شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

NCA-licensed MSOC · Tier 2

A licensed managed SOC, run from Riyadh around the clock

We monitor your environment, analyse alerts, respond within agreed authority and report in terms management understands.

From alert to actionIllustrative
  • Unusual sign-in to a privileged account

    Session and identity logs checked

    HighInvestigating
  • Phishing email to a finance employee

    Message quarantined · awareness notice

    MediumHandled
  • Weekly report for the security manager

    Detections · recommendations · trends

    InfoSent

24/7

continuous monitoring

L1 → L3

tiered escalation

Monthly

review meeting

Licence and trust

Licensed by the National Cybersecurity Authority

DataSec holds a Tier 2 licence to provide managed Security Operations Center services. The licence is listed in the NCA's public register and can be verified directly.

National Cybersecurity Authority

Managed Security Operations Center (MSOC) Services Licence — Tier 2

Licence number
010220341
Tier
Tier 2
Effective date
14 Jul 2026
Expiry date
14 Jul 2031
Verify on the NCA website

Who it is for

Who the service fits

You own the tools but not a 24/7 team

We run your existing tools with L1 to L3 analysts under documented procedures.

You are starting from scratch

We help you identify log sources and priorities and build coverage step by step.

You want to assess your current setup

A professional review of your existing operation with actionable recommendations.

Licence scope: A Tier 2 licence authorises the provision of managed SOC services to any organisation other than government entities and organisations that own, operate or host critical national infrastructure.

Getting started

What we need to start

  1. 1An inventory of critical assets and log sources
  2. 2Existing tools: SIEM, EDR, firewalls and cloud
  3. 3Your contacts and escalation path
  4. 4Limits of authority: what is executed directly and what needs approval
  5. 5An agreed onboarding and testing window

Integration

We integrate with your existing technology

We do not make you replace your tools. Our team has experience installing, managing and operating Splunk, and we integrate with your existing SIEM, EDR, firewall and cloud solutions.

  • Splunk
  • SIEM
  • EDR / XDR
  • Firewalls
  • Cloud
  • Identity

Operations

What operations include

Detection use-case development

Rules and scenarios built for your environment and reviewed as threats change.

Alert review

Every alert classified, false positives filtered out and the decision documented.

Response procedures and limits of authority

Documented steps per scenario: what is executed directly and what is escalated to you.

Reports and review meetings

Regular reports with clear indicators and a review meeting to improve coverage.

Examples

Illustrative detection scenarios

Generic examples for illustration; they do not represent client data or real cases.

Illustrative

Unusual sign-in to a privileged account

Verify the session → contact the owner → suspend the account on confirmation

Illustrative

Targeted phishing email

Quarantine the message → inspect the attachment → notify recipients

Illustrative

Suspicious outbound connection from a server

Analyse the destination → block at the firewall → scan the server

Assess your current SOC operation

If you already run a SOC or use a provider, we offer a professional review of detection coverage, alert quality and response procedures, with practical recommendations and no disruption to what already works.

Request an assessment

FAQ

Frequently asked questions

Do I need to buy a new SIEM?

No. We work with your existing tools and suggest alternatives only where there is a documented gap.

Where are my logs stored?

That is defined in the service agreement in line with National Cybersecurity Authority requirements and the Personal Data Protection Law.

What does the SOC execute without asking me?

Only what you agree to. Limits of authority are documented before go-live and reviewed in the review meetings.

Do you serve government entities?

A Tier 2 licence does not cover managed SOC services for government entities or organisations that own, operate or host critical national infrastructure. Our other services are available to them.

What affects the cost of a managed SOC?

Cost follows scope rather than a fixed price list: the number, type and volume of log sources, the number of assets and accounts monitored, the detection use cases you need, how long logs must be retained, and the hours of coverage agreed. Whether you already hold SIEM licences or need them provided also matters. We set this out in a written proposal after a scoping session.

How is a managed SOC different from MDR?

A managed SOC collects logs from across your environment, including network, servers, cloud, applications and identity, correlates them in a SIEM, and handles alerts within agreed authority. DataSec's Managed Detection and Response (MDR) service focuses on endpoints and identity through EDR/XDR tools, with direct containment such as isolating a host. Some organisations start with MDR and widen to a managed SOC later, or combine the two.

Does a managed SOC help with SAMA CSF or NCA ECC requirements?

Both expect security events to be monitored and handled: the SAMA Cyber Security Framework (CSF) calls for a designated security monitoring team (a SOC) with continuous event monitoring and centralised log analysis in a SIEM, and the NCA Essential Cybersecurity Controls (ECC) include a subdomain on cybersecurity event logs and monitoring management. Our documented procedures, alert decisions and reports can serve as evidence, but acceptance rests with your auditor or regulator. The service itself is offered only to organisations within the scope of our Tier 2 licence.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.