Damocles managed security

Know which alerts matter, what was investigated and what happens next.

Damocles Managed Security Operations combines source onboarding, source health, alert triage, investigation, escalation and reporting. The service records what data was available, what the analyst concluded, who owns the next action and which gaps remain open. Guardian gives the customer and provider one operational record of that work.

Synthetic Guardian Security Operations workspace showing source health, alerts, investigations and customer actions.
Synthetic Security Operations demonstration data using the Guardian business-workspace style. No customer information.
Source onboarding and healthAlert triage and investigationEscalation with clear ownershipGuardian actions and reporting
The customer problem

A monitoring platform full of events is not a security outcome.

Customers need to know whether the expected sources are reporting, which alerts were reviewed, what the analyst concluded, who must act and whether the response was completed. A specialist console alone rarely answers all of those questions for the customer.

Damocles defines the operating responsibility behind the selected compatible security technology. Aegis provides the managed monitoring and analyst service, while Guardian presents customer-scoped source health, alerts, investigations, actions and reports.

01

Know the data is arriving

Track expected agents, collectors and log sources so silence, delayed telemetry and zero-data conditions are visible instead of being mistaken for a quiet environment.

02

Separate material activity from noise

Use customer, asset, identity, vulnerability and source context to decide whether an alert is benign, suspicious, confirmed, unresolved or needs deeper investigation.

03

Drive an accountable response

Escalate a clear required action with ownership, timing, evidence, expected outcome and a defined path into containment, remediation or incident response when required.

Service coverage

The operational capabilities required to turn security technology into a managed service.

The service schedule defines the compatible connectors, customer scope, monitored sources, coverage window, investigation depth, escalation path and response responsibilities. Unsupported or missing data remains visible as a service condition.

ON

Source onboarding

Confirm approved collectors, agents, cloud, firewall, identity, endpoint, DNS, vulnerability and other security sources; map each source to the correct customer and expected operating state.

SH

Source and log health

Identify configured, reporting, delayed, zero-data, degraded and unavailable source states and distinguish a telemetry problem from an absence of security activity.

AT

Alert triage

Review alert context, affected assets and identities, known exposure, duplicate activity and customer-specific conditions before deciding whether an investigation is required.

IV

Investigation

Build a defensible record of the event using available telemetry, timeline, affected scope, related activity, evidence, analyst conclusion, disposition and remaining uncertainty.

ES

Escalation and coordination

Use agreed contacts, severity, service hours and response paths to move the issue to the customer, MSP, Damocles engineer or incident-response process that actually owns the next step.

RP

Operational reporting

Report monitored scope, source-health exceptions, material alerts, investigation outcomes, unresolved actions, recurring noise and service-improvement work.

Technical assurance

Validate the operating model behind security monitoring.

Review source health, triage, investigation and escalation workflows to identify telemetry gaps, inconsistent decisions and actions that may not reach accountable owners.

Source onboarding

Expected telemetry, ownership and usable context.

Ingestion health

Missing, delayed or malformed security data.

Detection workflow

How supported alerts enter triage and investigation.

Triage quality

Consistent priority, context and disposition decisions.

Investigation evidence

Timelines, artefacts and reasoning supporting conclusions.

Escalation and handoff

Triggers, authority and accountable customer actions.

Case lifecycle

Status, closure, exceptions and linked remediation.

Operational reporting

Source health, activity, outcomes and unresolved risk.

16governed test areas
4authorised testing perspectives
7controlled evidence outputs
1framework / control evidence mappings
What we actually test

Representative technical coverage with the evidence produced.

These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.

Jump to full coverage matrix ↓
Coverage area

Source onboarding

Damocles checks an expected telemetry source through ownership, collection method, parsing, event receipt and onboarding acceptance.

Evidence producedEvidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to source onboarding.
Framework references
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3
Coverage area

Source inventory

Damocles reconciles the customer-approved source inventory with platform entries, owners, expected event types and current status.

Evidence producedEvidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to source inventory.
Framework references
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3
Coverage area

Ingestion health

Damocles compares expected cadence with last-event time, transport state, parsing status and source-side health for sampled sources.

Evidence producedEvidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to ingestion health.
Framework references
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3
Coverage area

Telemetry gaps

Damocles identifies missing, delayed, filtered or unusable telemetry and records the affected detection and investigation use cases.

Evidence producedEvidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to telemetry gaps.
Framework references
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3
Coverage area

Detection content

Damocles reviews selected detection logic, data dependencies, scope, suppression, tuning history and known blind spots.

