Phakamo Managed SOC – Microsoft-Native MDR Control Plane
by Phakamo Holdings (Pty) Ltd
24x7 Sentinel MDR from South African soil. Pure Microsoft delivery. Data never leaves your tenant
Phakamo Managed SOC — built on Microsoft, delivered from South Africa, 24x7
Phakamo Tech is a South African managed security services provider, Level 1 B-BBEE, focused exclusively on the Microsoft security stack. We deliver a fully managed 24x7 Security Operations Centre service on your Microsoft Sentinel and Microsoft Defender XDR estate, integrated with Microsoft Security Copilot — operated by SA-citizen analysts under POPIA-compliant data residency.
Why Phakamo Managed SOC
- Microsoft-native architecture. Your security telemetry stays in your tenant. Phakamo operates via Azure Lighthouse delegation — zero exit risk, strongest POPIA Section 19 position, no shared application.
- Security Copilot integrated. For customers on Microsoft 365 E5, your included Copilot SCU pool powers an analyst experience accelerated by 20+ purpose-built Phakamo promptbooks, four custom plugins, and configured agents (Phishing Triage, Alert Triage, more).
- SA-based 24x7 SOC. Three-tier rotation with continuous coverage. P1 triage SLA from 15 minutes. P1 containment SLA from 60 minutes.
- POPIA evidence built in. Monthly Section 14 / Section 19 / Section 22 evidence packs delivered via standard Phakamo workbooks. Data residency in South Africa North; cold storage with 7-year WORM immutability lock.
What you get
- Microsoft Sentinel workspace operationalised across four data tiers (Analytics, Basic, Auxiliary data lake, Archive) — typically 47%+ ingestion cost reduction versus naive all-Analytics retention.
- Microsoft Defender XDR fully onboarded — Endpoint, Identity, Office, Cloud Apps.
- 12 Phakamo Sentinel workbooks covering Executive Posture, POPIA Evidence, MITRE Coverage, Identity Posture, Endpoint Posture, Cloud Posture, Threat Intelligence, Investigation Cockpit, Insider Risk, Ingestion Health, SLA Performance, and Service Review.
- ~30 Phakamo analytics rules tuned for the SA threat landscape.
- 6 Phakamo SOAR playbooks (Isolate-Host, Disable-Account, Purge-Email, Block-IP, Disable-OAuth-App, Notify-Customer).
- Phakamo curated threat intelligence (CSIR national feed, SABRIC, Phakamo-curated).
- Daily SOC briefing for active incidents; monthly customer service review; quarterly threat hunt session (Professional and above).
Plan tiers
Four plans designed for different scale and sovereignty requirements:
- Essentials — business-hours coverage, baseline content, ingestion up to 25 GB/day. For smaller organisations and proofs of value.
- Professional — 24x7 coverage, full Phakamo content library, Security Copilot integration, ingestion up to 100 GB/day. The standard offer for South African mid-large enterprise.
- Enterprise — Everything in Professional plus custom workbooks and rules, all Copilot agents, weekly threat hunt, named CSM and Technical Account Manager.
- Sovereign — Private Offer only. For national and provincial institutions and regulated entities requiring a dedicated team, bespoke content, and explicit data residency commitments.
Customer references
Phakamo serves major South African public-sector and regulated-industry organisations. References available on request under NDA.
Get started
Select your plan and subscribe. Phakamo will reach out within one business day to schedule the discovery call. Within 7 days from subscribe, your tenant is configured, content is deployed, and your 24x7 SOC service goes live.
For Sovereign-tier engagement, contact sales@phakamo.co.za for a Private Offer.