Wake County Public Schools currently leverages CrowdStrike Falcon as its primary endpoint protection platform. This solution delivers comprehensive threat prevention, real-time detection, and rapid response capabilities to protect district-wide devices from evolving cybersecurity threats, including malware, ransomware, and other advanced persistent threats. To further strengthen our security posture and ensure proactive threat management, we are exploring opportunities to augment our current capabilities by partnering with a seasoned external cybersecurity provider. The selected vendor must demonstrate the ability to: • Integrate effectively with CrowdStrike Falcon to enable real-time telemetry ingestion, threat intelligence sharing, and coordinated response actions. • Provide scalable, future-ready services that address the district’s current needs while remaining flexible to accommodate future technological investments and strategic priorities particularly the Microsoft Security Suite. • Deliver expert-level support across all Security Operations Center (SOC) tiers from Level 1 alert triage to Level 3 threat hunting and forensic analysis with a strong emphasis on proactive threat detection, incident response, and strategic security advisory. 1. Scope of Services Required This RFP specifically focuses on the provision of Level 2 and Level 3 SOC services. Proposers should detail their approach in delivering all levels of the following: 1.1 Level 1: Monitoring and Escalation Only • Security Event Monitoring: Continuous (24/7/365) observation of log sources and telemetry to detect potential security events from our CrowdStrike Falcon deployment and other integrated sources. • Alert Triage: Initial review and prioritization of events based on severity, business impact, and urgency. • Escalation and Notification: Timely notification of significant alerts to designated district personnel via agreed communication channels (e.g., email, SMS, phone, or ticketing system). 1.2 Level 2: Monitoring + Limited Response Support Building upon our existing Level 1 capabilities, the selected vendor will provide: • Advanced Log Analysis • Containment Support • Coordination and Contextualization