encryption itself usually runs in the middle of the night on a weekend, because that is when nobody is watching.

Picture a 40 person distribution company in Plano. On a Saturday at 1:47 in the morning, an alert fires. A user account that belongs to a warehouse supervisor is authenticating to the file server from a machine that supervisor has never used, and it is copying directories in bulk.

Under the first kind of SOC, the alert is triaged, classified, and turned into a ticket with a severity rating. An email goes to the two contacts on file, and if the contract includes phone escalation, a call goes to the number on record. That number rings in an office that is closed. The owner sees the email at 7:30 Saturday morning. By then the encryption finished around 4:00 and the company is looking at Monday with no order system.

Under the second kind, here is what happens. The analyst on shift sees the same alert, confirms it in about six minutes, and disables the account and isolates the source machine without calling anyone first, because the contract signed months ago gave that analyst permission to do exactly that. The owner gets the email at 7:30 too. It says an intrusion was contained at 1:53 and here is what we did and here is what we need from you today. The business opens Monday.

Same alert. Same technology underneath. Same monthly invoice, roughly. The variable was not the tooling. It was whether a person had permission to act without waiting for one of your people to wake up. That is the entire difference, and it is invisible on a feature comparison sheet. We have written before about what the first 24 hours after an attack actually look like, and the pattern holds every time. The outcome is set in the first hour, not the first day.

Containment Authority Is a Contract Term, Not a Technology

Here is the part that surprises people. Whether your provider can stop an attack is not really a question of what software they run, because both kinds of SOC usually run comparable detection tools. The deciding factor is a clause in your agreement that says what the provider may do to your systems without asking first.

That clause is called pre-authorized containment, and it is a business decision, not a technical one. You are agreeing in advance that a stranger may take one of your machines off the network at three in the morning, possibly while an employee is using it, without calling you. That trade carries a real cost, because sometimes the analyst will be wrong and an executive loses a laptop for two hours during a legitimate late night session. Every owner I have walked through this says yes anyway, once they weigh two hours of one person being annoyed against two days of the whole company being down. But it deserves a deliberate answer rather than an assumption.

If your provider does not have that authority, they are not able to stop anything, no matter how good their detection is or how many analysts they employ. They can only tell you faster. Ask directly whether your current agreement grants it, and ask to see the sentence. Our own managed SOC is built around that authority, because monitoring without it is just a more expensive smoke alarm.

The Non-Regulated Business Gets Sold the Wrong Product

There is a reason the evidence-producing model dominates the market. It is easier to sell. Compliance has a deadline and a form. A controller can put "SOC 2 readiness" in a budget line and defend it, because a customer contract is waiting on it. SOC 2 is an audit framework that proves to your customers you handle their data responsibly. It is legitimate and worth doing when someone is actually asking for it, and compliance work is a real service we deliver.

The problem is what happens to the business nobody is auditing. A 30 person mechanical contractor in Frisco has no regulator, no framework deadline, and no customer questionnaire. Nothing forces the conversation. So that business either buys nothing, or it buys a monitoring product built around producing evidence for an audit it will never sit through, and pays for retention and reporting features it has no use for while getting no containment at all.

That business is the one that gets hurt worst. It runs its billing, its job costing, its drawings, and its payroll on a handful of servers, and it has no in house IT department, which means the person who notices the problem at 2:00 in the morning is nobody. Attackers do not select targets by whether they are regulated. They select by whether the door opens. Businesses across McKinney, Plano, and Frisco fit this description exactly, and the market has largely not built a product for them.

The Questions That Separate the Two Kinds of Provider

When you are on a call with a provider, the useful questions are not about technology. Ask them what actions they are permitted to take on your systems at three in the morning without reaching you first, and ask them to point to where that is written. A provider selling containment will answer immediately, because it is a standard clause they negotiate constantly. A provider selling evidence will start explaining escalation procedures, which is the answer to a different question, and that hesitation is your answer.

Ask what happens when nobody picks up the phone. Every provider has an escalation tree, so ask what the last step is. If the last step is "continue attempting contact," the process terminates at your voicemail, and the attacker keeps working while it does.

Ask whether the response time they quoted is for security or for the help desk. This is the single most common source of confusion in this market, and it is usually not deceptive, it is just two numbers living on the same web page. A three minute answer time for a password reset ticket is a help desk measurement. It says nothing about how long it takes someone qualified to look at an intrusion alert on a Sunday. Ask for the security number specifically, and ask what event starts the clock and what event stops it.

Ask who is actually on shift overnight, and whether that is an employee of the company you are signing with or a subcontracted service. Neither answer disqualifies anyone. Not knowing the answer disqualifies you from evaluating the price.

Ask how they handle the mistake case. A provider with real containment authority has isolated a machine wrongly at some point, because that is what happens when people make fast decisions with incomplete information. Ask how long a wrongly isolated machine stays offline. A provider who says it has never happened is probably not containing anything.

