Layer3 Logo

24/7 security operations

Managed SOC

Your tools already saw it. The alert still needed a response.

A standalone security operations centre that works with your team and existing tools, monitoring around the clock and acting under containment rules you set.

Model

Standalone, alongside your team

Platform

Todyl, built on Elastic

Coverage

24/7/365 monitoring

Certified

ISO/IEC 27001:2022

At a glance — how the SOC works

Buying it

Managed SOC is sold on its own. Plenty of SOC customers keep their existing IT team or provider and we monitor alongside them — you do not have to move anything to buy detection and response.

Your tools

You do not have to replace what you already own. We ingest telemetry from the platforms you run and correlate it centrally. Where an existing tool limits what we can do, we say so — some platforms let us alert and advise but not contain directly.

Containment

For critical and high-severity incidents the SOC contains directly — isolating a host, terminating a process, quarantining a file, disabling a high-risk account. Anything outside the agreed authority escalates to your authorised contact. The authority is set by you, in writing, before we start.

Who is watching

Round-the-clock analyst cover comes through our Todyl partnership, operating from the United States inside secure facilities under defined access controls, so the desk is staffed at 3am New Zealand time. On a high-severity incident they contain first under the authority you agreed and raise it with us immediately; Layer3 engineers carry it from there. Governance, reporting and escalation sit in New Zealand, and our engineers are police-vetted.

Log retention

Searchable retention is 30 days by default. Longer retention is available where audit, insurance or regulatory obligations require it — worth deciding at onboarding rather than after an incident.

What you get in writing

A monthly operational report: incidents by severity, alerts investigated, confirmed incidents against false positives, time to detect and respond, containment actions and every tuning change. Quarterly, a shorter executive review pitched at governance level.

01

The problem

Most organisations do not have a tooling problem

The problem appears at 3.00 am. The alert fires and the report is generated, but action still depends on an analyst being available.

Noise

Alerts without an owner

Most environments generate more alerts than one team can triage, allowing high-priority activity to queue behind routine noise.

Blind spot

Attacks start with a login

Credential theft and session hijacking leave no malware behind. A tool watching processes on a laptop will not see a valid login from the wrong side of the world.

Coverage

One team cannot cover the clock

Three shifts, seven days, every public holiday. That is a roster problem before it is a security problem, and hiring one more analyst does not solve it.

Telemetry

What we watch

We ingest telemetry from supported tools you already own, avoiding an unnecessary platform replacement.

01

Microsoft 365

Audit and security logs across mail, files and collaboration.

02

Entra ID

Sign-in events, risk detections and conditional access decisions.

03

Endpoint

EDR and next-generation antivirus telemetry from every managed device.

04

Servers

Process, account and configuration activity across server infrastructure.

05

Firewall

Perimeter traffic, policy hits and outbound patterns.

06

Remote access

VPN authentication and session activity for anyone connecting from outside.

07

Email security

Alerts from your existing mail protection platform, correlated with everything else.

08

Hosted applications

Session and authentication logs from published desktops and virtual apps.

09

Cloud

Control-plane and identity activity across your cloud tenancy.

Every source is normalised into one schema. That is what turns an odd login, a new mail forwarding rule and a strange process on a laptop from three low-priority alerts into one incident.

How it runs

What happens between the alert and the answer

The SOC follows seven continuous stages from telemetry collection to reporting.

01

Telemetry

Logs arrive from identity, endpoint, network, cloud and email and are normalised into one schema.

02

Correlation

Rules mapped to MITRE ATT&CK combine signals across sources that mean nothing on their own.

03

Triage

An analyst validates and enriches the alert, reviews related activity and rules it true or false.

04

Investigation

Confirmed incidents get a timeline, the affected systems and users, and preserved evidence.

05

Containment

Action under the authority you agreed: isolate the host, kill the process, quarantine the file.

06

Escalation

Your security lead gets the summary, what was done, and the decisions that need you.

07

Reporting

Every case documented and timestamped, and rolled into the monthly and quarterly view.

Running underneath all seven

Threat hunting, detection tuning, intelligence updates and use-case expansion. Detection logic is actively managed, not static - analysts review false positives, refine thresholds and suppress known benign activity so the alerting stays high-confidence rather than high-volume.

Authority

What we will do without asking you

Containment authority is agreed in writing before the service starts and graded by severity. Automated action runs only under documented playbooks and agreed authority. Actions outside that authority are escalated to an authorised contact; if no contact is available, the SOC continues monitoring and follows the escalation arrangements in your service schedule. These are the defaults we propose.

Critical

Confirmed or highly probable compromise

Active ransomware behaviour, confirmed account takeover, lateral movement on server infrastructure, privileged account abuse.

