
For many cybersecurity managers, outsourcing a Security Operations Center (SOC) sounds like the ideal solution.
The concept is simple: let an experienced SOC team monitor your environment 24×7, investigate security alerts, respond to incidents and provide the expertise needed to protect your organisation while your internal cybersecurity team focuses on strategic priorities.
But in reality, not every outsourced SOC experience ends well.
Some SOC providers detect an alert, investigate it, and then hand the problem back to the customer.
The customer is then expected to coordinate the response, determine what needs to be isolated, work with the IT team on remediation, investigate the root cause and eventually confirm that the threat has been eliminated.
At that point, the question becomes:
If my SOC provider is only telling me that there is a problem, who is actually doing the heavy lifting?
At UnThreats, we believe outsourcing your SOC should mean more than simply outsourcing monitoring.
UnThreats is a Managed Security Service Provider (MSSP) operating across Singapore and Malaysia, delivering MxDR (Managed Extended Detection and Response) services built around CrowdStrike technology.
Our vision is simple:
When a security incident happens, your SOC provider should take ownership of the heavy lifting and allowing your cybersecurity team to focus on understanding the situation and making informed decisions.
Instead of simply saying:
“We detected a threat. Please investigate.”
The experience should be:
“We detected the threat, investigated it, triaged the incident, contained it according to the agreed response playbook, eradicated the threat, supported remediation and hardening, and prepared a detailed report for your review.”
That is the UnThreats SOC dream.
An effective SOC should not stop at identifying suspicious activity.
At UnThreats, our approach is designed around an end-to-end incident management lifecycle:
1. Investigation
When an alert is generated, our SOC analysts perform detailed investigation and analysis to understand what happened.
We look beyond the individual alert to establish the context of the event, identify affected systems and determine whether the activity represents a genuine security threat.
The objective is not simply to generate another ticket.
The objective is to understand the incident.
2. Triage
Not every alert represents the same level of risk.
Our SOC prioritises incidents based on their severity, impact and potential business risk. This allows the appropriate response to be initiated without wasting valuable time on low-priority events.
The result is a more structured and efficient incident response process.
3. Isolation
Once an incident is confirmed, containment becomes critical.
Where the customer’s onboarding instructions and approved response playbooks permit it, UnThreats can support or execute isolation actions to contain the affected asset and prevent the threat from spreading further.
This is where an outsourced SOC can move beyond “monitor and notify” into genuine incident response.
4. Eradication
Containing the incident is only part of the job.
The next question is:
What caused the incident, and how do we remove the threat from its source?
UnThreats investigates the underlying cause and supports eradication activities to eliminate malicious artefacts, persistence mechanisms and other identified elements of the attack.
The objective is to ensure that the threat is not simply contained temporarily, but properly addressed.
5. Remediation & Hardening
Incident response should not end when the immediate threat disappears.
Every significant incident should provide an opportunity to strengthen the environment.
UnThreats supports remediation and hardening recommendations designed to restore affected systems, address security weaknesses and reduce the likelihood of recurrence.
This transforms an incident from simply being a problem to becoming an opportunity to improve the organisation’s security posture.
Imagine this scenario.
It is 2:00 AM.
Your organisation’s SOC detects suspicious activity.
Instead of receiving a notification saying:
“Critical alert detected. Please investigate.”
Your SOC provider is already working on the incident.
The SOC investigates the activity.
The incident is triaged.
Affected assets are identified.
Containment actions are performed according to the agreed playbook.
The threat is investigated and eradicated.
Remediation and hardening requirements are identified.
And when you start your working day, instead of spending hours trying to reconstruct what happened from multiple systems and teams, you receive a detailed incident report explaining:
You can then focus on what matters most:
understanding the security event, assessing the business impact and making the right decisions.
That is what outsourcing your SOC should feel like.
UnThreats does not believe that an MSSP should simply become another source of alerts and tickets for the customer’s cybersecurity team.
Our MxDR approach is designed to provide customers with a SOC capability that can take an incident through the security response lifecycle.
Powered by CrowdStrike technology, UnThreats combines security telemetry, detection, investigation and response capabilities with SOC expertise to provide customers with a more streamlined operational model.
The goal is simple:
Less alert chasing.
Less coordination.
Less manual heavy lifting.
More actionable outcomes.
For cybersecurity managers, this means the SOC becomes an extension of the security team rather than another team that needs to be managed.
Perhaps outsourcing your SOC does not always end well.
But it can.
The difference is in what you expect from your SOC provider.
If your expectation is simply:
Detect → Notify → Wait for Customer
then you may still have a significant amount of work waiting for you.
But if your expectation is:
Detect → Investigate → Triage → Isolate → Eradicate → Remediate → Harden → Report
then you are looking for something fundamentally different.
You are looking for an end-to-end SOC partner.
At UnThreats, that is the dream we are working to make real.
Let your SOC provider do the heavy lifting.
Let your cybersecurity team focus on the bigger picture.
And when the incident is over, let the detailed report tell you exactly what happened.
UnThreats provides MxDR services across Singapore, Malaysia and the rest of the world, built around CrowdStrike technology and delivered through our SOC operations.
Because your SOC should not just tell you that something happened.
It should help take care of what happens next.