
WEBCON and Comprehensive SOC as a Service Implementation
Implementation date: 2026
Sector: software, SaaS
The expansion of its SaaS platform, the need to ensure full compliance with the NIS2 Directive, and the growth of its end-client base among companies operating in regulated industries that require a SaaS deployment prompted WEBCON to seek external SOC support.
WEBCON already had event monitoring tools in place, but wanted to enable real-time incident response. The company turned to OChK, which implemented a 24/7/365 SOC as a Service model, covering both environment setup and operational framework design.
Through this project, WEBCON now operates a centralized security monitoring system with continuous visibility into the volume and scope of environmental events. Offloading incident handling to OChK’s SOC allows WEBCON’s team to focus on expanding, optimizing, and maintaining its core platform.
About WEBCON
WEBCON is an AI-powered Business Process Automation (BPA) platform provider. The tool delivers comprehensive end-to-end automation, enabling companies across various industries to digitize and optimize both routine and mission-critical business operations.
Using the platform, internal teams can build enterprise-grade, scalable applications and securely implement AI. Because every solution shares a common architecture and governance model, organizations can create interconnected ecosystems with dozens of tailored workflows. WEBCON also integrates seamlessly with core business platforms, from ERP to CRM systems.
Importantly, the platform enables a collaborative approach where business stakeholders co-design applications from inception, ensuring solutions address actual workforce needs. More than 1,000 organizations in 70 countries automate their business processes using WEBCON, including Tauron, Pratt & Whitney Canada, Mitsubishi Electric, and Südzucker Group.
Challenges
WEBCON develops an enterprise Business Process Automation platform available in SaaS, on-premises, and hybrid deployment models. Driven by SaaS expansion, regulatory requirements under the NIS2 Directive, and a growing client footprint in regulated markets, WEBCON needed to establish a dedicated SOC capability for real-time security monitoring and incident response.
While WEBCON already maintained in-house event monitoring tools, the organization prioritized continuous product evolution, platform optimization, and rapid market responsiveness over managing a dedicated security center. Consequently, WEBCON sought an external specialized partner.
WEBCON selected OChK based on its extensive track record in cybersecurity and regulatory compliance services. OChK's experts recommended deploying a 24/7 SOC as a Service framework to deliver long-term continuous environment monitoring and proactive threat remediation for WEBCON.
Solution and implementation
The implementation of OChK's SOC as a Service solution comprised the following phases:
provisioning the security monitoring environment using Microsoft Sentinel as the SIEM system and Microsoft Defender XDR as the primary SOC operational console to centralize workflows and enhance threat detection efficiency;
implementing an Infrastructure as Code (IaC) framework using Azure DevOps, enabling automated configuration management, detection rule deployment, and environment scaling;
onboarding core log sources—including Microsoft Entra ID, Azure Activity, WAF, AKS, and virtual machines—configuring SIEM integrations, and tuning telemetry collection parameters;
designing, testing, and fine-tuning custom detection rules across key vectors, including identity, access management, administrative operations, and infrastructure activity;
defining and deploying the target SOC operational framework, establishing clear SLAs, communication protocols, and incident response procedures.
Technologies used
The project was executed leveraging the Microsoft security ecosystem alongside an Infrastructure as Code (IaC) approach, ensuring deployment automation and configuration consistency across all components:
SIEM & THREAT PROTECTION
IDENTITY & NETWORK SECURITY
COMPUTE & AUTOMATION
MONITORING & LOGGING
DEVOPS & IAC
Results
By establishing a centralized security operations hub and launching 24/7 SOC as a Service, WEBCON gained full, real-time visibility into security events across its SaaS ecosystem (Azure, WAF, AKS, Entra ID).
OChK acts as the first line of defense; every WEBCON client using the SaaS platform receives bundled SOC protection, providing robust enterprise security guarantees.
Implementing a standardized log ingestion model—leveraging Data Collection Rules, diagnostic settings, and native Azure service integrations—eliminated telemetry fragmentation and boosted analytical precision. In addition, optimizing data collection scopes reduced redundant log ingest, driving cost predictability and control for cloud security monitoring.
Deploying an Infrastructure as Code (IaC) model automated SOC management, strengthened configuration consistency, and streamlined change management workflows.
Close cross-team collaboration, combined with iterative detection rule tuning, tailored monitoring to the platform's specific architectural footprint, significantly reduced false positives, and elevated threat analysis quality.
OChK's SOC specialists handle alert triage, threat identification, and response, freeing WEBCON's internal engineering teams to focus entirely on platform feature development and infrastructure management.
We could have built an in-house SOC team from scratch, but that would have diverted our engineers away from core platform engineering—and product innovation is our top priority. That's why we rely on proven strategic partnerships. They allow us to focus on delivering customer value without compromising on quality or security. OChK took over 24/7 first-line monitoring and immediate incident response. As a result, our engineering team has the bandwidth to drive WEBCON's continuous development, while every SaaS client gets enterprise-grade SOC coverage included out of the box.

Paweł Jawień
VP of Information Security at WEBCON
What are your challenges?
Let's face them together!