Blackpoint Cyber SNAP: 24/7 SOC Monitoring

What Blackpoint Cyber SNAP is

You are probably reading this because your plan includes managed detection and response, and Blackpoint Cyber SNAP is the platform we run it on. SNAP watches for activity that means somebody is in an account or on a device who should not be, and behind it sits a staffed security operations center: real analysts, on shift, every hour of the day.

This is the human layer of our managed detection and response service, part of the wider managed cybersecurity and compliance stack. The other layers try to stop things. This one works out what got through.

What happens when an alert comes in

Threat detection software is good at raising alerts. What matters is the next few minutes.

An analyst reads it and makes a call. Most alerts are not incidents: a vendor’s scheduled task doing what it has done for a year. The one that matters usually looks ordinary, like a correct password used at an odd hour from an unfamiliar network.

When the call is that it is real, the response starts on the authority you gave us when the service was set up. Containment first, phone call second, cleanup and the written account after. At 3am there is no other order that helps.

What you will see during an incident

  • A phone call, to the contacts you named for exactly this, at whatever hour it happens.
  • A device that has gone quiet. Device isolation makes a machine behave as though somebody unplugged the network cable — no internet, no file shares, no email sync — and some are shut down outright. That is deliberate and reversible.
  • An account that will not sign in, until we have reset the credentials and confirmed it is yours again.
  • A ticket, so there is one thread for questions.
  • A written summary once things are stable: what was seen, what was concluded, what was done.

What you will notice the rest of the time

Almost nothing, most months. SNAP runs in the background and never asks you to make a security decision, so it is not the approval prompt you know from ThreatLocker, a different layer.

One thing is worth knowing in advance. If we call and ask you to stop using a device, stop using it. Do not restart it, do not power it back on, and do not try to clean anything up. Leave it alone and work from another machine until we say it is safe.

Why we run Blackpoint Cyber SNAP

Buying a detection platform is easy. Staffing it is not. Three shifts of trained analysts is not something a business your size should be building, and one person with a pager is not coverage.

Your monitoring runs on Blackpoint Cyber SNAP, with the vendor’s own staffed 24/7 SOC behind it, on Advanced plans and up. The people come with the platform, and the authority to contain something at 3am is written into the service, not improvised during an incident. If you are not sure this layer is on your plan, ask your account manager.

The service behind this article

For the service-level view, endpoint protection and EDR covers the agent on your device and what it stops by itself, and incident response and disaster recovery planning covers the plan the SOC’s actions plug into once an incident is confirmed.

Common questions

Do I need to do anything when the SOC calls?

Answer the phone and do what the analyst asks: confirm whether a sign-in was you, or leave a device alone.

My device was isolated and I have work to do. Now what?

Send a ticket or call and we will tell you where things stand. Isolation buys analysts time to look at the machine before anything else changes on it. Work from another device meanwhile.

Is this the same thing as the antivirus on my computer?

No. The software on your device stops what it recognizes by itself. This is the layer that reads what got through.

What if I spot something myself?

Tell us and let us rule it out. Send a ticket to support@umbrellaitgroup.com or call (904) 930-4261.

Copyright © 2026. Umbrella IT Group. All rights reserved.