Security operations

SOC services in Dubai, UAE

A security operations centre, or SOC, that watches your systems around the clock, decides which alerts are real, and contains the ones that are. Run on the Fortinet Security Fabric, with your telemetry held in the UAE.

Managed SOC services in Dubai, UAE
Why it matters

Detection tooling produces alerts. A SOC decides which ones matter

Most organisations that suffer a serious incident had the telemetry to catch it. The alert fired. It then sat in a queue with several thousand others, because no one was rostered to look at it when it arrived.

The hard part of security operations is not the platform. It is staffing three shifts through weekends and public holidays, It is keeping detection rules current as systems change. It is holding the authority to disconnect something at two in the morning without waiting for approval.

That is the work a managed SOC takes on. The tooling is the easy half to buy, and the half that gets bought first. That is why so many networks are well instrumented and still slow to respond.

What you get

What a managed SOC covers

Monitoring is the visible part. What determines whether an incident is contained or merely observed is everything arranged around it.

24x7 monitoring across every source

Cloud, on-premises networks and endpoints correlated in FortiSIEM in real time, with analysts investigating anomalies, not forwarding them on.

Response that runs at machine speed

Confirmed threats trigger pre-approved Shuffle SOAR playbooks that isolate endpoints, revoke credentials and block infrastructure in seconds.

Hunting for what did not alert

L3 analysts run hypothesis-driven hunts against MITRE ATT&CK techniques, looking for the compromise that never matched a rule.

Detection content that keeps up

Rules and correlation logic are tuned to your environment continuously, so new techniques are covered within days, not at the next contract cycle.

Intelligence with regional context

FortiGuard Labs feeds augmented with commercial and sector ISAC data, so adversary infrastructure is blocked before it is aimed at you.

Evidence assembled as it happens

Events map to the UAE regulatory stack as they are logged, so the audit pack exists before the assessor asks for it.

Services

SOC services we operate

Not every organisation needs every layer on day one. We will tell you which of these your environment justifies and which would be paying for coverage you already have.

24x7 SIEM monitoring

FortiSIEM correlates events from cloud, network, identity and endpoint sources in real time, with analysts investigating what the correlation surfaces, not passing it straight on.

Endpoint detection and response

FortiEDR and XDR provide behavioural blocking of ransomware, credential theft and fileless attacks, acting on behaviour, without waiting for a signature to exist.

Network detection

FortiNDR analyses east-west traffic and user behaviour inside the network, which is where an intrusion spends most of its time and where perimeter tools stop looking.

Email and deception

FortiMail and FortiDeceptor extend detection to the delivery route most intrusions still use, and to decoys that produce a high-confidence signal when touched.

Automated containment

Shuffle SOAR executes pre-approved playbooks on confirmed threats, isolating endpoints and revoking credentials in seconds instead of waiting on a rota.

Open automation platform

Shuffle carries over 300 integrations and no per-playbook licensing, so automation coverage is decided by what is useful, not by what each new playbook costs.

Incident response hours included

Bundled IR hours come with the service, 20 on Advanced and 80 on Sovereign. Forensic work during a confirmed breach is not a separate negotiation.

Post-incident reporting

Incidents are tracked end to end against MITRE ATT&CK, from detection through recovery to a root-cause report written to be read outside the security team.

Proactive threat hunting

Analysts work in tiers. L1 and L2 validate and escalate, and certified L3 analysts run hypothesis-driven hunts for indicators no rule has flagged. That is the category dwell time is made of.

MITRE ATT&CK coverage

Detection coverage is mapped to ATT&CK techniques and reported, so gaps are a known quantity, not an assumption.

Threat intelligence

FortiGuard Labs intelligence augmented with commercial feeds and sector-specific ISAC data, focused on adversaries active in the GCC.

Detection engineering

Rules, use cases and correlation logic are developed and tuned against your environment as it changes and as new techniques appear regionally.

Multi-cloud visibility

AWS Middle East, Azure UAE and local sovereign clouds monitored through one view, covering misconfiguration, identity abuse and unauthorised data movement.

