OT SOC as a Service
OT SOC as a service, running on the platform you already own
You bought an OT security platform. ForgeSOC puts trained analysts behind it, so alerts get validated, triaged and escalated to someone who can act on them.
01 / What it is
What OT SOC as a service means here
An OT security operations center watches the alerts coming out of your plant networks and decides which ones matter. ForgeSOC is a managed OT SOC. We take the alerts from the passive OT visibility and threat detection platform you already run, and we do the daily work of looking at them.
The platform sees traffic on your ICS and SCADA networks. It raises alerts about new devices, unusual commands, changed logic, odd protocol use and loss of visibility. Someone has to read those alerts, compare them with what the site normally does, and decide what is noise and what is not. In most plants, nobody has the time. That is the gap this service closes.
This is managed OT security monitoring built for lean teams. You keep your platform, your tools and your response decisions. We supply the people and the process around them.
02 / What's included
What is included in the managed OT SOC
Every engagement covers the same core work, whatever coverage window you pick.
Alert validation
We check each alert against context and suppress duplicates, so your team only hears about what is real.
Context review
We review asset, network and event context. A new device on a PLC subnet reads differently than one on a guest segment.
Severity and rationale
Every escalation carries a severity and a written reason, so the person on the other end can decide quickly.
Tickets and follow-up
We create the ticket, notify the right contact and follow up until the finding is handed to your team.
Telemetry health
We watch platform connectivity. If a sensor or integration goes quiet, we flag it, because silence is a finding.
Reporting and true-up
You get a monthly report of alerts and escalations, plus a quarterly asset true-up to keep the inventory honest.
US OT escalation
Confirmed findings go to US-based OT specialists who understand process systems, not just IT alerts.
Onboarding
We set up access, review the platform, map escalation paths, build the contact tree and runbooks, review baseline alerts and run a test escalation.
03 / Coverage options
Coverage options: 24/7/365, nights and weekends, or one shift
| 24/7/365 | Nights and weekends | Single shift | |
|---|---|---|---|
| Hours covered | Every hour, including weekends and holidays | The hours your own team is off | One window on weekdays, US overnight or US business hours |
| Best for | Sites that need continuous eyes on OT alerts | Teams that cover business hours themselves | Sites with one clear gap to close |
| Alert handling | Validation, triage and escalation at all times | Validation, triage and escalation after hours | Validation, triage and escalation in the window |
| Reporting | Monthly report and quarterly asset true-up | Monthly report and quarterly asset true-up | Monthly report and quarterly asset true-up |
| Upgrade path | This is the full service | Move to 24/7/365 when ready | Add hours or move to 24/7/365 |
04 / Not included
What the OT SOC does not do
We are plain about the edges of the service, because surprises during an event help nobody. ForgeSOC monitors, triages and escalates. We do not respond.
Response decisions stay with you. You know your process, your safety constraints and what can be taken offline. If a finding needs outside help, we can connect you with response partners.
- No platform deployment, upgrades, sensor maintenance or administration.
- No detection engineering or extensive tuning of your platform.
- No deep forensics or threat hunting.
- No containment, remediation, incident response or recovery.
- If your platform is not tuned yet, we can scope a readiness project first.
05 / Your platform
How it fits with the platform you already own
We do not ask you to rip anything out or buy a second tool. ForgeSOC works inside the OT security platform you already have, through read-only access over your existing secure remote access. Your data stays in your environment.
Many teams bought a platform after an assessment, an insurance push or a compliance review under frameworks like ISA/IEC 62443 or NIST CSF. The platform went in. The consoles filled with alerts. Nobody owned the daily review. A managed OT SOC turns that purchase into something that produces results.
06 / Who it's for
Who this OT security operations center is for
The best fit is a company with one to ten sites, a lean OT or IT security team, and a detection platform nobody watches consistently. We work with water and wastewater, manufacturing, oil and gas midstream, food and beverage, pharma and life sciences, and building and facility systems.
Engineering firms and integrators can also offer this service to their own clients, under their name or ours. You keep the client. We run the SOC.
A platform without analysts is a camera with nobody watching the screen.
08 / FAQ
OT SOC as a service: common questions
01Do we need to buy a new platform?
No. We work on the OT visibility and threat detection platform you already own. If you do not have one, we can talk through your options on a fit call.
02Does ForgeSOC respond to incidents?
No. We monitor, triage and escalate. Response decisions stay with you, and we can connect you with response partners if you want one.
03Which coverage option should we start with?
If nobody watches your OT alerts today, 24/7/365 is the full service. If your team covers business hours, nights and weekends closes the gap. You can change later.
04Where do the analysts work?
L1 and L2 analysts work from a dedicated, secured SOC in the Philippines. Confirmed findings escalate to US-based OT specialists.
Keep reading
Next step
Put analysts behind your OT platform
Book a 20-minute fit call and we will tell you straight whether this fits your sites.