
Cybersecurity is not simply about having more security tools. It is about how effectively those tools, people and processes work together when a real threat occurs.
For many organisations, engaging a Managed Security Service Provider (MSSP) is an effective way to gain access to a 24×7 Security Operations Centre (SOC), security expertise and advanced threat detection capabilities without having to build and operate a SOC internally.
However, not every MSSP operates in the same way.
At UnThreats, we have deliberately taken a different approach.
As an MSSP operating across Singapore and Malaysia, UnThreats provides Managed Extended Detection and Response (MxDR) services built around CrowdStrike technology. At the heart of our SOC is a simple principle:
One SOC. One SIEM platform. One operating model. One mission — better security outcomes for every customer.
The Traditional MSSP Approach: More Platforms, More Complexity
The MSSP market is highly competitive. Customers have different technology environments, existing investments and security requirements. As a result, many MSSPs support multiple SIEM platforms to accommodate different customer preferences and win more business.
On paper, this appears to provide flexibility.
A customer can choose the SIEM they already use, or select a platform that fits their requirements.
However, there is an operational trade-off.
When a SOC operates multiple SIEM platforms, analysts may need to work across different technologies, interfaces, detection mechanisms, query languages, data models and operational processes.
Instead of having one consistent operating model, the SOC becomes a collection of different operating environments.
This can create:
The issue is not that multiple SIEM platforms are inherently insecure.
The issue is operational efficiency and consistency at scale.
In cybersecurity, complexity can become an enemy of speed.
And when an organisation is under attack, speed matters.
UnThreats has chosen a different model.
Rather than operating multiple SIEM platforms within our SOC, UnThreats standardises on CrowdStrike NG-SIEM as our SOC’s core SIEM platform.
This is a deliberate operational decision.
Our objective is not to sell customers as many security products as possible.
Our objective is to deliver effective security operations and real protection.
By operating a common NG-SIEM platform across our MxDR customers, our SOC analysts work within a consistent technology and operational environment.
This allows UnThreats to build deeper expertise in the platform, continuously improve our detection engineering and optimise our SOC processes around a single operating model.
Every security operations team needs to understand its tools deeply.
With one primary SIEM platform, our analysts become highly familiar with:
Instead of constantly switching between different SIEM technologies, our SOC team can focus on what matters most:
detecting, investigating and responding to threats.
This is the philosophy behind the UnThreats SOC.
One of the significant advantages of standardisation is the ability to reuse security knowledge.
Suppose UnThreats develops a new detection use case for Customer A.
The use case may have been created because of a specific threat observed in Customer A’s environment, a new attack technique identified by our threat intelligence team, or a broader threat emerging globally.
If the use case is applicable to other customers, we can evaluate and redeploy it across the relevant MxDR environments.
This creates a force multiplier.
Instead of solving the same security problem independently for every customer, our SOC can develop the detection once and apply it where relevant.
For example:
Threat identified → Detection use case developed → Validated by UnThreats SOC → Applicable customers identified → Detection deployed → Continuous tuning
This means that improvements made within the UnThreats SOC can potentially benefit multiple customers.
That is one of the key values of operating a standardised MxDR platform.
The same principle becomes even more powerful when it comes to threat hunting.
Threat hunting should not always be viewed as an isolated activity performed only for one customer.
Imagine our threat intelligence team identifies a new adversary technique that could affect organisations across Singapore and Malaysia.
Or imagine Customer A experiences a suspicious behaviour that suggests a previously unknown attack technique.
The UnThreats SOC can initiate a threat hunt based on that intelligence and assess its relevance across the broader MxDR environment.
Because our customers operate under the same UnThreats SOC and NG-SIEM operating model, our analysts can apply the relevant hunting methodology across the customer base.
The result is a simple but powerful concept:
A threat hunt may originate from:
When applicable, the resulting hunting methodology can be extended across the UnThreats MxDR environment.
This provides an additional layer of collective security intelligence for our customers.
This is where the UnThreats model becomes particularly valuable.
Consider two different approaches.
Customer A → SIEM Platform 1
Customer B → SIEM Platform 2
Customer C → SIEM Platform 3
Customer D → SIEM Platform 4
A new threat is identified.
The SOC must determine:
Customer A
Customer B
Customer C
Customer D
↓
UnThreats NG-SIEM
↓
Common SOC Operating Model
↓
Common Detection & Threat Hunting Capability
A new threat is identified.
Our team develops the appropriate detection or hunting methodology and can evaluate its applicability across the MxDR customer environment.
This does not mean every customer receives identical detection rules regardless of their environment. Security use cases still need to be relevant to the customer’s technology, risk profile and available telemetry.