Data residency

Security telemetry is processed and held inside UAE jurisdiction, which is a requirement under the PDPL for some organisations and a procurement condition for others.

Compliance evidence packs

Monthly reporting includes the evidence an assessor asks for, mapped to the framework you report against.

Co-managed authority

On Sovereign, your team retains defined authority over containment actions, so automation runs inside limits you set, not ones we assume.

Compliance

The frameworks SOC reporting has to satisfy

UAE regulation is specific about monitoring, logging and incident evidence. Reporting is mapped to the control being examined so an audit is a retrieval exercise.

NESA and the UAE Information Assurance Standards

The IAS expects continuous monitoring, retained logs and demonstrable incident handling. Events are mapped to the relevant controls as they are generated, and the monthly pack carries the evidence, not a pointer to an archive.

DESC ISR

Dubai government and semi-government bodies are examined on detection coverage, response times and closure. Incident records run from first detection to root cause in a form an assessor can follow without a follow-up request.

UAE PDPL and data residency

The Personal Data Protection Law shapes where telemetry may be processed and how long it may be held. Security data stays inside UAE jurisdiction, which is the part most easily overlooked when a SOC is bought from outside the region.

SAMA CSF, NCA ECC, ISO 27001 and PCI DSS

Financial, Saudi-regulated, certified and cardholder environments each ask for monitoring evidence on their own cycle. Reporting maps to whichever set applies, instead of one generic report that leaves the mapping to you.

How we work

How the SOC runs

iConnect SOC analysts in Dubai

Telemetry is connected from cloud platforms, on-premises networks, identity providers and endpoints, so correlation happens across sources, not inside any single one.

  • Log sources agreed against what each one actually contributes to detection, not against a list of everything that can emit a log
  • Coverage gaps named at the start, because a source no one listed is the one an intrusion uses
  • Retention set against the framework you report on, not a default

FortiSIEM correlates events and filters false positives so analysts spend their time on incidents, not on noise. That is what decides whether a night shift is worth paying for.

  • Baseline detections in place from around day 30, tuned to your environment by about day 90
  • Triage tuned against your normal behaviour, since one organisation's anomaly is another's scheduled batch job
  • Mean time to detect and mean time to respond reported monthly, so MTTD and MTTR are a trend and not a claim
  • Only validated, high-fidelity incidents escalated to your team

Certified analysts confirm what the platform surfaces, and hunt for what it did not, working from hypotheses about technique, not waiting for a rule to fire.

  • Hypothesis-driven hunts run against MITRE ATT&CK techniques seen regionally
  • Findings fed back into detection content, so a hunt result becomes a rule
  • Quarterly hunting on Advanced, monthly with ATT&CK coverage reporting on Sovereign

Confirmed threats trigger pre-approved playbooks, and the actions permitted are agreed with you before anything is authorised to run unattended.

  • Containment scope agreed in advance, so nothing business-critical is isolated without a conversation first
  • Bundled IR hours cover hands-on forensic work, 20 on Advanced and 80 on Sovereign
  • Root-cause report issued after the incident, written for readers outside the security team
Why iConnect

Why organisations choose iConnect for SOC services

Telemetry that stays in the UAE

Security data is processed and retained inside UAE jurisdiction, which settles the residency question before procurement raises it.

One fabric, not a translation layer

FortiSIEM correlates natively from FortiEDR, FortiGate, FortiNDR, FortiMail and FortiDeceptor, which onboards faster and correlates better than a stack assembled from unrelated products.

Automation without a licence meter

Shuffle carries no per-playbook fee. The number of automated responses is decided by what is worth automating, not by what each one costs.

Response hours already in the contract

Bundled IR hours mean a confirmed breach is handled under the agreement, not renegotiated during it.

Authority you can keep

The co-managed model on Sovereign leaves your team in control of what may be contained automatically and what needs a human decision.

Audit evidence as a by-product

Events map to NESA, DESC ISR, PDPL and the rest of the stack as they are logged, so the pack assembles itself.

Client feedback

What our clients say

“Whenever an issue arises, iConnect is there immediately: quick, efficient and proactive in keeping everything running without disruptions. iConnect has become a crucial part of our operations.”

