Frequently asked questions
FAQ : Managed SOC
Answers to questions from a CISO or CTO in the evaluation phase. Each answer describes what exists, not what is planned.
Data collection and processing
How are logs collected?
Lightweight agents installed on your equipment collect security events and transmit them to the platform continuously. Each agent mutually authenticates with the platform by certificate: no collector communicates without presenting a certificate validated by our internal certificate authority. The transmission is end-to-end encrypted (TLS 1.3). In on-premises deployment mode, agents communicate directly with local nodes, with no outbound traffic to external systems.
What sources can you ingest?
Linux and Windows systems, network equipment (routers, switches, firewalls) via syslog, web applications, databases, messaging services, and cloud sources via API or forwarding. Any source capable of emitting structured or semi-structured logs is integrable. Sources outside common standards require a dedicated parser development. The list of natively supported sources is provided at scoping.
How are logs normalised and parsed?
At ingestion, each event is parsed to extract structured fields: timestamp, source host, event identifier, concerned user, IP address. Events are then enriched (geolocation by local processing, name resolution) and indexed in a common schema. Parsing quality directly determines detection relevance: a poorly parsed source creates blind spots in coverage.
What happens with a proprietary-format business application?
A dedicated parser is developed from a log sample provided during scoping. The timeline depends on the format complexity and the availability of technical documentation. Sources identified at scoping are included in the initial perimeter. Sources discovered after go-live are handled via a contract amendment.
How long are logs retained?
Default retention is 90 days online (queryable in real time) and 12 months in cold archive. Extended levels (24 months, 7 years) are available for organisations subject to specific regulatory requirements. The retention policy is documented in the contract and cannot be modified without bilateral agreement.
Can I query my own logs?
Yes. The client portal exposes a search interface across all your logs within the online retention window. Queries are strictly limited to your data: no cross-tenant visibility with another client's data is possible, including for a CyberAar analyst. An access API is available for integration with your internal tools.
What log volume is included, and what happens if it is exceeded?
The volume is defined contractually in compressed gigabytes per day. An alert mechanism triggers at 80% of the contractual threshold. In the event of persistent overrun, a pricing amendment is proposed. No data is lost or truncated without your explicit agreement.
Detection and alerting
Do you have native detection rules?
Yes. The platform includes a set of rules covering documented attack techniques: privilege escalation, lateral movement, persistence, data exfiltration. These rules are maintained and updated as new vulnerability publications and indicators of compromise emerge. A note is sent with each significant update to the rule set.
What framework are the rules aligned with?
Rules are aligned with the MITRE ATT&CK framework. Each alert references the corresponding technique and tactic, enabling rapid qualification and facilitating communication to your management or compliance teams.
Can I request rules specific to my industry?
Yes. Business-specific rules are developed from the use cases you identify: abnormal behaviour on your critical applications, out-of-hours access to sensitive systems, unusual transfer volumes. This development draws on logs already collected and does not require additional sources if the relevant data is already being ingested.
How are severity levels defined?
Four levels: informational, low, medium, critical. The classification combines the detected technique (MITRE ATT&CK reference), the criticality of the affected asset (defined at scoping with you), and known indicators of compromise. The same type of event may be raised at different levels depending on the context of the asset concerned.
How are triggering thresholds configured?
Thresholds are calibrated against your nominal behaviour during the burn-in phase (first weeks of deployment). They are reviewed quarterly and after each significant change in your environment. Every modification is tracked and documented in the service log.
Through what channels am I alerted?
Critical alerts trigger an immediate notification via the channels configured at onboarding: team messaging, webhook to your incident management tool, or direct notification to the designated point of contact. Channels are configurable and can target different teams depending on the nature of the alert. Medium and lower alerts are available in the portal and consolidated in periodic reports.
How do you handle false positives?
Every reported false positive is subject to a documented analysis. If the rule is too sensitive, the threshold is adjusted. If the behaviour is legitimate and recurring, a documented exception is created. The false positive rate per rule category is tracked monthly and presented in the service report.
What happens if an alert is not handled in time?
