SOC_STATUS · Bangkok SOC online · Protection · MDR · MPR · Managed SOC Coverage · SIEM · EDR · XDR

SLA

SOC SLA and Response Times

Buyers deserve clear targets before they subscribe. These are the response commitments by edition. Cybersecurity reduces risk; it does not guarantee zero incidents.

Quick answer

Protection is best-effort in business hours. MDR targets an 8 business-hour response on qualified alerts. MPR targets 4 business hours, with 24×7 handling for criticals. Managed SOC targets a 1-hour response on critical incidents with full 24×7 analyst coverage.

Comparison at a glance

Target Protection MDR MPR Managed SOC
Monitoring Endpoint protection and basic alerts 24/7 SIEM monitoring and alerting 24/7 monitoring plus threat hunting 24/7 analyst-led monitoring and response
Human support Business hours Business hours 24×7 for criticals 24×7
Response SLA Best effort 8 business hours 4 business hours 1 hour (critical)
Active containment No Guided next steps Remote IR assistance Yes (edition scope)

What “response” means

Response time is the target window from when a qualified alert is raised in our monitoring stack to when an analyst (or automated playbook under analyst oversight) acknowledges and begins investigation or customer notification, whichever your edition includes. It is not a promise that every attack is blocked, or that full remediation finishes inside the same window.

Severity levels we use

Critical: active ransomware behaviour, confirmed compromise, or widespread account takeover. High: likely malicious activity needing same-day attention. Medium: suspicious activity needing investigation. Low / informational: tuning, vulnerability context, or awareness items. Only Critical and High normally consume the published SLA clocks; Medium and Low are handled in priority order during support hours for your edition.

Business hours vs 24/7

MDR and above keep automated monitoring and alerting around the clock. Human investigation and customer callbacks follow each edition’s support model. MPR escalates criticals 24×7. Managed SOC keeps analyst-led response 24×7 with the tightest critical SLA.

Honest limits

Missed coverage from revoked access, outdated contact lists, or out-of-scope assets is outside the SLA. Service credits, if any, are handled case by case under your order terms, not as an unlimited warranty.

Common questions

Are SLAs the same as uptime guarantees?

No. These targets cover analyst response to qualified security alerts. Platform maintenance windows are scheduled to minimise monitoring gaps.

Which edition should I pick for overnight ransomware risk?

MDR and above monitor 24/7. For overnight human response and containment, choose MPR (criticals) or Managed SOC (1-hour critical target).

Where do I see this at checkout?

Each plan card on Pricing lists monitoring, support hours, and SLA. This page defines severity and what the clock measures.

Ready to scope your environment?

Tell us endpoint count and cloud platforms, we recommend a tier within 24 hours.

LINE Messenger