SIEM access
For Microsoft Sentinel: Reader access to your Log Analytics workspace, plus Sentinel Reader role. For QRadar: read-only admin access. For Splunk: a service account with search permissions. For Elastic: viewer role on relevant indices.
Communication channel
A named contact (typically IT lead or CISO) for day-to-day communication and an emergency escalation contact for out-of-hours P1 incidents.
Environment documentation
If available: network diagram, list of critical assets (domain controllers, file servers, privileged accounts), and any existing detection rules or known exceptions. Not mandatory - we can work without these and build understanding over time.
Onboarding call
We start with a 30-minute call to review your environment, confirm access, and agree on detection priorities. Adam will have your environment under monitoring within 48 hours of access being granted.
Need more help? Contact Adam directly.
Use email for general support, or phone for active P1/P2 incidents.