Evidence producedEvidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to detection content.
Framework references
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3
Coverage area

Alert triage

Damocles samples representative alerts and records enrichment, severity, disposition, timing and analyst rationale.

Evidence producedEvidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to alert triage.
Framework references
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Showing 6 representative areas. The full governed matrix contains 16 coverage areas.

Standards and assurance coverage

See how this engagement is structured, classified and mapped before opening the full evidence matrix.

References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.

01 · Test method

How testing is structured

Approved methodology, verification and testing guidance used to select and structure relevant procedures within the authorised scope.

Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3
02 · Finding language

How weaknesses and severity are classified

Findings are reported against the governed service coverage and customer impact. Separate classification references are shown only where they are part of the approved profile.

03 · Control evidence

What maps into compliance and assurance work

1governed evidence mapping across 1 approved framework, with framework-level context where exact controls are not claimed.
1 contextual
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Contextual
Framework-level context

Reviews sampled telemetry health, detection handling, alert triage, investigation evidence, escalation, action ownership, case closure and operational reporting within the managed-security-operations scope.

Jump to full control mapping ↓
04 · Evidence package

What the customer can use after the engagement

An operating-model review with source and workflow evidence, material gaps, prioritised actions and validation outcomes.

  • Authorised scope and rules of engagement
  • Coverage matrix
  • Retest and residual-risk record
  • + 4 additional controlled outputs

What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.

How we test

Manual validation backed by controlled evidence.

Damocles reconciles expected sources with ingestion health, samples detections and traces representative alerts through triage, investigation, escalation, customer action and closure. Operational records support service review but monitoring cannot guarantee detection of every attack.

How to read the mapping

Evidence is mapped to the part of a control we can actually assess.

Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.

All relevant frameworks
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Information Security Manual June 2026Prudential Standard CPS 234 Information Security effective 1 July 2019
Testing perspectives4 authorised viewpoints and access models

Source owner and onboarding contact

Confirms expected telemetry, collection method, ownership and source-side health during onboarding and gap review.

Included when
Used for source inventory and ingestion accountability.
Access required
Source inventory, owners, expected event types and maintenance context.
Limitations
Cannot establish SOC handling after ingestion.

Monitoring or SOC analyst

Reviews ingestion state, detection output and representative alerts in the monitoring platform.

Included when
Used for health, detection and triage procedures.
Access required
Platform access, parser state, last-event time, detections and alerts.
Limitations
Sampled alerts cannot prove every attack is detectable.

Investigation and escalation analyst

Builds timelines, preserves evidence and applies severity and escalation procedures to representative cases.

Included when
Used for investigation and handoff assessment.
Access required
Case records, queries, evidence stores, escalation matrix and contacts.
Limitations
A sample does not establish handling of every incident type.

Customer action owner and service reviewer

Tracks customer-owned actions, closure evidence, reporting and service-improvement decisions.

Included when
Used for communication, closure and periodic review.
Access required
Action register, reports, service measures, attendees and decisions.
Limitations
Service review cannot eliminate telemetry or detection limitations.
Exact test coverage and evidence16 governed coverage areas
What Damocles tests, the evidence produced and the scope boundary for each controlled coverage area.
Coverage areaWhat Damocles testsPerspective and accessEvidence producedReferences and limits
Source onboardingDamocles checks an expected telemetry source through ownership, collection method, parsing, event receipt and onboarding acceptance.Source owner and onboarding contact
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for source onboarding.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to source onboarding.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Source onboarding when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled source onboarding; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Source inventoryDamocles reconciles the customer-approved source inventory with platform entries, owners, expected event types and current status.Customer action owner and service reviewer
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for source inventory.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to source inventory.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Source inventory when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled source inventory; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Ingestion healthDamocles compares expected cadence with last-event time, transport state, parsing status and source-side health for sampled sources.Source owner and onboarding contact
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for ingestion health.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to ingestion health.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Ingestion health when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled ingestion health; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Telemetry gapsDamocles identifies missing, delayed, filtered or unusable telemetry and records the affected detection and investigation use cases.Source owner and onboarding contact
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for telemetry gaps.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to telemetry gaps.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Telemetry gaps when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled telemetry gaps; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Detection contentDamocles reviews selected detection logic, data dependencies, scope, suppression, tuning history and known blind spots.Source owner and onboarding contact
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for detection content.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to detection content.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Detection content when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled detection content; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Alert triageDamocles samples representative alerts and records enrichment, severity, disposition, timing and analyst rationale.Source owner and onboarding contact
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for alert triage.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to alert triage.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Alert triage when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled alert triage; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Investigation workflowDamocles reconstructs representative investigation timelines from alerts, queries, evidence, hypotheses and analyst decisions.Monitoring or SOC analyst
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for investigation workflow.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to investigation workflow.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Investigation workflow when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled investigation workflow; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

