How Seculogik helps a small SOC do the work of a large one
Most fully staffed SOCs are two to ten people, and most of them run 24/7 anyway. Here is where the hours actually go, and what a decision layer gives back.
The SANS SOC Survey 2025 puts the most common fully staffed SOC at between two and ten people, and reports that 79% of SOCs run around the clock. Do the arithmetic and a 24/7 rota is impossible at the low end. That team is not understaffed by accident; it is understaffed by definition — and so is the MSSP bench watching several clients from one screen. Every tool such a team buys should be judged by one measure: the hours it gives back.
Seculogik is built for that measure. It is not another SIEM and not another sensor. It sits above the detection stack you already run — open-source SIEM and data stacks such as Wazuh, OpenSearch, Elastic / ELK and ClickHouse; market platforms such as Splunk, Microsoft Sentinel, CrowdStrike, Microsoft Defender, SentinelOne, Cortex XDR, Fortinet, Okta and Entra ID; cloud telemetry from AWS and Azure. If a source is not on the list, we build the connector, or you push events through the generic webhook and map them once. Whatever feeds it, the job is the same: turn the flood of alerts into a small number of qualified cases, and tell the team what to do next.
This post is about where a small team's hours go, and what a decision layer does about each.
Hour sink one: manual correlation
Microsoft and Omdia's vendor-commissioned State of the SOC study (2026) found that two thirds of SOCs lose at least a fifth of their weekly capacity to manual correlation. That is a full day per analyst per week spent joining alerts by hand: the same host name in three consoles, and a decision made from memory about whether they belong together.
Seculogik's Correlation Engine does that joining before a human looks. Nine independent strategies examine every alert from different angles — is this entity already part of an active campaign, is the attack progressing through its stages, did two independent sources see the same thing, is a user's risk building slowly, does the cluster match a recognised attack storyline, has the same attacker artefact surfaced across several cases, does a known-benign pattern explain it all — and vote on one verdict. The analyst opens a case that already knows which alerts belong to it, and why. That "why" stays with the case as a readable decision trace, so the reasoning is still there when the shift changes or the auditor asks.
Hour sink two: noise that looks like signal
Every SOC knows the moment: one rule fires thousands of times in a few minutes. That is not thousands of incidents, and it is not one line in a list either; it is one incident that deserves to be rated higher than any of its parts. Seculogik absorbs the burst and files it as a single, appropriately rated case — hundreds of low-severity failed logons become one high-severity brute-force case — and nothing is lost if a component restarts mid-burst. On the other side of the ledger, a catalogue of known-benign patterns suppresses the scheduled-backup class of event and names the pattern it matched in the trace, so suppressed never silently becomes gone.
Hour sink three: deciding what to open first
Queues without ranking are lists, and lists get worked top to bottom by whoever is on shift. The Decision Center opens on a decision queue instead: awaiting triage, SLA at risk, high risk, unassigned critical — computed the same way every time, so two analysts looking at the same board see the same priorities. Cases are auto-assigned on capacity to the analysts who opted in, SLA clocks run per severity, and the kill-chain position of a case advances with its evidence, so the case that reached lateral movement rises above the one still at initial access. For an MSSP, every client has its own case space, enforced at several independent layers, and an alert that cannot be attributed with confidence waits in a quarantine queue rather than landing in the wrong client's view.
Hour sink four: the write-up
An analyst who has decided still has to explain — to the shift lead, to the client, to the regulator. Seculogik keeps the decision trace with the case: which signals mattered, how the verdict was reached, and what would have changed it. The case report tells that story with its kill-chain position, and the SOC Reporting add-on turns the same evidence into per-client reports, scorecards for NIST CSF, ISO 27001, GDPR, DORA and NIS2, and evidence packs that state their own methodology and coverage. Every number carries the evidence behind it, and a metric that cannot be computed says so rather than guessing. The write-up becomes a by-product of working the case, not a second job at the end of the shift.
Hour sink five: the second opinion nobody has time to give
A two-person SOC has no L2 to ask. SIROC is the L2 in the room: an AI analyst that reads the case, argues it in the open — benign hypotheses first, evidence both ways, verdict last — and has its cited evidence checked against the case's own alerts. A verdict the evidence does not support is downgraded in front of the analyst, not quietly accepted. By default it runs on a local open-licence model on your own CPU, so the second opinion costs electricity rather than an API bill or a data transfer. If you choose to bring your own cloud key for some tasks, secrets and personal data are redacted before anything leaves the box, and every cloud-bound call is written to a tamper-proof ledger. When an analyst agrees or corrects it, the correction is kept with the case, so the second opinion can be improved on your cases rather than on somebody else's.
Hour sink six: the response nobody wants to script at 03:00
Workbooks run the routine — tag, escalate, assign, notify, enrich — so nobody types the same five steps at three in the morning. Before anything destructive, such as isolating a host or blocking an address, the workbook pauses at an approval gate and waits for a person; the pause holds until someone answers, restart or no restart. When the answer is yes, remote response agents on your own hosts carry it out with vendor credentials that stay on those hosts. The platform never holds them.
What we do not claim
We do not claim to replace the analyst, and we do not sell an autonomous SOC. We publish no accuracy percentage of our own, because no credible cross-vendor benchmark for AI triage exists yet and we would rather help build a reproducible one than quote a number nobody can check. We are early, with a design-partner programme rather than a customer wall.
What we do claim is that a small team on Seculogik spends its hours on decisions, and that every decision it makes is ranked, evidenced and still readable when the shift changes. If that is the measure you buy tools by, a demo answers it in thirty minutes, on your own telemetry, from whatever stack you already run.