// FAQ

Answers from the people doing the work.

Common questions from CISOs, IT directors, and security teams about how SENTINEL works, what we deliver, and what it costs.

// Onboarding & delivery

How fast can we onboard to the SOC?

Typical onboarding is 2–4 weeks. We start with asset discovery, log source inventory, and use-case mapping, then bring you live with custom runbooks and escalation paths.

Do you replace our existing SIEM?

We work with what you have. If your SIEM isn't the right fit, we bring our preferred stack (Splunk, Sentinel, or Elastic) — but we never force a rip-and-replace unless it's the right answer.

What does a typical first 90 days look like?

Days 0–30: discovery, log onboarding, baseline. Days 31–60: use-case development, alert tuning, runbook creation. Days 61–90: full SOC operations, first quarterly review. We publish a written report at the end of every 30 days.

Can you take over a half-built security program?

Yes — we run a 1-week "rescue audit" to stabilize the current state, then a 30-day plan to either fix or replace what's not working.

// Incident response

What happens if we get breached while on retainer?

Call the hotline. A senior incident commander is on the line in 60 minutes (or 15 minutes for top-tier). We isolate, contain, and recover — and we have ransomware negotiators on staff.

Do you help with ransom payment decisions?

Yes. We help you evaluate options, negotiate when appropriate, and — in 64% of our cases — avoid payment entirely by recovering from backups. We never recommend paying if there's a viable alternative.

Do you support law enforcement and regulators?

Yes. We provide court-admissible evidence, work with the FBI / Interpol / national CERTs, and support GDPR / SEC / HIPAA disclosure processes with your legal team.

// Team & operations

Are you vendor-agnostic?

Yes. We integrate with what you run — Splunk, CrowdStrike, SentinelOne, Palo Alto, Wiz, AWS, Azure, GCP — and we'll never push what you don't need.

What certifications does your team hold?

OSCP, OSEE, OSCE, CREST, CISSP, CISM, GIAC (GCIH, GCFA, GCFE, GREM, GCTI), AWS Security Specialty, CCSP. 100% of analysts hold at least one senior security certification.

Where is your team located?

Distributed across EU, North America, and APAC, with overlap hours for most time zones. Three SOCs: Dublin, Austin, Singapore. We sign BAAs and DPAs before any data flow.

// Pricing & commercial

What does it cost?

Essentials starts at $4.5k/month, Professional at $12k/month, Enterprise is custom. Pen tests start at $8k; IR retainers at $25k/year. See the pricing page for the full breakdown.

Do you sign NDAs and DPAs?

Yes — before the first call. We also support HIPAA, SOC 2, ISO 27001, and PCI DSS requirements out of the box.

Can we do a pilot?

Yes. We offer a 90-day pilot on all our managed services — fixed price, with mutual exit terms. About 30% of pilots don't convert to long-term engagements; we tell you when that happens.

What happens after launch?

We offer SLA-backed support, on-call rotations, monthly business reviews, quarterly purple-team exercises, and an annual roadmap partnership.

// Compliance

How do you handle data privacy & sovereignty?

Data stays in your region by default. EU SOC is GDPR-compliant with EU-only residency; US SOC follows HIPAA and CCPA. We sign BAAs and DPAs before any data flow.

Do you support ISO 27001 / SOC 2 / PCI DSS / NIS2?

Yes. We support gap assessments, control implementation, evidence collection, internal audits, and certification support across all major frameworks.

Are you certified?

Yes. SENTINEL itself is SOC 2 Type II and ISO 27001 certified. We are CREST-accredited for pen testing and a certified PCI QSA. Ask for our latest reports.

// Still have questions?

Talk to a senior engineer.

No salespeople, no scripts. 30 minutes, no charge, and you'll leave with at least one useful answer.