The SocSage blog

Field notes from the agentic SOC.

Deep dives on Microsoft Sentinel, alert fatigue, human-in-the-loop security, BEC investigations and the economics of running a SOC as a UK MSP. No listicles, no fluff — the kind of post we wish had existed when we were building this.

MSP Business

SOC Economics for UK MSPs: Build vs Buy vs Augment in 2026

A numbers-first breakdown of the three ways a UK MSP can deliver SOC services to SME clients — build an in-house SOC, buy an MSSP, or augment Tier 1 with agentic AI. Which wins depends on your book, your margin, and your appetite for operational risk.

30 May 202612 min read
Compliance

Cyber Essentials Plus for Microsoft 365: 2026 Controls Checklist

Table-stakes for UK public sector contracts. The complete 2026 controls checklist, mapped to the exact Microsoft 365 settings your assessor will check.

23 May 20269 min read
Incident Response

BEC on Microsoft 365: How an AI SOC Investigates It in 90 Seconds

Step-by-step walkthrough of a real Business Email Compromise investigation — from Sentinel impossible-travel alert to quarantined mailbox.

16 May 20268 min read
Microsoft Sentinel

Microsoft Sentinel Alert Fatigue: How AI Triage Cuts Through 85% Noise

Sentinel produces 10,000–50,000 alerts per tenant per month. Most are noise. How agentic triage resolves 60% before a human sees them.

9 May 20267 min read
Security Operations

What Is HITL (Human-in-the-Loop) in Cybersecurity?

HITL is a mandatory approval gate between AI investigation and AI action. Why it's the right pattern for agentic SOC, with real examples.

2 May 20266 min read
AI & Automation

What Is Agentic AI in Cybersecurity? (And Why It's Changing the SOC)

Agentic AI means autonomous investigation with a human gate on destructive actions. What it actually looks like inside a SOC — and why it changes the economics.

25 April 20267 min read

See it in your own tenant.

The posts are the theory. A 14-day pilot on one of your real tenants is the proof.

Start 14-day pilot Talk to a human