Short answer
No. FirstNet does not run its own SOC (security operations centre). Sophos MDR delivers the 24/7 SOC layer, including threat hunting and analyst-led detection, and FirstNet's Incident Response team acts on its alerts with you.
In detail
The model has two arms. It works like this:
- Sophos MDR analysts watch your environment, hunt for threats and send an alert when they spot suspicious activity.
- FirstNet's support desk receives the alert.
- FirstNet's Incident Response team then works with you to contain the threat, fix the cause and recover.
- An incident response runbook, agreed at onboarding, sets out how alerts arrive, who steps in and which remediation playbook applies.
Around this, FirstNet handles onboarding, setup, customer success, compliance reporting and escalation for every Sophos deployment. Higher support tiers add expanded incident response. The Premium tier includes on-site remediation support where it applies.
FirstNet is a Sophos MSP and Titanium Partner. Titanium is the top tier of the Sophos Partner Program, and it gives FirstNet direct escalation paths into Sophos.
Source: FirstNet Security service page →
Didn’t answer your question?