Critical alerts not acknowledged within the contractual deadline trigger automatic escalation and a notification to your designated point of contact. The escalation procedure, including delay thresholds and recipients, is defined contractually and tested during simulation exercises.
Day-to-day operations
Who handles my alerts?
Alerts are handled by dedicated analysts. Each client has a named analyst who knows your context, your critical assets, and your incident history. Qualification of critical alerts always involves a senior analyst.
What is your coverage schedule?
Our team is distributed across four time zones: Dakar (WAT), Casablanca (GMT+1), Paris (GMT+1/+2), Montreal (GMT-4/-5). This organisation provides effective coverage from 06:00 to 24:00 WAT on business days. Outside this window and at weekends, critical alerts trigger an on-call protocol with notification to the designated point of contact. We document what is actually covered rather than claiming uninterrupted monitoring.
What are your response time commitments?
Acknowledgement of a critical alert: 30 minutes. Initial qualification (true positive or false positive): 2 hours. Preliminary incident report: 4 hours after confirmation. These timelines are measured and reported in the monthly service report.
What do you actually do when an incident is confirmed?
We qualify the incident (scope, identified technique, affected assets), document the timeline, and transmit the identified indicators of compromise. We recommend containment actions appropriate to your context. If your organisation has an internal response team, we provide technical support; otherwise our teams can intervene directly as part of an incident response engagement.
Do you do incident response, or only detection?
Detection and incident qualification are included in the managed SOC service. Operational incident response (containment, eradication, remediation) can be activated as a separate engagement, billed independently. We take no action on your infrastructure without your explicit mandate.
What do I see in the client portal?
The portal displays the status of your open incidents, key service indicators (alert volume, handling times, false positive rate), report history, and the list of your monitored assets with their status. You can submit questions directly to your named analyst and follow exchanges within the interface.
In what format are reports delivered?
A weekly report summarises alerts handled, confirmed incidents, and detected trends. A monthly report covers service performance indicators and posture recommendations. Individual incident reports are available in the portal upon closure. All reports are exportable as PDF, in French and English.
Sovereignty and confidentiality
Where is my data hosted?
In shared deployment, data is hosted on servers in Europe (Helsinki, Finland) with a European infrastructure provider, with no transit through US or Asian cloud services. For organisations subject to data residency requirements, we offer a dedicated deployment in your infrastructure or with a provider of your choice, including on-premises in your own facilities.
Who at CyberAar can access my logs?
Access to client data is limited to analysts assigned to your perimeter and engineers responsible for platform operations. Every access is logged and auditable. No access is granted to commercial staff, third parties, or other teams without your explicit agreement.
Is my data isolated from other clients' data?
Yes. Isolation is enforced across three layers: transport (TLS 1.3 with mutual client certificates), storage (separate encryption keys per organisation), application layer (role-based access control, no cross-tenant visibility possible). An analyst assigned to one client has no technical access to any other client's data.
Do you use AI on my data, and where does it go?
Automated triage agents are under development. Before any algorithmic processing, technical identifiers (hostnames, accounts, internal IP addresses) are replaced by pseudonymised tokens; the mapping remains in local memory and is never transmitted. Running inference locally, without recourse to an external service, is our target for the production phase. Any output generated with algorithmic assistance is submitted for validation by a human analyst before delivery.
Are my incident reports protected?
Reports are encrypted at rest (AES-256) and in transit (TLS 1.3). Access is limited to the users you have authorised in the portal. Reports are never shared between clients or used for external aggregated analysis.
What happens if I terminate? Can I recover my data?
Upon termination, your logs and reports are returned to you in a standard exportable format (JSON, CSV depending on data type) within 30 days. After that period, all your data is deleted from our systems and a deletion certificate is sent to you.
Can I deploy the platform in my own infrastructure?
Yes. The platform is built entirely on open-source components deployable in your data centre or with the cloud provider of your choice. We offer deployment support, including installation, configuration, and skills transfer to your teams.
Continuity and vendor lock-in
You are a young company. What happens if you cease operations?
