At 3:00 AM on a Friday, a finance manager’s account signs in from an unfamiliar country and starts downloading files from a shared drive. The SIEM raises an alert within seconds. What happens next depends on people, not software.
If no analyst is awake, the alert waits in a queue until morning. If someone sees it but has no authority to disable the account, they email a manager who is asleep. Either way, the attacker gets hours to move deeper into the network, and a manageable incident becomes a serious business disruption.
Enterprises across the Middle East and Africa are investing in monitoring platforms. Yet continuous threat monitoring is a staffing and process commitment before it is a technology commitment. This article looks at what makes round-the-clock security operations real: people, shifts, authority, handovers, and evidence.
Genuine coverage means a qualified person can investigate and act on a threat at any hour, not just see it. A Security Operations Center (SOC) running continuously should provide:
A monitored inbox, automated notifications, or an on-call phone number can all claim to be “always on”. None of them guarantees prompt investigation. Acknowledging an alert without the skills, access, or authority to act on it is not incident response. It is only a timestamp.
One analyst seat staffed around the clock needs several people. A week has 168 hours, while a full-time employee works a fraction of them, and cannot sustainably work only nights and weekends.
Illustrative example only, not a staffing standard. Take one seat that must be filled every hour of the year:
In this example, keeping one chair occupied takes five to six people. Two analysts per shift doubles that. Your real figure depends on local working-hour rules, shift length, leave entitlements, handover overlap, and how much resilience you need.
Covering the gap with overtime or a few experienced analysts tends to cause fatigue and turnover. When one key person leaves, the night rota can collapse.
Overnight coverage works only if the right level of expertise is reachable when an alert turns serious.
Senior expertise can be made available at night through specialists on shift, a regional team in another time zone, or a defined escalation arrangement with committed response times.
Tier labels prove nothing on their own. A “Tier 3 team” reachable only during office hours does not help at 3:00 AM. Ask what each tier actually does overnight, how fast it responds, and what it is allowed to decide.
A shift handover is a security control, not paperwork. Context lost between shifts can be as damaging as a missed alert. A good handover covers:
Consider a service account showing unusual logins at 9:45 PM. The evening analyst has confirmed two sign-ins from a new IP range and asked the application owner whether a migration is under way. The shift ends at 10:00 PM. If the handover says only “watching payroll account”, the night analyst may close the next alert as noise, or repeat the same checks and lose an hour.
Structured templates, case-management records, checklists, and written escalation notes keep each investigation moving as one thread instead of restarting at every shift change.
When an incident needs action on a weekend night or public holiday, the deciding question is who can approve it. Define in advance:
Technical escalation, passing an alert to a more senior analyst, is not the same as decision authority, permission to take a production system offline. Both need named people and response times.
A process that only notifies managers who are asleep or travelling creates the appearance of coverage. The alert is escalated on paper while the attacker keeps working. Pre-approved containment for well-understood scenarios, such as isolating a laptop showing confirmed ransomware behaviour, closes much of this gap.
Night-shift decisions should match the quality of daytime ones. Fatigue, workload, staff turnover, and uneven experience all pull quality down unless it is checked. Practical controls include:
If review results differ between day and night shifts, that gap is the clearest sign that coverage exists on the rota but not in practice.
The Middle East and Africa is not one operating environment. A rota that works in one country often needs adjusting in the next.
This is why a global rota cannot simply be copied into every Gulf market. Validate holidays, working arrangements, and legal obligations for each country you operate in.
| Model | Staffing availability | Investigation | Response authority | Escalation | Key limitation |
|---|---|---|---|---|---|
| Continuous staffed SOC | Qualified analysts on shift every hour | Immediate | Defined, including pre-approved containment | Documented matrix with backups | Highest staffing and planning effort |
| Monitored inbox or alert queue | Alerts collected continuously, people not always present | Delayed until staff are available | Usually none out of hours | Often informal | Threats progress while alerts wait |
| On-call arrangement | Staff contacted when needed | Depends on who answers, and how fast | Varies with the person reached | Depends on availability | Response time uncertain, especially on holidays |
| Automated monitoring with human escalation | Technology runs continuously, people act per procedure | Automated enrichment, human validation | Automated actions only where pre-approved | Defined by playbooks | Only as good as its playbooks and people |
Automation and on-call support are valuable parts of a SOC. Neither should be presented as equal to fully staffed continuous operations unless the service design actually supports that claim.
Ask providers to show, not tell. Request evidence of:
A provider that offers a “24/7” label but cannot produce these documents is asking you to trust a marketing statement.
These indicators help show whether continuous security operations are working:
Read these together and split them by shift. A two-minute acknowledgement means little if the alert then sat uninvestigated for four hours. Strong daytime numbers can also hide weak performance at night.
Building all of this in-house is demanding, so some enterprises use managed SOC services to reach specialist analysts and established shift structures. Providers such as Sattrix, which operates a CREST-certified SOC, are one option for organizations planning 24/7 SOC coverage in MEA. Whichever route you choose, assess service scope, staffing, escalation, and response authority individually rather than assuming they come with the label.
Continuous monitoring works only when people, processes, and technology hold up through every shift, including 3:00 AM on a public holiday. A SIEM and an alert queue are the starting point, not the finish line.
Before trusting any coverage promise, from your own team or a provider, confirm four things: who investigates alerts at night, who is allowed to act, how context passes between shifts, and what evidence shows it working. Evaluate the capability behind the coverage promise, not the availability label.
It means qualified analysts can investigate and act on security alerts at any hour, including nights, weekends, and holidays. Genuine coverage includes triage, investigation, defined escalation paths, and authority to start approved containment. Collecting alerts continuously without anyone able to act on them does not meet that standard.
There is no universal number. One seat staffed every hour needs 8,760 hours of cover a year, and one analyst provides far fewer once leave, holidays, and training are deducted. Illustrative calculations often land around five to six people per seat, but local rules and shift design change the result.
Monitoring means alerts are collected and reviewed at all hours. Incident response means someone can investigate, decide, and act, for example by isolating a device or suspending an account. A service can offer the first without the second, so check response authority and response times specifically.
Investigations often outlast a single shift. A structured handover passes on open cases, evidence, actions taken, assets to watch, and pending escalations, with named ownership. Without it, the next analyst may close a live threat as noise or waste time repeating work already done.
Weekend days differ between countries, and religious holidays such as Eid follow the lunar calendar, so their dates shift every year. Rotas need early planning for these periods, plus confirmed escalation contacts in each country, because business decision-makers may be unavailable on different days.
On-call support can be valuable, but response depends on who answers and how quickly. Unless response commitments are documented, measured, and tested, including at night and on holidays, an on-call arrangement should not be treated as equal to staffed continuous operations.
Useful measures include time to acknowledge, mean time to detect, mean time to respond, time to escalation, service-level compliance, handover quality, and after-hours exercise results. Review them together and by shift, because fast acknowledgement alone does not prove an alert was properly investigated.
Ask for overnight and holiday staffing details, escalation matrices, containment decision authority, sample handovers, service-level definitions and measurement methods, quality assurance reports, and evidence from real incidents or exercises. Documented proof matters more than a service description claiming the SOC never sleeps.