IONSEC

Ongoing retainer

T3aaS — Tier 3 as a Service

Tier 1 and Tier 2 handle volume; the hard cases escalate. T3aaS gives you that senior escalation tier on demand — the reverse engineers, threat hunters and forensic analysts who resolve the alerts nobody else can close — without carrying the headcount full time.

The escalation tier nobody staffs

Tier 1 triages and Tier 2 investigates, but the alerts that resist both — the unfamiliar binary, the beacon that only fires weekly, the anomaly that might be a misconfiguration and might be an actor — need people who reverse engineer for a living. Hiring that skill set full time is expensive and hard to retain, so in most SOCs those cases get closed as inconclusive.

What we plug in

T3aaS gives your existing team a senior escalation path on demand. We take the hard cases through to a verdict, hunt proactively across your estate between escalations, and feed everything we learn back into your detections so the same class of alert resolves itself next time.

Backed by our own research

The analysts on your retainer are the same team that publishes APT research and builds the open-source tooling in our resources section. What we see in the field and in our research shapes the hunts we run for you, often before the technique is widely documented.

Where an escalation ends up

Most cases close where they arrive. The ones that do not are the reason a tier-3 retainer exists: they fall to specialists who do memory forensics and malware reverse engineering every week, instead of sitting in a queue waiting for someone who does it twice a year.
  • Closed at tier 1
  • Tier 2
  • Tier 3
  • Resolved

What you get

  • Named senior analysts with an agreed escalation SLA
  • Written verdict and analysis report for every escalated case
  • Scheduled proactive threat hunts with findings reports
  • Malware analysis reports with IOCs and behavioural signatures
  • Detection rules delivered into your SIEM or EDR, tuned to your estate

Who it is for

  • SOCs and MSSPs without an in-house reverse engineering capability
  • Security teams closing too many alerts as inconclusive
  • Organizations that need Tier 3 depth but cannot justify the headcount
  • Teams whose detection content has drifted out of tune with their estate

Common questions

What is Tier 3 security support?

Tier 3 is the most senior escalation level in a security operations centre: the reverse engineers, threat hunters and forensic analysts who resolve the alerts that Tier 1 triage and Tier 2 investigation cannot close. Tier 1 handles volume and Tier 2 investigates, but cases like an unfamiliar binary or a beacon that only fires weekly need people who reverse engineer for a living.

What is Tier 3 as a Service?

Tier 3 as a Service (T3aaS) gives an existing security team on-demand access to senior escalation specialists — malware analysis, reverse engineering, threat hunting and detection engineering — without hiring that skill set full time. The provider takes the hard cases through to a verdict and feeds what it learns back into the customer’s detections.

Does this replace our SOC?

No. T3aaS sits behind your existing Tier 1 and Tier 2 as the escalation tier. Your team keeps ownership of the queue and pulls us in on the cases that warrant it.

How is the retainer sized?

By expected escalation volume and how much proactive hunting you want alongside it. Unused capacity in a period is applied to hunting and detection engineering rather than lost.

What happens if an escalation turns into a real incident?

We transition straight into our incident response process with the context already in hand — no re-briefing, no waiting on a separate engagement to be scoped.

What is threat hunting?

Threat hunting is the proactive search for attackers already inside an environment who have not triggered an alert. Rather than waiting for detection tooling to fire, hunters start from a hypothesis about attacker behaviour — a technique, a persistence mechanism, an anomalous pattern — and go looking for evidence of it across the estate.

Talk to the team that does the work

Tell us what you are protecting and we will tell you honestly whether T3aaS — Tier 3 as a Service is what you need first.

Or email us directly at[email protected]