The difference is that the underlying operational capability is standardised, allowing UnThreats to scale security expertise more efficiently.
It is important to clarify that choosing one SIEM platform does not mean every customer has the same IT environment.
Our customers can have different:
UnThreats MxDR is designed to work with these different environments while maintaining a common SOC operating model.
The standardisation happens where it creates the most operational value:
inside the SOC.
Customer-specific requirements can still be addressed through appropriate integrations, data sources, detection rules and response procedures.
The platform is standardised.
The security service remains tailored.
UnThreats builds its MxDR service around CrowdStrike technology, combining the strength of CrowdStrike Falcon telemetry with NG-SIEM and our SOC expertise.
CrowdStrike provides the technology foundation.
UnThreats provides the operational layer around it.
This includes capabilities such as:
The objective is not simply to generate alerts.
An alert by itself is not protection.
The real value comes from understanding what happened, why it happened, how serious it is, what else may be affected, and what needs to be done next.
From Alert Management to Security Outcomes
A traditional alert-centric SOC can become overwhelmed by the volume of alerts generated by multiple security technologies.
More tools can mean more alerts.
More alerts can mean more noise.
More noise can mean analysts spend more time determining what deserves attention.
UnThreats takes a different view.
We believe a modern MxDR service should focus on security outcomes rather than security tool count.
Our approach is therefore centred on:
Telemetry → Detection → Context → Investigation → Threat Hunting → Response → Remediation
The goal is to move beyond simply telling customers:
“We detected an alert.”
Instead, we want to provide:
“We identified a security event, investigated the context, determined the potential impact and provided actionable recommendations for remediation.”
That is the difference between alert management and security operations.
Cybersecurity operations are ultimately performed by people.
Even with advanced automation and artificial intelligence, skilled analysts still need to investigate complex incidents, understand attacker behaviour and make security decisions.
Therefore, the SOC itself needs to be efficient.
By focusing on one primary SIEM platform, UnThreats can concentrate its SOC expertise rather than spreading that expertise across multiple platforms.
This creates several potential advantages:
Deeper platform expertise
Our SOC team focuses extensively on NG-SIEM rather than maintaining expertise across numerous SIEM technologies.
Faster use-case development
New detections can be developed within a common platform and operating model.
Better knowledge sharing
Lessons learned from one investigation can be evaluated for applicability across other customers.
More efficient threat hunting
Threat-hunting methodologies can be developed and potentially extended across the MxDR environment.
Consistent operations
Analysts follow a common operational methodology rather than switching between fundamentally different SOC platforms.
Continuous improvement
Improvements to processes, detections and workflows can be evaluated systematically across the service.
Supporting multiple SIEM platforms can certainly be a valid business model.
For some MSSPs, platform flexibility is an important part of their service proposition.
UnThreats has simply chosen a different priority.
We believe that operational efficiency, security effectiveness and real protection should come before platform variety.
We do not want to compete by saying:
“We support every SIEM.”
We want to compete by saying:
“We know our platform deeply, we know how to operate it effectively, and we use that expertise to protect our MxDR customers.”
That distinction is important.
Our strategy is not to maximise the number of security platforms inside our SOC.
It is to maximise the effectiveness of the security operations we provide.
The UnThreats approach can be summarised simply:
One Platform
CrowdStrike NG-SIEM forms the core SIEM platform within the UnThreats SOC.
One Operating Model
Our analysts work within a consistent SOC process and methodology.
One Knowledge Base
Detection engineering, threat intelligence and lessons learned can be continuously improved.
One Threat-Hunting Capability
Relevant intelligence and hunting methodologies can potentially be extended across the MxDR customer environment.
One Mission
Deliver better security outcomes and real protection for our customers.
At UnThreats, we believe an MSSP should not simply become another source of security alerts.
A modern MxDR provider should help customers reduce risk.
That requires technology, people, processes and operational discipline working together.
Our decision to focus the UnThreats SOC around CrowdStrike NG-SIEM is therefore not a limitation.
It is our strategy.
By deliberately standardising our SOC platform, we can focus our expertise, streamline our operations, accelerate the development of security use cases and create opportunities for security intelligence generated from one customer or threat intelligence source to benefit other customers where applicable.
This is the operational advantage we want to bring to organisations in Singapore, Malaysia and worldwide.
UnThreats MxDR is not about having more security platforms.
It is about making the security operation work better.
Better efficiency. Better detection. Better threat hunting. Better context. Better response.
And ultimately:
Real protection, delivered through a SOC built around one platform and one mission.