Head of IT Infrastructure and Network SecurityDragon Oil
FAQ

SOC questions we get asked

The labels overlap and vendors use them loosely. In practice MDR usually means detection and response on the endpoint estate, delivered on the provider's tooling. A managed SOC covers a wider surface, taking telemetry from network, identity, email and cloud alongside endpoints. It can also be co-managed, so your team keeps authority over what happens on your systems. Three questions matter more than the label. Which data sources are ingested, who may take a containment action, and how fast that action happens at three in the morning.

It depends on the tier. Essentials runs 8x5 monitoring with 24x7 alerting, which suits organisations that want cover without a night shift decision path. Advanced and Sovereign both run 24x7 monitoring and response. An analyst is watching your environment outside your working hours, and is authorised to act on it. The distinction to check when comparing providers is whether out-of-hours means someone watching or someone permitted to intervene.

Security telemetry is processed and retained inside UAE jurisdiction. That matters under the UAE Personal Data Protection Law, and for public sector bodies with residency obligations. Ask any provider the question directly. A regional support desk is not the same thing as regional data storage. We monitor across AWS Middle East, Azure UAE and local sovereign clouds through a single view, not one console per platform.

A managed SOC is operational from around day 30, which covers log source connection, baseline detections and the first playbooks. It is properly tuned by about day 90, once normal behaviour in your environment is understood well enough to stop treating it as suspicious. Any provider promising full value on day one is describing a product installation, not a detection capability. Tuning cannot happen before there is traffic to learn from.

Confirmed threats trigger pre-approved containment playbooks. Those isolate the affected endpoint, revoke compromised credentials and block the infrastructure involved. What is pre-approved is agreed with you in advance, so nothing is disconnected that your business cannot afford to lose without a conversation first. Every tier above Essentials includes bundled incident response hours, 20 on Advanced and 80 on Sovereign, so a confirmed breach does not arrive with a separate invoice attached.

Security events and audit logs are mapped to the UAE regulatory stack. That covers NESA and the UAE Information Assurance Standards, DESC ISR, the UAE PDPL, SAMA CSF, NCA ECC, ISO 27001 and PCI DSS. Monthly reporting includes a compliance evidence pack. That is the part that saves time at audit. The evidence is assembled as it is generated, not reconstructed from log archives once an assessor asks for it.

Neither is useful, and both are common. Alert triage happens inside FortiSIEM before anything reaches you, and analysts validate what the correlation surfaces, so what arrives is a high-fidelity incident, not a queue. Reporting is monthly on Advanced and Sovereign. Advanced adds quarterly threat hunting. Sovereign runs it monthly, with MITRE ATT&CK coverage reporting. The report says what was hunted and what was found, not how many events passed through.

SOC as a service means the platform, the analysts and the response process come from a provider on a subscription. You are buying a running capability, not a licence to build one. The alternative is an in-house SOC, which needs the tooling plus enough analysts to cover three shifts, leave and attrition. Most organisations compare the two on total cost and on how long each takes to reach useful coverage.

It depends on scale and on how much security work you already carry. An in-house SOC needs enough analysts to staff three shifts, plus cover for leave and attrition. On top of that sits the platform, the detection content, and someone to keep both current. A provider spreads that cost across clients. Large regulated organisations often run both: an internal team holding business context and escalation, with a provider covering nights and weekends.

Largely, yes, and the honest answer is that it depends on what they emit. The SOC runs the Fortinet Security Fabric end to end. FortiSIEM correlates events natively from FortiEDR, FortiGate, FortiNDR, FortiMail and FortiDeceptor, with no translation layer in between. That onboards faster and correlates better. Third-party sources are ingested where they produce usable telemetry. We will tell you during scoping which of your existing tools earn their place in the detection pipeline and which are producing noise.

Contact us

Talk to our team about your requirement

We’re happy to answer any questions you may have and help you determine which of our services best fit your needs.

Our Value Proposition

What happens next?

1

We’ll arrange a call at your convenience.

2

We do a discovery and consulting meeting 

3

We’ll prepare a detailed proposal tailored to your requirements.

Schedule a Free Consultation