EscalationDamocles compares sampled escalation decisions and timing with severity, responsibility, contact and handoff requirements.Source owner and onboarding contact
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for escalation.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to escalation.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Escalation when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled escalation; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Customer communicationsDamocles reviews representative customer notifications for timing, content, channel, acknowledgement and follow-up.Source owner and onboarding contact
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for customer communications.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to customer communications.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Customer communications when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled customer communications; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Investigation evidenceDamocles verifies that sampled investigations retain queries, events, notes, timestamps and decision evidence needed for review.Source owner and onboarding contact
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for investigation evidence.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to investigation evidence.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Investigation evidence when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled investigation evidence; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Action ownershipDamocles traces remediation and containment actions to named customer or provider owners, due dates and acceptance evidence.Customer action owner and service reviewer
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for action ownership.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to action ownership.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Action ownership when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled action ownership; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Closure criteriaDamocles checks sampled closures for disposition, evidence, customer acknowledgement, residual actions and reopen criteria.Source owner and onboarding contact
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for closure criteria.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to closure criteria.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Closure criteria when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled closure criteria; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Operational reportingDamocles reviews operational reports for source health, alerts, investigations, timing, actions, trends and stated limitations.Source owner and onboarding contact
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for operational reporting.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to operational reporting.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Operational reporting when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled operational reporting; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Service reviewDamocles walks through service-review inputs, attendees, decisions, actions and subsequent improvement tracking.Customer action owner and service reviewer
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for service review.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to service review.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Service review when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled service review; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Service boundaries and exclusionsDamocles records monitored sources, hours, responsibilities, exclusions, response authority and customer dependencies.Source owner and onboarding contact
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for service boundaries and exclusions.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to service boundaries and exclusions.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Service boundaries and exclusions when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled service boundaries and exclusions; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Detection limitationsDamocles documents known telemetry, detection, timing and response limitations and states that monitoring cannot guarantee detection of every attack.Source owner and onboarding contact
Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for detection limitations.
Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to detection limitations.
Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3

Applicability: Applies to Detection limitations when the operational process and representative records fall within the managed service period.

Limit: The conclusion is limited to the sampled detection limitations; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded.

Framework and control mappings1 governed evidence mappings
Where scoped technical evidence maps to approved security frameworks and control objectives.
Framework and controlsMapping typeWhat Damocles assessesEvidence producedApplicability and limits
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Framework-level context
ContextualReviews sampled telemetry health, detection handling, alert triage, investigation evidence, escalation, action ownership, case closure and operational reporting within the managed-security-operations scope.Source-health records, event and alert timestamps, sampled investigation timelines, analyst decisions, escalation and action records, closure evidence and service-review outputs.

Applies: Framework-level context is relevant where a customer uses NIST SP 800-53 to organise security monitoring, incident handling and assurance activities and wants the managed-service evidence available to its broader control assessment.

Limit: No individual NIST control is claimed as verified. Sampling cannot prove continuous detection of every attack, complete control implementation, enterprise-wide monitoring coverage or organisational compliance.

Assurance boundary: Damocles maps assessed coverage and observations to agreed objectives as traceable technical evidence. The review is not a certification, does not establish complete compliance, and does not confirm controls outside the authorised scope.

Report and evidence outputs7 controlled output types

Authorised scope and rules of engagement

Records authorised scope and rules of engagement produced from the authorised Managed Security Operations work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Coverage matrix

Records coverage matrix produced from the authorised Managed Security Operations work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Retest and residual-risk record

Records retest and residual-risk record produced from the authorised Managed Security Operations work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Source inventory and health record

Records source inventory and health record produced from the authorised Managed Security Operations work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Investigation timeline

Records investigation timeline produced from the authorised Managed Security Operations work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Escalation and action record

Records escalation and action record produced from the authorised Managed Security Operations work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Service review record

Records service review record produced from the authorised Managed Security Operations work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.
What you receive

An operating-model review with source and workflow evidence, material gaps, prioritised actions and validation outcomes.

Operating responsibility

Know exactly who does what when an alert, source failure or investigation requires action.

Managed security fails when monitoring, investigation, containment and remediation are treated as one vague responsibility. The service schedule separates analyst work, customer or MSP ownership and separately contracted response activity.

