Konfirmity
Layer 6 of 7 — Security Operations

// security operations

Somebody is watching, and you can see who

L6 is the layer a compliance platform cannot fill in. It reports the threats currently affecting you and the incident work still open, because there is a staffed desk behind it.

// what it watches

What this layer watches

Security Operations reports “Set Up” until the right integration is connected, because until then there is nothing honest to say about it. A platform that showed you green here would be describing an environment it cannot see.

  • Threat intelligence matched against your actual environment, not a generic feed
  • Detections raised from your cloud and endpoint telemetry
  • Incident response work and whether it is inside its SLA
  • Coverage itself: whether a detection reached an analyst at all, which is what the managed desk is accountable for

// what turns it red

What turns it red

Each row is a live measurement on your own environment, not a checklist item. The third column is the part a compliance-first tool cannot offer.

What is measuredWhat it saysWhere clicking it takes you
Threat intelligence currently matching your environment rather than a generic feedN Threats Affecting YouThe security operations surface, with the matched threat named
Open work on the incident response SLA categoryN Open IncidentsThe incidents queue
Detections raised from your cloud and endpoint telemetry, worked to a determinationN Open IncidentsThe signal record, its verdict and its closure
Signals that reached no analyst at all, recorded as a coverage gapCoverage gapThe desk's own accounting, and your monthly availability figure
Work parked because it cannot progress without you acting in your own environmentBlocked on clientA queue of its own, so it is never mistaken for finished
Whether security operations is switched on for youSet Up SOCThe security operations surface

This table is not the whole check

Behind this layer sits a full detection lifecycle: agentic triage with stated grounds, tiered analysts on recorded shifts, correlation, suppression scoping and a client-approved baseline. No table does that justice.

See how deep we go

// getting to green

What it takes to go green

  1. Telemetry is collected from the environments you have already connected at L1 and L5.
  2. Every detection is triaged by machine before a human sees it, and the machine records what it concluded and why.
  3. An analyst takes ownership, investigates, and closes with a determination and a written analysis you can read.
  4. The layer clears when no threat is affecting you and no incident work is open.

// the evidence

The evidence this produces

None of this is collected for the auditor's benefit. It is the by-product of work that had to happen anyway, which is why it holds up when someone checks.

  • Monitoring and incident response evidence, produced by operations that actually ran
  • A per-signal record of what was detected, what the machine concluded and what the analyst decided — follow one signal through
  • Incident timelines that survive an auditor asking what happened on a specific date

// questions this answers

Security operations coverage, answered directly

Is this a dashboard or a staffed service?

Staffed. L6 reports the threats currently affecting you and the incident work still open because real analysts on recorded shifts are working those signals. A compliance-first platform cannot fill this layer in, because there is nobody behind it.

What happens to a detection before an analyst sees it?

An agentic investigation gathers context and reaches a verdict, recording the grounds it rests on. That happens on every signal, and the machine only acts on its own conclusions for alert types where it has earned that authority from analyst review.

What if a detection reaches nobody?

It is recorded as a coverage gap rather than sitting in a queue nobody is watching. The distinction Konfirmity draws is whether anyone was ever asked, not whether anyone replied.

Want to see this one live?

Book 30 minutes and we will walk through “Somebody is watching, and you can see who” in the actual platform, using your environment as the example.

Book a demo