Many organisations buy a SIEM, connect a few firewalls and domain controllers, and call it a SOC. Months later the console is full of alerts nobody trusts, analysts close tickets out of habit, and the first real sign of an intrusion comes from a user or a third party. Collecting logs is the start of monitoring, not the end of it. Real maturity is measured by how reliably the team detects genuine threats and responds in time.
Stages 1 and 2: coverage and a use-case library
The first stage is about knowing what you can actually see. Inventory your critical assets and map them to log sources: identity providers, domain controllers, VPN and remote access, email, endpoints, firewalls, DNS, proxies, cloud control planes and core business applications. Check that time is synchronised, that logs are parsed into a consistent schema, and that you are alerted when a source goes silent. A log source that stopped sending three weeks ago is worse than none, because it gives false comfort.
The second stage is a use-case library tied to real risk. Vendor default rules generate volume, not relevance. Record each use case in writing: the threat scenario, the log sources required, the detection logic, the expected false-positive profile, the response playbook and an owner. Map every entry to MITRE ATT&CK techniques so you can see coverage and, more importantly, gaps. Then prioritise by sector:
- Banks and financial institutions: abuse of privileged accounts, unusual activity around payment and messaging systems, and changes to SWIFT-connected infrastructure, in line with the SWIFT Customer Security Programme (CSP).
- Government bodies: credential abuse, unauthorised data transfers and lateral movement between network zones.
- Private companies: follow-on activity after phishing, remote access abuse, and ransomware precursors such as mass file modification or backup tampering.
Stage 3: detection engineering and automation
Treat detections as code. Keep rules in version control, peer-review every change, test rules against recorded or simulated attack data, and track metrics per rule: how often it fires, how often it is a true positive and how long it takes to triage. Tune or retire rules that never earn their place.
Once playbooks are stable, introduce SOAR automation for the repetitive work: enriching alerts with asset and identity context, checking indicator reputation, collecting evidence and opening tickets. Keep a human in the loop for high-impact actions such as disabling accounts or isolating servers until the playbook has proved reliable. Align the overall incident process with NIST SP 800-61 so that roles, escalation and lessons learned are defined before a real incident arrives.
Stage 4: purple teaming, hunting and measurement
Purple teaming puts the attacking and defending sides in the same room. Choose an ATT&CK technique, execute it in a controlled way, and observe three things: did the tooling detect it, was the alert actionable, and did the analyst know what to do. Every miss becomes a new or improved detection. It is the most efficient way to validate a use-case library, because it tests your detections against behaviour rather than assumptions.
Threat hunting is hypothesis-driven. For example: if an attacker held valid credentials, what would service-account behaviour look like in our environment? Hunts depend on rich endpoint and identity data, and every successful hunt should end as a permanent detection. Hunting without that feedback loop is a hobby, not a capability.
Measure progress with meaningful indicators rather than raw alert counts:
- Log-source coverage of critical assets.
- ATT&CK coverage of the techniques relevant to your threat profile.
- Mean time to detect and mean time to respond.
- The proportion of alerts that turn out to be true positives.
- The share of incidents handled through tested playbooks.
Review these quarterly and set one or two improvement goals at a time, rather than trying to advance every stage at once.
How Wethaq ICT helps
Wethaq ICT designs and operates SOC services that follow this progression. We assess your current visibility, build a use-case library aligned to your sector and to MITRE ATT&CK, engineer and tune detections, automate routine response and run purple-team exercises with your team. Whether you build in-house, use a managed service or combine both, we help you advance one measurable stage at a time.
Let’s build a secure foundation for your digital future
It starts with a free consultation: we learn your challenges and goals, then propose a service package tailored to your needs and budget.

