TecnetSOC Updates: July 2026

TecnetSOC in July 2026: automatic isolation with live case tracking, exposure alerts by email and backup recovery drills from your portal.

October 6, 2026 6 min read
TecnetSOC Updates: July 2026

Your TecnetSOC portal rolled out several things in July, and you don't have to wait for any of them: they're already live in your account. We'll start with the ones that will change your day to day. If June was the month of giving you control, July is the month of giving you proof: your portal stops asking you to trust it and starts showing you what it does.

TecnetSOC now stops the threat and shows you every step

Live investigation detail in the TecnetSOC portal

When something happens, the first question is always the same: is someone on it? Now the answer is on your screen.

When we confirm a threat on one of your devices, the platform can isolate it from the network automatically to stop the attack, and the case opens as a live page that updates while our team works.

  1. You choose the level of automation: device by device, you decide whether isolation is automatic or you'd rather we contact you first. Critical infrastructure devices are never isolated on their own.
  2. Follow the response live: a stage timeline shows where the case is, from detection to closure, and every action appears with its time, who did it and its result.
  3. Know when the first response arrives: with a managed response plan, a critical incident has a first-response target of one hour.

TecnetSOC now alerts you when something is exposed

In June we launched the screen that answers "how exposed are we?" In July, that screen learned to come find you.

The attack surface module was redesigned so you start with what's urgent: the score, the verdict and the action of the moment appear first, and every finding opens its action plan in one click.

  1. Find out without logging in: when a new critical or high exposure appears, an alert goes to your contacts by email, and that email opens the exact finding, ready to address.
  2. Prioritize with real-world data: findings flag what's already being exploited, with labels such as "used by ransomware" or "new this week."
  3. Get evidence you can act on: if one of your servers receives access attempts from the internet, you'll see it in your portal with that traffic as proof, and the finding closes on its own when the attempts stop.
  4. Attack Surface is now part of your TecnetSOC portal: it's activated during onboarding with your own domain, with no extra plan to buy. It doesn't replace a penetration test or fix exposures on its own: it tells you what to prioritize, and you decide the next step.

TecnetSOC attack surface module

TecnetProtect Backup: rehearse tomorrow's recovery today

The important question about a backup is whether it will work on the day you need it. July was about letting you answer that whenever you want, from your portal and without affecting your operation.

  1. You manage your plans. As an administrator, you create, edit, duplicate and delete your backup plans from the portal, whenever you need to.
  2. You choose how much to keep. When you create or edit a plan, you set the retention for your copies: 15 days, 30 days, a custom period or long-term history, all edited on one screen.
  3. Rehearse your recovery with evidence. Run a drill without touching your operation, watch it progress server by server and keep the record of who ran it, on which servers and with what result.
  4. Your team knows how to get back in. In your recovery plan you confirm your critical services, and if you ever run from the recovered site, the portal shows how your users connect, opening only what you authorized.
  5. A powered-off device doesn't count as a failure. If a device is off at backup time, it's marked as Skipped, and its pending copy runs as soon as you turn it on.
  6. Your backups keep running. They complete every night with no one stepping in, so you don't depend on someone keeping watch.

TecnetSOC modules

If TecnetSOC manages your backups, you'll see them marked as managed by our team.

More updates already in your portal

  1. Neo. The assistant you already knew in your portal now has its own name and look: it's called Neo, you find it with a visible button on every screen and it explains what you see with your own data.

  2. Reports. Your weekly, monthly and quarterly report now uses an executive dashboard format: the first page has the overall verdict, what changed from the previous period and the action required. It can also reach you as an email summary.

  3. Device protection. Every detection opens a record: what was detected, on which device and what the protection did, labeled "Action required" or "Resolved," with filters by type, date and device.

  4. Reviews. If you disagree with a verdict, request a review from your portal: your comment stays on the case timeline and the answer comes signed with the real name of the person who handled it.

  5. Devices. A new device shows up covered in your portal within minutes, and the "Online" status now means every monitoring source is reporting on time; if one falls behind, you see it as "Partial signal."

Requesting a review in TecnetSOC

Device detail in the TecnetSOC portal

And in the details: you get a notice when a domain is verified in your exposure monitoring, a case's time and its alert email's time are the same real detection time, all the figures on your dashboard come from a single source, and notifications only go to the people involved in each case.

What July brings you

Your security stops asking for your trust and starts giving you proof: you see the response as it happens and you rehearse recovery before you need it. That's where TecnetSOC is headed: every part of your service should be something you can check for yourself, with our team behind you when the severity calls for it.

In your portal, the updates section has the full history and marks what's already included in your service.

Future updates are also built on what you tell us. If there is something you want to see in TecnetSOC, write to us at hola@tecnetone.com

Gustavo Sánchez

Gustavo Sánchez

Microsoft Cloud and Cybersecurity expert with more than a decade of experience in the technology industry. He is recognized for his extensive knowledge in implementing cloud-based solutions and protecting data and systems against cyber threats. As a leader and speaker, Gustavo continues to share his knowledge and best practices at technology events and training programs.