The 24/7 desk acts first under the authority you agreed, and you and Layer3 are notified immediately. Host isolation and process termination inside the endpoint platform, parallel notification to your security lead, live investigation until the situation is stable, and a full incident record with timeline and evidence.

High

Credible indicators, limited blast radius

Suspicious administrative activity, repeated failed authentication patterns, malware execution blocked by endpoint controls.

Targeted containment where there is risk of spread, escalation inside the agreed window, then findings and remediation recommendations.

Medium

Suspicious, needs validation

Anomalous login patterns, unusual mailbox rule creation, endpoint behavioural anomalies with no confirmed execution.

We investigate and advise. Validation, an advisory notification with recommended remediation, and inclusion in the monthly reporting review.

Low and informational

Logged, not chased

Policy violations, anomalies benign after validation, threat intelligence enrichment alerts.

Documented and reported as trend, so the pattern is visible without generating work.

Identity containment follows the same severity model. If the SOC assesses an account as high risk, we disable it to contain the threat and record the action in the incident. Privilege changes and actions outside the agreed containment authority are escalated to your authorised security contact.

Comparison

What this is not

Several services are presented as a managed SOC but provide materially different coverage.

Endpoint-only detection and response

Watches the device

A stolen session and a valid login from another country never touch an endpoint agent. If the attacker signs in as your finance manager rather than dropping a file, there is nothing on the laptop to detect.

A platform licence

Sells you the console

Detection you operate yourself is limited by your team’s availability. A dashboard cannot investigate or respond when no analyst is on duty.

An offshore alert relay

Forwards the ticket

Alerts passed on without investigation, by people with no view of your environment, no working relationship with your team, and no accountability in your jurisdiction.

Layer3 Managed SOC

Watches everything, and acts

Telemetry unified across endpoint, identity, network and cloud. Analysts investigate and contain rather than forward a ticket — round-the-clock cover comes through our Todyl partnership, so the desk is staffed at 3am, and Layer3 engineers who know your environment carry the case from there. Containment follows the authority you set in writing, and the accountability is ours, in New Zealand.

Identity

The attacks that leave no malware

Identity is where modern intrusions start. These are the behaviours the SOC is built to catch, across Microsoft 365 and Entra ID.

Account takeover and session hijacking

A stolen token means the attacker never sees your login page. Detection keys on what the session then does, not on how it authenticated.

Phishing that defeats multi-factor

Adversary-in-the-middle kits proxy the real sign-in and capture the session after MFA succeeds. The authentication looks clean because it was.

Impossible travel and anomalous access

Two successful sign-ins that cannot both be true, and access patterns that do not match how that person has ever worked.

Mailbox rule manipulation

The quiet signature of business email compromise: a forwarding or delete rule created so the owner never sees the replies.

Privilege escalation and role abuse

Privileged role assignments and changes, watched as events in their own right rather than discovered at the next access review.

OAuth consent and token misuse

Malicious application consent grants persistence that survives a password reset. Consent events are monitored as an attack path, not as admin noise.

Identity alerts are correlated with endpoint telemetry and email security alerts, so a sign-in anomaly and a process on that user's laptop land in the same case rather than two queues.

The platform

One agent. One platform.

The SOC runs on Todyl, a unified security platform built on Elastic. Six modules, one agent on the endpoint, and one place where the telemetry meets. Layer3 is the founding Todyl partner in New Zealand.

SIEM

Managed cloud SIEM

Deep visibility across sources, with searchable retention and the audit trail compliance work depends on.

EDR

Endpoint detection and response

Behavioural prevention, memory protection and the containment actions the SOC executes directly.

MXDR

Managed extended detection and response

The 24/7 analyst function: validation, investigation, threat hunting and authorised response.

SOAR

Orchestration and automation

Playbooks that act in seconds on the cases where waiting for a human costs you the environment.

GRC

Governance and compliance

Control and process management, so the evidence exists before somebody asks for it.

SASE

Secure access and zero trust

Network access without the VPN problems, available if you want the SOC watching that layer too.

Governance

Evidence, not adjectives

You should be able to prove what was watched, what fired, what was done about it and who decided. All four are reportable.

Monthly operational report

Volume

Incidents by severity, alerts investigated, and confirmed incidents against false positives.

Performance

Time to detect and time to respond, measured against the objectives agreed at onboarding.

Tuning

Every detection change documented, so alert reduction is visible rather than asserted.

Quarterly executive review

Risk themes

Trend analysis and threat patterns observed in your environment, written for decision-makers rather than analysts.

Control effectiveness

What is working, what is not, and the detection enhancements made since the last review.

Recommendations

Specific control improvements, prioritised, with the reasoning attached.

Between reports

Portal access

Role-based access to open and closed cases, investigation notes, containment actions with timestamps, and severity and resolution status. Your security lead sees what we see, when we see it.

