en

SOC Implementation for an IT Company

Client:
International IT company
Industry:
Information technology, cybersecurity
Focus:
SOC and SIEM implementation for centralized security monitoring
Main challenge:
Lack of centralized monitoring, slow incident detection, and risk of data compromise
Market:
International
Services provided:
SOC / SIEM Implementation
Key Takeaways
  • 47 detection and 25 response scenarios
  • ISO 27001 compliance: 32% → 94%
  • Achieved 91% SOC 2 audit readiness
  • Reduced incident detection time from 36 hours to 8 minutes
  • Reduced incident response time from 8 hours to 35 minutes
  • 95%
    Asset coverage
    100%
    Logging compliance
    347
    CVEs identified
    SOC Implementation for an IT Company
    An international IT company approached Datami to strengthen infrastructure security, centralize security monitoring, and prepare for certification. The Datami implemented a Wazuh-based SOC, configured 47 detection scenarios (use cases) and 25 response scenarios (playbooks), increasing ISO 27001 compliance to 94%.

    The international IT company provides infrastructure monitoring solutions and processes personal and financial data. With more than 50,000 users, maintaining a high level of security is critical.

    For this business, cybersecurity directly affects service availability, compliance with industry standards, and the ability to detect and respond to incidents.

    Project goals and challenges
    At the start of the project, the client had no SIEM system or centralized security monitoring, making threat detection difficult.

    This increased the risk of data breaches, non-compliance with ISO 27001 and SOC 2, and disruptions to critical services.
    • Implement a SOC and SIEM for centralized security monitoring across the infrastructure
    • Reduce incident detection and response times while improving alert accuracy
    • Achieve ISO 27001 and SOC 2 readiness with a scalable security architecture
    icon
    IT infrastructure
    100+ hosts: Windows, Windows Server 2022, Ubuntu Server, Active Directory, and public-facing hosts.
    icon
    Key risks
    No SIEM, slow incident detection, excessive log noise, and risk of data compromise.
    icon
    Expected outcome
    Centralized monitoring, faster incident response, and compliance with security standards.

    Our approach

    Datami implemented the SOC in stages by deploying the Wazuh SIEM system and integrating it into the client's infrastructure. The approach included documentation analysis, threat detection scenarios, and attack simulation.

    Security monitoring was centralized across critical systems, preparing the infrastructure for compliance. Detection rules were configured, log noise and false positives reduced, allowing the system to focus on critical incidents.

    Black-box

    Compliance-driven

    Built monitoring scenarios and use cases aligned with security standards and regulatory requirements.
    Gray-box

    Purple team

    Validated SIEM effectiveness through cyberattack simulations and analysis of how the system detected them.
    Key project stages and solutions

    SOC implementation followed a phased approach, considering the complex IT infrastructure, service continuity, and certification goals. 

    At the beginning of the project, the sequence of work and regular reporting were agreed upon. 

    The primary communication with the client took place during weekly Google Meet meetings and via email.

    • SIEM deployment
      Implemented Wazuh and connected Active Directory, Windows workstations, and Ubuntu servers to centralized security monitoring.
    • Configuration and validation
      Built detection scenarios, collected telemetry, reduced false positives, and validated the system through attack simulations.
    • Project finalization
      Analyzed results, prepared the final report, technical documentation, and recommendations for future operations.
    How we can help you?

    Every cybersecurity case study we solve involves deep analysis, tailored solutions, and measurable results.
    Datami has already helped over 600 companies strengthen their digital defenses — and we can do the same for your business.
    Ready to take action?

    Let’s start with a free consultation!
    Results and recommendations

    Results and recommendations

    As a result of the project, the client received a Wazuh- and Zabbix-based SOC with centralized monitoring of 95% of critical assets and a complete audit trail. Datami implemented 47 detection scenarios and 25 response scenarios, identified 347 CVEs, and achieved 99.98% monitoring uptime.

