
The ITH Security Operations Center (SOC) is a fully managed security operations center that provides continuous monitoring of infrastructure, threat detection, and real-time response to security incidents—all without the need to invest in building your own team.


A Security Operations Center (SOC) is more than just tools. It consists of people, processes, and technology working together as a single mechanism to protect the organization—from threat identification to a full-scale response.
The SOC team collects, correlates, and analyzes events from all layers of your infrastructure—networks, endpoints, the cloud, and applications. Both critical resources and network performance...
As part of our SOC, our analysts don’t just issue alerts—they take action. Every incident is verified, classified (Low / Medium / High / Critical),...
Monthly reports, incident documentation in accordance with NIS2, MTTD and MTTR metrics, and recommendations for implementing new security measures. Your organization’s management always has a...
We map your organization’s resources, identify the attack surface, and prioritize ongoing monitoring based on your industry’s specific characteristics.
Logs from all sources are sent to our center. The correlation engine looks for attack patterns.
We eliminate false alarms by calibrating the rules to match your network's normal activity patterns. We use behavioral analysis to improve detection accuracy. We configure the agents.
SOC monitors network traffic and analyzes events 24/7. For critical incidents, the SLA response time is up to 1–2 hours, and notifications about detected threats are sent to you immediately.
Every month, we provide a comprehensive overview of incidents, threat trends, and recommendations for managing vulnerabilities and strengthening your organization’s security procedures. Every quarter, we provide a management report (risk overview).
We cover the full spectrum of threats—from external attacks to unauthorized activities within the organization.
ITH's SOC Service as a Response to the Requirements of the NIS2 Directive
Starting in 2026, thousands of Polish cybersecurity companies will be required to implement the requirements of the NIS2 Directive. Among other things, the directive requires continuous monitoring of incidents, reporting them within 24 hours, and having documented security and incident response procedures. The ITH SOC meets these requirements
immediately upon implementation—without the need to build your own processes from scratch.

SOC from an operator with its own network
ITH is a telecommunications provider and IT integrator offering full visibility into networks, data centers, the cloud, and endpoints—all in one place.
We cover the full spectrum of threats—from external attacks to unauthorized activities within the organization.
We detect characteristic patterns of file encryption and network propagation before the data is locked.
Detection of network traffic anomalies and immediate activation of mitigation procedures in collaboration with the ITH Anti-DDoS service.
Analysis of email logs, detection of account takeovers and suspicious logins from unknown locations.
Monitoring the behavior of privileged users and anomalies in access to sensitive resources.
Correlation with current CVE feeds and real-time threat intelligence.
Detection of post-exploitation techniques: pivoting, privilege escalation, and unauthorized access to Active Directory.

Typically, it takes between 14 business days and several months (depending on the provider) from the signing of the contract to the full launch of the security operations center. During this implementation period, the integration of new data sources, SIEM configuration, and security tuning take place simultaneously. A dedicated ITH engineer will be with you every step of the way.
Our team of analysts works 24/7. In the event of a critical or high-severity incident, an analyst takes immediate action (isolation, blocking) while simultaneously notifying the designated individuals within your organization at any time of day or night.
We provide you with a SIEM environment managed by ITH. If you already have a SIEM system in place (e.g., Splunk, Microsoft Sentinel, IBM QRadar), we can integrate with it or perform parallel monitoring.
Yes, this is one of the key distinguishing features of ITH’s SOC service. We provide comprehensive documentation of security incidents in the format required by NIS-2, timely notifications to the CSIRT, and regular reviews of security and risk management procedures. For more information, visit ith.eu/wdrozenie-nis-2 and ith.eu/nis2.
We collect only security logs (events, network metadata, alerts)—not message content or business data. The data is stored on ITH servers located in Poland, in accordance with the GDPR and a data processing agreement.
Yes. As part of our SOC, we use artificial intelligence and machine learning to analyze network traffic patterns and detect anomalies that deviate from normal activity. Both event correlation and preliminary incident classification are automated, allowing our experts to focus on actual threats rather than alert noise.