For the auditor

An attributable trail

Structured incident records, documented containment approvals, and analyst actions that are timestamped and attributable to a named person. Exportable for internal audit, external review or your insurer.

Where your data sits

Stated plainly

Telemetry is processed in the Todyl platform. Round-the-clock analyst cover comes through our Todyl partnership, operating from the United States so the desk is staffed at 3am New Zealand time, and Layer3 engineers carry the case from the moment it is raised. Governance, reporting and escalation sit here. Data is encrypted in transit, access is role-based and least-privilege, and every access is logged. Searchable retention is 30 days by default, with longer retention available where audit or regulation needs it.

Layer3 operates an ISO/IEC 27001 certified information security management system. SOC operations, information handling and incident response are governed inside that externally audited framework.

Onboarding

Monitoring goes live once, and correctly

Structured onboarding, run by a project manager with senior engineers behind them. Authority is defined before anything is switched on.

01

Authority and planning

Confirm the log sources, agree severity thresholds and containment authority, document the identity containment model, and set escalation contacts and channels.

02

Telemetry integration

Connect endpoint, identity, cloud and network sources, validate that alerts flow and cases are created, and test containment actions in controlled scenarios.

03

Tuning and baseline

Reduce false positives, align detection thresholds to your environment, establish baseline metrics and confirm the reporting format and cadence.

04

Steady state

Monitoring live around the clock, monthly reporting running, and the quarterly review in the calendar.

By the numbers

What a year of this looks like

Read the last three figures together. Fifty-six million events became ten thousand alerts worth investigating, and those became two thousand three hundred cases that needed a decision. That is high-confidence alerting rather than volume.

21+

Years delivering managed IT, security and cloud

1,500+

Secured endpoints

2,500+

Users protected

56m+

Security events collected in 2025

10,000+

Alerts analysed in 2025

2,300+

Security cases generated in 2025

Layer3 has operated in New Zealand since 2005 under an ISO/IEC 27001 certified management system, with police-vetted engineers, serving police organisations, Crown and government agencies, non-profits including medical, and businesses across regulated industries.

Customers

Who we already look after

Customer example

KPMG tested

The Police Credit Union holds members' personal details and financial histories. Layer3 was chosen after a KPMG vendor audit, the Government CIO Cloud Risk Assessment Tool and a board Audit and Risk review.

Read the Police Credit Union case study

Before you ask

The questions we always get

If yours is not here, ask it directly and you will get a straight answer.

Book a discovery call

Yes. Managed SOC is sold on its own. Plenty of our SOC customers keep their existing IT team or their existing IT provider, and we monitor alongside them. You do not have to move anything to buy detection and response.

In charge. The SOC does the work they cannot staff around the clock: continuous monitoring, correlation across sources, and first-line investigation. They keep ownership of risk decisions, and they are who we escalate to. The containment authority is set by them, in writing, before we start.

No. We ingest telemetry from the platforms you already run and correlate it centrally. Administration of those platforms can stay with you. Where an existing tool limits what we can do, we say so plainly rather than working around it quietly - the honest constraint is that some platforms let us alert and advise but not contain directly.

For critical and high-severity incidents, the SOC contains directly: isolating a host, terminating a malicious process, quarantining a file or disabling an account assessed as high risk. Privilege changes and actions outside the agreed containment authority are escalated to your authorised security contact. The full breakdown is on this page under authority.

The MXDR analyst function operates 24/7 from the United States, inside secure facilities under defined access controls. Layer3 governance, reporting and the people you deal with day to day are in New Zealand, and our engineers are police-vetted. We would rather tell you that upfront than have you discover it during due diligence.

MDR usually means endpoint detection with a managed service attached. MXDR correlates across endpoint, identity, network, cloud and email. The difference matters because most intrusions now begin with a login rather than a file, and an endpoint-only service cannot see a valid sign-in from the wrong country.

Searchable retention is 30 days by default. Longer retention is available where audit, insurance or regulatory obligations require it, and it is worth deciding this at onboarding rather than after an incident.

A monthly operational report: incidents by severity, alerts investigated, confirmed incidents against false positives, time to detect and respond, containment actions taken, and every detection tuning change. Quarterly, a shorter executive review pitched at governance level, not technical detail.

It runs in four phases: defining authority, integrating telemetry, tuning, then steady state. The tuning phase is the one that varies, because it depends on how noisy the environment is to begin with. We will give you a dated plan at contract, not a guess on a web page.

Usually, yes. Insurers and enterprise customers increasingly ask whether monitoring is continuous, whether incidents are documented, and who is accountable. Structured incident records with attributable analyst actions answer all three, and they are exportable.

Next step

Find out what is watching

Most organisations are surprised by how much of their environment produces no security telemetry at all. That gap is the first thing we map, and you get the answer whether or not you buy anything.

Layer3

Book a discovery call - 30 minutes, no obligation