Managed Security Services

AKATI Sekurity has operated a 24/7 security operations centre for more than a decade. Analysts monitor, correlate and respond across endpoints, networks, cloud workloads and identity, and the same team leads the investigation if an incident occurs.

What is covered

Six services under one contract, delivered by the same team. The security operations centre runs 24 hours a day, every day of the year, staffed by analysts, threat hunters and detection engineers who are already hired, trained and rostered, so cover does not depend on any one person remaining in post.

SOC

Managed Security Operations Centre

A dedicated 24/7 command centre. AKATI deploys and operates the SIEM platform, writes the detection use cases and maintains them as the environment changes. Events are correlated across every log source in scope, alerts are qualified before they reach you, and confirmed activity is escalated with the evidence behind it.

Managed SOC
MDR

Managed Detection and Response

Detection and response agents deployed across endpoints and servers. The SOC handles analysis, triage and containment at the device itself, which covers the laptops and servers a network view alone does not reach.

Managed detection and response
XDR

Extended Detection and Response

Proactive threat hunting for activity already inside the network. Analysts work to the MITRE ATT&CK framework and look for the behaviour that automated defences do not raise on their own.

Extended detection and response
CTI

Cyber Threat Intelligence

The AlphaCERT team delivers curated global threat intelligence and situational awareness, reporting on threats and attacker tactics active in your own sector rather than in general.

Cyber threat intelligence
ASM

Attack Surface Management

Continuous automated discovery of external-facing assets, including domains, addresses and cloud services. Unknown assets and weaknesses are identified and prioritised for remediation.

Attack surface management
Dark Web

Brand Protection and Dark Web Monitoring

Continuous scanning of the open, deep and dark web for brand mentions and leaked credentials, with notification in time to act before exposed material is used against you.

Brand protection

What happens day to day

Collection

Log sources across endpoints, servers, network, cloud and identity are connected to the platform AKATI operates.

Correlation

Events are correlated across sources rather than assessed in isolation, which is what distinguishes an intrusion from routine activity.

Qualification

An analyst reviews the correlated activity and confirms whether it is genuine before anything is raised with you.

Escalation

Confirmed activity is escalated with the supporting evidence and a recommended action, inside the response time set in your agreement.

Containment and investigation

Where an incident is declared, the same team moves into containment, forensic investigation and root cause analysis.

Reporting

Findings, actions taken and the state of the environment are reported back on the cycle agreed in the contract.

Service tiers

Every tier is scoped to the environment. The SIEM licence model, the user count and the number of log sources set the final shape.

Managed security service tiers and the capabilities included in each.
CapabilityLightStandardPremium
StandardStandardPremium
IncludedExtended
Board and staff

Response commitments and retainer hours are set in the agreement. Tell us the environment and the team will put a written scope and a quote against it.

Questions

What does a managed security service provider do?

A managed security service provider operates the security monitoring and response function on a client's behalf. AKATI Sekurity runs a 24/7 security operations centre that collects and correlates events across a client's environment, qualifies what is genuine, escalates confirmed activity with the supporting evidence, and leads containment and investigation when an incident is declared.

What does AKATI monitor?

Endpoints, servers, network infrastructure, cloud workloads and identity systems, together with any other log source brought into scope. Coverage extends beyond the estate itself through attack surface management, which tracks external-facing assets, and dark web monitoring, which tracks leaked credentials and brand misuse.

What is the difference between managed detection and response and a managed SOC?

A managed SOC monitors the whole estate through a SIEM platform, correlating events from every log source in scope. Managed detection and response works from agents placed on endpoints and servers, which allows containment at the device itself. AKATI delivers both, and most clients run them together, with the SOC providing breadth and MDR providing depth.

Does AKATI provide the SIEM platform, or do we?

Either arrangement works. AKATI deploys and operates the platform, writes the detection use cases and maintains them as the environment changes. The platform licence can sit with AKATI or with the client, and that choice is one of the things that sets the price.

What do we need to provide?

Access to the log sources that are being brought into scope, a named contact who can be reached when something is escalated, and an agreed list of actions AKATI is authorised to take without asking first. Everything else, including platform operation and detection engineering, sits with AKATI.

What happens when AKATI finds something?

An analyst reviews the correlated activity and confirms whether it is genuine before anything reaches you. Confirmed activity is escalated with the supporting evidence and a recommended action, inside the response time set in the agreement. Where an incident is declared, the same team moves into containment, forensic investigation and root cause analysis.

Is incident response included?

The Standard and Premium tiers include an incident response retainer, which is a standing block of investigation hours available without raising a new engagement. Gartner named AKATI a Representative Vendor for incident response retainer services in 2025 and again in 2026, and Frost & Sullivan recognised the firm for digital forensics in Asia-Pacific in 2024.

How quickly does AKATI respond to a confirmed incident?

Response times are committed contractually. Every tier carries a response commitment and the Premium tier carries a shorter one. The exact figure is set in the agreement against the environment being covered.

How is the service priced?

Pricing is scoped rather than listed, because the work is driven by the size of the estate. The three variables that matter most are who holds the SIEM licence, the number of users, and the number and type of log sources in scope. Send those three and the team can put a written quote against them.

Offices and coverage

AKATI Sekurity is headquartered in Kuala Lumpur, with offices in Singapore, Hong Kong and New York. The firm serves more than 400 organisations, with clients across five continents and in more than 40 countries, including banks, financial technology firms, payment processors, government regulators and operators of critical infrastructure.

Speak with the team

Tell us the environment, the log sources and what is already in place. The team will come back with a written scope and a quote.