Finally, ask what they do with what they find. Detection and containment handle the emergency, but the recurring problem is usually structural, an account that should have been disabled months ago, a server exposed to the internet that nobody remembered, credentials from an old breach still being reused. That work belongs to security engineering and advisory support, and it is the piece most businesses skip because it does not fit neatly into a monitoring subscription. Our CyberSphere platform applies the same idea to what is exposed on your perimeter, and dark web monitoring covers credentials already circulating without your knowledge.

What This Actually Costs You to Get Wrong

Translate all of this into the numbers your bookkeeper cares about. A distribution business with 40 people down for two days is not just two days of revenue. It is overtime to catch up, late deliveries that cost you a customer relationship you spent six years building, and a forensic engagement running into five figures because your cyber insurance carrier requires an approved firm to determine what data left the building.

That last one deserves attention. Your carrier is going to ask what controls you had in place. If your application said you had 24/7 monitoring and what you actually had was an email notification service, you are now in a conversation about whether the policy responds. Carriers have gotten specific about this, and "we had a SOC" is no longer a sufficient answer on a claim form. What they want to know is what the SOC was contractually able to do.

Then there is notification. Depending on what data was touched and where your customers live, you may be legally required to tell people, which means a lawyer, a mailing, and a public record of the event. Backup and recovery determines how fast you come back. Containment determines how much you have to disclose at all, because an attack stopped at 1:53 in the morning may have touched nothing that triggers a notification duty.

For businesses that already have an IT provider they are happy with, none of this requires firing anyone. A general IT company keeping your systems running and a security team watching for intrusions are different jobs with different staffing, and they work well side by side. That arrangement is what MSP integration is, and it is frequently the cleanest path for a business that likes its current help desk but has realized nobody is actually watching for attackers. We covered why those two functions are not interchangeable in our piece on the gap between uptime monitoring and intrusion detection.

One more thing worth saying plainly. Email security is not a separate topic from this one. The alert your SOC triages at 2:00 in the morning usually traces back to a message somebody opened at 4:00 the previous afternoon.

Where to Start

You do not need to change providers to answer the question in this article. Pull your current agreement and look for language about what your provider may do to your systems without your approval. If what you find covers only notification and escalation, you now know exactly what you are paying for.

If you would rather have someone go through it with you, we will do that at no charge. Start with a security assessment to see what is actually exposed, or reach us through /contact or at 512-518-4408. We are based in McKinney and work with businesses across Collin County, Allen, Plano, Frisco, and the wider DFW area. The conversation takes about 30 minutes, and you will leave it knowing which of the two products you are buying.

Frequently Asked Questions

What is the difference between a SOC that monitors and a SOC that responds?

A monitoring SOC detects suspicious activity and notifies you, which means your business is protected only as fast as your team can be reached and act. A responding SOC has written permission to take action on your systems, such as disabling an account or isolating a machine, without waiting for you. The technology is often similar. The difference is contractual authority, and it determines whether an attack at 2:00 in the morning is contained or simply documented.

Does my business need a SOC if we are not regulated?

Yes, and arguably more so. Regulated businesses are pushed into monitoring by an audit deadline, which means the topic at least comes up. A non-regulated business has nothing forcing the conversation, so it often has no coverage at all while running its entire operation on a few servers. Attackers select targets by whether the door opens, not by whether an auditor is watching.

How do I know if my current provider can actually stop an attack?

Ask them what they are permitted to do to your systems at three in the morning without reaching you first, and ask to see that sentence in your agreement. If the answer describes escalation procedures and contact attempts rather than actions, they can alert you but they cannot contain anything. Also confirm whether any response time they have quoted applies to security incidents or to routine help desk tickets, because those are different numbers.

Will pre-authorized containment disrupt my employees?

Occasionally, yes. An analyst working with incomplete information at three in the morning will sometimes isolate a machine that turns out to be doing something legitimate, and that employee loses access until it is reviewed, usually a matter of hours at most. Weigh that against the alternative, which is a full company outage lasting days. Ask any provider how often it happens to them and how quickly a wrongly isolated machine is restored.

Can we keep our current IT company and still add security monitoring?

Yes, and that is the most common arrangement we set up. Keeping systems running and hunting for intruders require different people with different training, and there is no requirement that one company do both. Your existing IT provider continues handling support and infrastructure while a security team handles detection and response, with a defined handoff between them so nothing falls in the gap.

Need Help With This?

Innovation Network Design helps businesses across McKinney, Dallas, and nationwide with expert cybersecurity services.

M

Mark Sullivan

Innovation Network Design

With nearly a decade in cybersecurity and IT infrastructure, our team delivers expert insights to help businesses in McKinney, Dallas, and across DFW make informed security decisions. Have a question? Get in touch.

Ready to Secure Your Business?

Get a free security assessment and find out where your organization stands.