    The key outcome of the project was a significant improvement in incident response speed and compliance levels:

    • Incident detection time was reduced from 36 hours to 8 minutes;
    • Incident response time was reduced from 8 hours to 35 minutes.

    ISO 27001 compliance increased from 32% to 94%, while SOC 2 readiness improved from 28% to 91%. The client also received technical documentation, including:

    • Disaster Recovery Plan,
    • Incident Response Policy,
    • Access Control Policy,
    • Vulnerability Assessment and Compliance Reports.
    Key project results

    SOC implementation helped the client centralize security monitoring, significantly reduce incident detection and response time, and improve control over critical assets.

    This case study shows that for a complex IT infrastructure, continuous monitoring, quality logging, and tested response scenarios are the foundation of resilience against modern cyber threats. Phased SOC implementation enables faster attack detection and systematically improves security process maturity.

    Metric
    Before the project
    After the project
    SOC and monitoring
    No centralized monitoring
    SOC and SIEM implemented
    Detection time
    Up to 36 hours
    8 minutes
    Response time
    Up to 8 hours
    35 minutes
    Standards compliance
    ISO 27001 – 32%, SOC 2 – 28%
    ISO 27001 – 94%, SOC 2 – 91%
    Security maturity
    Fragmented processes and high log noise
    47 detection scenarios, 25 response scenarios
    Business outcome
    Risk of data breaches and service disruptions
    Greater control, faster response, and audit readiness
    More success stories with Datami
    Browse other project case studies
    Cloudflare Zero Trust & SIEM for SaaS
    Cloudflare Zero Trust & SIEM for SaaS
    • MTTD reduced to 1–2 hours
    • False positives reduced by 50–65%
    Services:
    Cloudflare Zero Trust and Wazuh SIEM implementation
    Aug 4, 2026
    WordPress Website Recovery After a Hack
    WordPress Website Recovery After a Hack
    • Backdoor infections and web shells were completely removed.
    • 9 unauthorized admin accounts were removed.
    Services:
    WordPress Security Audit (White-box)
    Aug 4, 2026
    SIEM Wazuh Implementation for a Financial Company
    SIEM Wazuh Implementation for a Financial Company
    • PCI DSS & ISO 27001 audit-ready
    • Reduced false positives by 60–70%
    Services:
    SIEM Implementation (Wazuh)
    Jul 1, 2026
    Security image
    Ready to assess your project's security?
    Contact Datami — we’ll help you identify risks, strengthen your cybersecurity, and confidently pass certification.
    Datami articles
    Why AI Tokens Introduce a New Class of Smart Contract Risks Oleksandr Filipov
    Oleksandr Filipov
    Why AI Tokens Introduce a New Class of Smart Contract Risks

    A smart contract can pass a Solidity audit without a remark and still be exploitable - if part of the decision-making sits with a model. What a real audit with 40 findings reveals, and what to check before listing.

    4 min Aug 4, 2026
    When AI Meets Smart Contracts: How Prompt Injection Creates a New Web3 Attack Surface Oleksandr Filipov
    Oleksandr Filipov
    When AI Meets Smart Contracts: How Prompt Injection Creates a New Web3 Attack Surface

    A smart contract can pass the most rigorous audit and the product around it can still be exposed. All it takes is an AI reading on-chain text as a command. A new class of Web3 risk, from a real Datami finding.

    3 min Aug 3, 2026
    Cybersecurity Risk Self-Assessment: 6 Gaps Fintech Companies Notice Last Oleksandr Filipov
    Oleksandr Filipov
    Cybersecurity Risk Self-Assessment: 6 Gaps Fintech Companies Notice Last

    Most companies learn about their weak spots not from their own team, but from a due diligence partner or an attacker. We explain which gaps in fintech remain unnoticed the longest and why.

    4 min Jul 27, 2026
    Order a consultation
    We value your privacy
    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie policy