Damocles
AN

Analyst responsibility

Monitor the contracted scope, review source health, triage alerts, investigate material activity, retain evidence, record disposition, escalate required action and tune approved workflows within the agreed service model.

Customer / MSP
CU

Environment ownership

Maintain access, supported source configuration, asset and identity context, contact details, change authority and the internal ability to complete customer-owned remediation or business decisions.

Shared
SR

Source-health responsibility

Damocles identifies missing, delayed or degraded telemetry and provides the evidence. The party that owns the device, connector, licence, network path or third-party platform completes the corrective change unless managed engineering is included.

Investigation
IR

Investigation record

For material activity, the service records alert origin, priority, timeline, affected assets or users, evidence reviewed, analyst conclusion, disposition, linked actions and any data limitation that prevented a stronger conclusion.

Separately contracted
CT

Containment and incident response

Endpoint isolation, account disablement, firewall changes, forensic acquisition, malware analysis, emergency response and broader incident handling are performed only where the service schedule or a separate incident-response authority includes them.

Separately contracted
RM

Remediation engineering

Patching, firewall or identity changes, endpoint rebuilds, cloud remediation and other engineering work remain customer or provider actions unless Damocles implementation or managed remediation is expressly included.

Common engagement options

Select the service tier and compatible technology model according to the responsibility required.

Platform capacity, source health, analyst coverage, response authority and incident-response capacity remain separate commercial and operational decisions.

Platform
PH

Platform and source-health operations

Maintain the approved platform, connectors, agents, collectors, source mappings, health monitoring and support without continuous analyst triage.

Managed service
BH

Business-hours Aegis

Add alert triage, investigation, escalation and reporting during the agreed business-hours coverage window.

Managed service
24

24×7 Aegis coverage

Add continuous monitoring and agreed escalation where the service model, source availability and operational capacity are expressly contracted.

Technology option
CP

Compatible commercial monitoring platform

Use an approved licensed monitoring and vulnerability platform with Guardian customer views and Aegis service delivery.

Technology option
PC

Provider-controlled monitoring platform

Use an approved self-hosted or provider-controlled option with explicit infrastructure, storage, maintenance, retention and analyst responsibilities.

Mixed estate
HY

Hybrid source operations

Combine approved endpoint, firewall, cloud, identity, DNS, vulnerability and other sources under one customer operating model while retaining source-specific support boundaries.

Delivery lifecycle

A repeatable service lifecycle from source onboarding to reviewed closure.

Contacts, service hours, severity, escalation, response authority and customer responsibilities are agreed before live monitoring begins.

01

Onboard the customer

Confirm products, sources, contacts, priorities, customer mappings, service hours, escalation paths and response authority.

02

Establish the baseline

Record expected source health, normal activity, key assets and identities, known exposure, business-critical systems and operational exceptions.

03

Monitor the service

Track source health and incoming security activity during the contracted coverage window and surface data-quality conditions that reduce investigation confidence.

04

Triage and investigate

Prioritise alerts, gather available context, correlate relevant activity, document evidence and determine whether the event is benign, suspicious, confirmed or unresolved.

05

Escalate and respond

Contact the agreed party and create the required customer action, engineering task, containment pathway or incident-response process with the available evidence attached.

06

Review and improve

Track closure, report unresolved issues, tune approved logic, correct source gaps and improve the customer baseline and service coverage over time.

What you receive

Operational records that show what was connected, monitored, investigated and left open.

The customer should be able to understand service health and material security activity without interpreting raw platform output.

SI

Source inventory and health record

Approved sources, agents, collectors, customer mappings, expected state, current health, last-seen context and known support or data-quality exceptions.

BL

Onboarding baseline

Known assets, identities, critical systems, normal activity, exclusions, contacts, service hours, escalation assumptions and customer-specific context used during triage.

IR

Investigation records

Priority, status, alert origin, evidence, timeline, affected scope, analyst conclusion, disposition, uncertainty and linked customer action.

ER

Escalation record

Who was contacted, when, why, which evidence was provided, what action was required and which response path or authority applied.

SR

Service report

Monitored scope, source health, material alerts, investigations, unresolved actions, service gaps, recurring issues and improvement activity for the reporting period.

TP

Tuning and improvement plan

Approved source, detection, triage, workflow and operational changes required to reduce noise, restore visibility or improve investigation quality.

What we need from the customer

A managed service needs accurate source ownership, customer contacts and a clear responsibility split.

The customer or MSP provides the approved source list, required access, customer and asset mappings, escalation contacts, change authority, incident contacts, expected service hours, critical-system context and known environment constraints.

