
Q. What is the HDUK Cyber Security solution?
A. HDUK’s SOC/SIEM service is a 24/7/365 security monitoring solution that continuously
reviews activity across your organisation—your users, endpoints, servers, network devices,
and cloud systems—to identify suspicious or malicious behaviour.
It combines:
– Enterprise-grade SIEM technology to collect and correlate log data
– A dedicated Security Operations Centre (SOC) team who investigates
alerts, validate threats, and take appropriate action
This ensures threats are caught early, understood quickly, and escalated to you or HDUK
engineers when intervention is required.
Q. Why do we need SOC/SIEM if we already have antivirus?
A. Antivirus is essential—but today, on its own, it’s not enough.
– Antivirus blocks known malware.
– SIEM detects behavioural anomalies, unusual logins, insider threats, lateral
movement, and advanced attacks that antivirus often misses.
_ SOC analysts actively watch for and respond to threats in real time.
A simple analogy:
– Antivirus = locking the front door
– SIEM = security cameras and an alarm system
– SOC = trained professionals watching the cameras and responding
Q. What does the HDUK SOC/SIEM service monitor?
A. Our monitoring covers:
– User identities and behaviour (UEBA)
– Endpoints (desktops and laptops)
– Cloud services (Microsoft 365, Azure, and more)
Q. What happens when the SOC detects a threat?
A. All alerts are reviewed by trained analysts. Depending on the severity, actions may
include:
– Triggering MFA prompts
– Disabling compromised accounts
– Isolating infected or suspicious devices
– Escalating to HDUK engineers or your internal IT team
You receive clear communication on what was detected and what action was taken.
Q. Do you respond to incidents, or do you only notify us?
A. The SOC handles detection, investigation, and qualification of threats. Remediation (fixing
or recovering systems) is carried out by HDUK engineers, where required.
Q. How quickly are alerts handled?
A. Threats are triaged and prioritised by the SOC team:
– High priority threats: responded to immediately, 24/7/365.
– Lower priority issues: handled during business hours (07:00–18:00).
Q. How does SOC/SIEM help protect our organisation?
A. The service helps by:
– Detecting anomalies early
– Identifying indicators of compromise
– Enabling rapid response to attacks
– Providing complete visibility across your IT estate
This significantly reduces the risk of data breaches and security incidents.
Q. Does the SOC/SIEM service include UEBA (User and Entity Behaviour
Analytics)?
A. Yes. UEBA is built into the service and helps detect abnormal behaviour, even when no
malware is present—especially useful for spotting compromised accounts.
Q. Is the SOC team UK‑based?
A. The service is delivered by a certified European SOC team operating 24/7/365 with more
than 20 experienced analysts. They work from the events and alerts supplied by your
environment – only HDUK engineers have access to the environments themselves.
Q. What is included in the monthly cost?
A. Your subscription covers:
– SIEM log collection and monitoring
– 24/7 SOC analysis of alerts
– Threat escalation and incident guidance
– UEBA behavioural analytics
– Log ingestion and correlation across supported systems
Q. Are there any hidden costs?
A. Not for the base service. Additional charges may apply for:
– On-site remediation work
– Non-standard integrations
– Additional or specialised log sources outside the agreed scope
Q. What does the implementation process look like?
A. The onboarding is carried out in the background with no impact on your ability to use the
platform with no downtime required. Typical onboarding includes:
1. Adding customer to the portal to onboard into the service
2. Deployment of monitoring agent
3. Configuration of log sources
4. Initial monitoring and calibration to reduce false positives
5. Switch over to Live Mode
Q. How long does onboarding take?
A. The full onboarding process should take less than a day. The monitoring period is
typically two weeks which enables us to dial in the settings, reduce false positives and
establish work patterns after which the system is fully switched into Live Mode.
Q. How is HDUK’s SOC/SIEM service different from others?
A. We provide:
– A SOC service tailored for UK organisations
– Managed detection and response integrated across cloud and on-premise systems
– Behavioural analytics (UEBA)
– A fully staffed 24/7 SOC analyst team
– Support for compliance and governance requirements
Q. What happens if a threat occurs outside business hours?
A. The SOC responds immediately—day or night—to contain the threat, isolate devices, or
disable accounts as necessary. Out of hours, they are required to notify HDUK Senior Staff of
any serious threats that can immediately be investigated.
Q. Does SOC/SIEM replace cyber insurance, backups, or MFA?
A. No. SOC/SIEM complements other security measures. You should still maintain:
– Secure backups
– MFA enforcement
– User awareness training
– Cyber insurance
Q. What types of issues are most commonly detected?
A. Some frequent examples include:
– Compromised or brute-forced accounts
– Phishing attempts
– Lateral movement between devices
– Suspicious or anomalous behaviour
– Data Extraction
Q. What value does SOC/SIEM offer to directors and leadership teams?
A. The service provides:
– Reduced organisational risk
– Strong protection for financial and sensitive data
– Evidence for governance and compliance
– Peace of mind knowing threats are handled 24/7
Behind the technology and security that customers have come to know and trust with HDUK, it's our people that make the real difference. We take great pride in offering dedicated IT support for our customers by investing in specialists, that are experts in the tools you use every day. It's why we put people at the heart of our business.
We are dedicated to providing reliable, secure, industry-leading IT solutions to elevate your business, maximise your potential and create a Modern Workplace to be proud of.
Working remotely has never been so important, so join the 7,500 users who already trust HDUK with their hosted services.