The platform is built entirely on open-source components. No proprietary licence conditions its operation. The underlying infrastructure can be taken over by any qualified third party. Your data remains yours and is recoverable at any time. Our orchestration layer and client portal are proprietary: a third party taking over would need to redevelop them. For shared deployments, we commit contractually to providing a complete image of your environment with 90 days' notice in the event of cessation of operations.
Am I locked into your solution?
No. Data is exportable at any time in standard formats. The platform relies on open protocols and non-proprietary formats. If you wish to migrate to another solution or internalise operations, we provide the necessary documentation and transition support.
What happens to my investment if I change provider?
You retain all your exported logs, reports, and configurations. Detection rules developed for your context belong to you and can be exported. In deployment within your infrastructure, the platform remains operational without our involvement.
Can I audit your platform?
Yes. The code of the underlying open-source components is public and auditable at any time. Our orchestration layer and client portal are not published. For the shared environment, we accept scoped technical audits on request, under conditions defined contractually. Our own information security management system is pursuing ISO/IEC 27001:2022 certification.
Deployment and integration
How long to become operational?
For a standard perimeter (Linux and Windows systems, common network equipment), the time to active monitoring is two to four weeks. This includes agent deployment, source configuration, the rule burn-in period, and validation of the first alerts with your teams. A perimeter involving proprietary applications or a hybrid cloud environment requires additional weeks, estimated at scoping.
What is the impact of agents on my servers?
CPU consumption is below 1% under nominal load. Memory footprint is below 100 MB. Agents operate in passive mode: they collect and transmit existing logs without modifying the configuration of monitored services. Load tests can be arranged in your qualification environment before any production deployment.
Does this replace my existing monitoring tool, or complement it?
Either scenario is possible. The platform can replace an existing monitoring tool or coexist with it, ingesting only the relevant events. The chosen configuration depends on your architecture and operational constraints; it is defined at scoping.
Can I keep my existing ticketing or monitoring tools?
Yes. Standard integrations allow the platform to connect to your existing incident management tool via webhook or API. Qualified alerts then feed directly into your ticket queue without double entry.
What do you need opened on my network?
Agents emit outbound connections to the platform on a dedicated port (TCP, TLS-encrypted). No inbound port is required on your equipment. For remote shared deployments, the precise list of destination IP addresses is provided in advance for configuring your outbound firewall rules.
How does onboarding support work?
The onboarding phase includes a technical scoping session (source inventory, critical asset definition, notification configuration), agent deployment with your teams, a burn-in period with daily analysis of initial alerts, and a validation checkpoint before entering normal monitoring mode. An operational reference document is handed over at the end of this phase.
Commercial and compliance
How do you charge?
Billing is monthly, based on the number of monitored assets and the contractualised log volume. There are no variable charges linked to the number of alerts or incidents handled in the month. The rate is established after scoping the perimeter and service level.
What is included in each service level?
Service levels are detailed on the managed SOC page. In summary: the base level covers monitoring, detection, and alerting. Higher levels add qualification by a dedicated analyst, specific business rule development, access to the advanced client portal, and incident response support.
How does the pilot programme work?
The pilot programme allows the platform to be deployed on a restricted perimeter for a fixed period. At the end of the pilot, a report documents the detections made, false positives encountered, and adjustments performed. This report serves as the basis for the decision on extended deployment. Pilot conditions (perimeter, duration, deliverables) are defined contractually.
Are you ISO 27001 certified?
Our information security management system is aligned with ISO/IEC 27001:2022 and the certification process is under way. We do not claim certification until it has been obtained.
Do you help address regulatory requirements in my sector?
Yes, within the scope of our role. The platform contributes to the traceability of security events, the preservation of evidence, and the detection of incidents — elements required by frameworks such as DORA, NIS 2, or local sectoral regulations. We document what the platform covers and what it does not, so you can integrate it correctly into your compliance file.
Do you sign a confidentiality agreement?
Yes. A non-disclosure agreement is signed before any sensitive information exchange and prior to any access to your data. The service contract includes specific confidentiality clauses covering log data.
A question is not on this list, or you need an answer tailored to your specific context: