Analysts at monitoring stations on a dedicated, secured SOC floor providing OT SOC as a service

OT SOC as a Service

OT SOC as a service, running on the platform you already own

You bought an OT security platform. ForgeSOC puts trained analysts behind it, so alerts get validated, triaged and escalated to someone who can act on them.

01 / What it is

What OT SOC as a service means here

An OT security operations center watches the alerts coming out of your plant networks and decides which ones matter. ForgeSOC is a managed OT SOC. We take the alerts from the passive OT visibility and threat detection platform you already run, and we do the daily work of looking at them.

The platform sees traffic on your ICS and SCADA networks. It raises alerts about new devices, unusual commands, changed logic, odd protocol use and loss of visibility. Someone has to read those alerts, compare them with what the site normally does, and decide what is noise and what is not. In most plants, nobody has the time. That is the gap this service closes.

This is managed OT security monitoring built for lean teams. You keep your platform, your tools and your response decisions. We supply the people and the process around them.

02 / What's included

What is included in the managed OT SOC

Every engagement covers the same core work, whatever coverage window you pick.

Alert validation

We check each alert against context and suppress duplicates, so your team only hears about what is real.

Context review

We review asset, network and event context. A new device on a PLC subnet reads differently than one on a guest segment.

Severity and rationale

Every escalation carries a severity and a written reason, so the person on the other end can decide quickly.

Tickets and follow-up

We create the ticket, notify the right contact and follow up until the finding is handed to your team.

Telemetry health

We watch platform connectivity. If a sensor or integration goes quiet, we flag it, because silence is a finding.

Reporting and true-up

You get a monthly report of alerts and escalations, plus a quarterly asset true-up to keep the inventory honest.

US OT escalation

Confirmed findings go to US-based OT specialists who understand process systems, not just IT alerts.

Onboarding

We set up access, review the platform, map escalation paths, build the contact tree and runbooks, review baseline alerts and run a test escalation.

03 / Coverage options

Coverage options: 24/7/365, nights and weekends, or one shift

24/7/365Nights and weekendsSingle shift
Hours coveredEvery hour, including weekends and holidaysThe hours your own team is offOne window on weekdays, US overnight or US business hours
Best forSites that need continuous eyes on OT alertsTeams that cover business hours themselvesSites with one clear gap to close
Alert handlingValidation, triage and escalation at all timesValidation, triage and escalation after hoursValidation, triage and escalation in the window
ReportingMonthly report and quarterly asset true-upMonthly report and quarterly asset true-upMonthly report and quarterly asset true-up
Upgrade pathThis is the full serviceMove to 24/7/365 when readyAdd hours or move to 24/7/365

04 / Not included

What the OT SOC does not do

We are plain about the edges of the service, because surprises during an event help nobody. ForgeSOC monitors, triages and escalates. We do not respond.

Response decisions stay with you. You know your process, your safety constraints and what can be taken offline. If a finding needs outside help, we can connect you with response partners.

  • No platform deployment, upgrades, sensor maintenance or administration.
  • No detection engineering or extensive tuning of your platform.
  • No deep forensics or threat hunting.
  • No containment, remediation, incident response or recovery.
  • If your platform is not tuned yet, we can scope a readiness project first.

05 / Your platform

How it fits with the platform you already own

We do not ask you to rip anything out or buy a second tool. ForgeSOC works inside the OT security platform you already have, through read-only access over your existing secure remote access. Your data stays in your environment.

Many teams bought a platform after an assessment, an insurance push or a compliance review under frameworks like ISA/IEC 62443 or NIST CSF. The platform went in. The consoles filled with alerts. Nobody owned the daily review. A managed OT SOC turns that purchase into something that produces results.

06 / Who it's for

Who this OT security operations center is for

The best fit is a company with one to ten sites, a lean OT or IT security team, and a detection platform nobody watches consistently. We work with water and wastewater, manufacturing, oil and gas midstream, food and beverage, pharma and life sciences, and building and facility systems.

Engineering firms and integrators can also offer this service to their own clients, under their name or ours. You keep the client. We run the SOC.

A platform without analysts is a camera with nobody watching the screen.

08 / FAQ

OT SOC as a service: common questions

01Do we need to buy a new platform?

No. We work on the OT visibility and threat detection platform you already own. If you do not have one, we can talk through your options on a fit call.

02Does ForgeSOC respond to incidents?

No. We monitor, triage and escalate. Response decisions stay with you, and we can connect you with response partners if you want one.

03Which coverage option should we start with?

If nobody watches your OT alerts today, 24/7/365 is the full service. If your team covers business hours, nights and weekends closes the gap. You can change later.

04Where do the analysts work?

L1 and L2 analysts work from a dedicated, secured SOC in the Philippines. Confirmed findings escalate to US-based OT specialists.

Next step

Put analysts behind your OT platform

Book a 20-minute fit call and we will tell you straight whether this fits your sites.