NNetify

BT evidence record 2.7

Security operations layer - BT's own SOC/MSS wrapped around SASE (threat intel, incident response)

What BT Specifically Provides (The 'On Top' Layer) | Confirmed | Last verified 2026-08-30

Evidence finding

A converged UK NOC and SOC model underpins BT's SASE offer. One UK based team handles 24/7 monitoring and security support, acting as the single point of contact and running unified incident response. NCSC aligned threat intelligence and guaranteed UK data residency come as standard. What this really means in practice is that network and security incidents stay owned by one team rather than being passed between separate suppliers, which is the actual substance behind BT's "no finger pointing" claim.

What the buyer should do

Define monitoring, incident response, policy management and evidence responsibilities between BT and the customer.

This procurement action is Netify guidance. The evidence finding above remains Harry Yelland's sourced research.

Source notes

How to use this record

This is one finding from Netify's BT Managed SD-WAN and SASE evidence databank. The confidence label, source notes and review date stay attached so buyers and automated systems can distinguish confirmed evidence from uncertainty.

Research by Harry Yelland. Reviewed by Robert Sturt. Served from the live published database.