Monitoring & incident response
DeviceHub monitors security-related events and defines processes for efficient incident detection, analysis, and response.
Continuous cloud security monitoring
We operate centralized security monitoring for our cloud environment to quickly detect, assess, and respond to threats.
- Centralized telemetry & SIEM aggregation
Security signals from our Microsoft cloud services are collected and analyzed within a Security Information and Event Management (SIEM) platform to provide real-time visibility and alerting.
- Automated detection & analytics
We employ automated detections—combining rule-based alerts and behavioral analytics—to identify anomalous activity and potential threats, with continuous tuning to reduce false positives.
- Log retention
Security logs, including audit and login events, are retained for 365 days in line with our policy to support investigations and compliance.
- Incident response
A dedicated Incident Response (IR) team follows a documented process with defined escalation paths.
- Monitoring scope
Our monitoring is presently focused on identity and access telemetry from Microsoft Entra (sign in and audit events).
- Resilience & Recovery
We leverage Microsoft services to protect data and sustain operations in the event of an incident.
