Security operations centre
Someone watching your environment at 2am, and engineers who fix what they find.
Attacks often start outside business hours, when nobody is reading alerts. North Ark's security operations centre monitors your environment around the clock, contains threats as they happen and hands the cause to the same engineers who run your security tools.
Start with a Microsoft 365 security assessment
What is included
- Monitoring around the clock, including overnight, weekends and public holidays
- Alert triage and investigation in Microsoft Defender XDR and Microsoft Sentinel
- Containment actions agreed with you in advance, such as isolating a device, disabling an account or blocking a sender
- Escalation to your nominated contacts by severity, with a call for anything critical
- Detections engineered and tuned for your environment, so alerts are worth acting on
- Root causes fixed by North Ark engineers
- Threat hunting across your environment for signs that alerts missed
- A monthly report of incidents, response times, trends and the fixes made

Why one team for monitoring and engineering
When monitoring and engineering sit with different providers, alerts get closed and causes stay open. Our SOC analysts and engineers work from the same detections, runbooks and repository, so an alert at 2am becomes a permanent fix the next day.
How it runs
- Onboard: Defender and Sentinel connected, log sources reviewed and ingestion costs checked.
- Tune: detections adjusted to your environment and noisy alerts removed.
- Agree: severities, containment actions and escalation contacts written into your runbook.
- Monitor: alerts triaged and incidents worked around the clock.
- Improve: monthly review of incidents, detections and fixes.
Your obligations
Round-the-clock detection supports the reporting windows in the SOCI Act, APRA CPS 234 and the Notifiable Data Breaches scheme, and it is increasingly expected by cyber insurers. Incidents come with the evidence you need to decide on notification.
Questions buyers ask
Which tools does the SOC work with?
Microsoft Defender XDR and Microsoft Sentinel. If you don't run Sentinel yet, we design it with ingestion costs under control.
What will the SOC do without asking us?
Only the containment actions you approve in advance, such as isolating a device or disabling a compromised account. Everything else is escalated to your nominated contacts.
How quickly do you respond?
Response targets for each severity are written into your agreement, and critical incidents are escalated by phone.
Do we need Microsoft E5?
No. The SOC works with the Defender and Sentinel capabilities you have, and we show you where a licence change would close a gap.
How is it priced?
A fixed monthly fee based on the size of the environment and the log sources in scope, agreed for a 12-month term. Sentinel ingestion is billed by Microsoft.
Can it run on its own, without other managed services?
Yes. It can run on its own, or as part of Managed Microsoft 365 and security or full Managed Engineering.
Start a conversation
Put someone on watch overnight.
Tell us who watches your alerts today.
Talk to an Engineer