The service cannot reliably investigate activity from missing, delayed or unsupported data. Source gaps remain visible and are not represented as evidence that no risk exists. Where a conclusion cannot be validated because the required source or context is unavailable, that limitation is retained in the investigation or service record.

What happens after delivery

The Managed Security Operations engagement continues until the customer understands the work, the owners and the remaining risk.

The report or service record is the beginning of remediation, not the end of the engagement. These steps keep the outcome usable after formal delivery.

01

Confirm the material issues

Damocles walks the customer through the findings, evidence, affected scope, dependencies and uncertainty so there is agreement on what requires action.

02

Assign ownership

Each material recommendation is allocated to the team that can implement it, with a clear expected outcome and realistic dependency on other changes.

03

Sequence remediation

Quick risk reduction, structural change, compensating controls and longer-term engineering are separated so the customer can plan the work sensibly.

04

Capture implementation evidence

Configuration records, change references, screenshots, test results, source state or other agreed evidence are retained for later review.

05

Verify the result

Where included, Damocles reviews the changed state, performs a retest or reassessment, and records whether the original exposure is resolved, reduced or still present.

06

Record residual risk

Issues that cannot be fully removed remain visible with the accepted limitation, compensating control, review date and decision owner.

Commercial structure and change control

How a Managed Security Operations engagement is scoped and kept commercially clear.

The proposal identifies the authorised scope, delivery method, assumptions, customer inputs, working window, deliverables, briefing, remediation support and any included retest or follow-up. Fixed-scope engagements are priced against that agreed boundary; retainers and managed services use the recurring quantity and service model stated in the schedule.

When the environment, target count, repositories, locations, access, service coverage or required evidence changes materially, Damocles records the impact before continuing. The customer can approve a variation, reduce the scope, defer the additional work or create a separate engagement. Hidden scope expansion is avoided because it produces poor testing and unreliable delivery dates.

Third-party licences, specialist platforms, travel, after-hours work, emergency response, remediation engineering and work outside the agreed deliverables are included only when listed in the proposal. Existing customer technologies can be used where they are supported and suitable; Damocles does not require a particular vendor simply to deliver the service.

Continuing the work in Guardian

Guardian is the customer and provider operating layer for the service.

Guardian presents source health, customer-scoped alerts, investigations, vulnerability context, risks, All Actions and approved reports through one workspace. External MSPs can operate authorised customer contexts while retaining the agreed first-line relationship.

Compatible security technologies remain distinct connector and delivery options. Aegis is the Damocles managed operational service behind them, and the service record keeps platform health, analyst conclusions and customer-owned actions visible as separate responsibilities.

Questions buyers ask before engagement

Practical questions about Managed Security Operations.

The final answer depends on the customer environment and scope, but these are the points that should be resolved before work begins.

Q1

How long will it take?

Timing depends on scope, access, environment stability, customer availability and the review depth required. The proposal states the expected delivery window and the assumptions that can change it.

Q2

Can the scope change after work starts?

Yes, but the change is recorded. Damocles explains the coverage, timing and commercial impact before additional work is performed.

Q3

Will Damocles work with our existing team or provider?

Yes. Internal teams, developers, cloud partners, infrastructure providers and MSPs can participate where responsibilities, access and communication paths are clear.

Q4

How are findings prioritised?

Priority considers practical exploitability or failure likelihood, exposure, affected business capability, data, privilege, dependency, available compensating controls and remediation effort.

Q5

Is remediation included?

Remediation guidance and handover are included as stated in the proposal. Implementation, managed change, emergency work and extensive engineering are separate unless expressly included.

Q6

How is closure verified?

Closure uses the method suitable for the issue: retesting, rescanning, code or configuration review, operational evidence, restored source health, tabletop follow-up or another agreed validation method.

Scope, assumptions and boundaries

Coverage, response and retention are contractual service details—not implied by the phrase “managed SOC.”

Monitored sources, ingestion, retention, service hours, triage, investigation depth, escalation, response time, containment, incident response, forensic work and remediation engineering are included only where expressly contracted. A 24×7 monitoring window does not automatically grant authority to isolate endpoints, disable identities or make production changes.

No monitoring service can identify or prevent every malicious event. Unsupported sources, missing data, telemetry delay, unavailable customer context and customer response delays remain explicit service conditions and can limit the strength or speed of an investigation conclusion.

Take the next practical step

Review the sources, service gaps and investigations the current operating model cannot explain clearly.

We will map the compatible technology, source-health model, analyst responsibilities, escalation, reporting, response authority and Guardian customer experience required.