03 · IT Security
Round-the-clock monitoring, detection and response by L1–L3 analysts — with SIEM, threat intelligence and vulnerability scanning included, and no licensing or in-house team costs.
Service details
A Security Operations Center (SOC) is a team of security analysts, supported by technology, that watches your IT environment around the clock, detects attacks and responds before they turn into a breach. Our SOC analyzes events from your servers, network, cloud and applications 24/7/365, and our team handles the incidents it finds.
Building an in-house SOC means hiring at least a dozen specialists for shift work and buying expensive SIEM and threat intelligence licenses. With our service you get the whole capability — people, processes and technology — running on our own compute clusters, without licensing costs and billed according to use.
How it works
What's included
Every incident is analyzed and handled by our team, with a 15-minute response to critical incidents.
A shared or dedicated SIEM platform running on our clusters, with full log archiving.
Creating and tuning rules and detection scenarios for your environment, system tuning and troubleshooting.
Up-to-date indicators of compromise and attacker techniques built into detection.
Regular scanning of your assets with our ReconMore scanner, so weaknesses are fixed before they are exploited.
Post-breach analysis, incident forensics and malware analysis when something does get through.
Proactive searches for attackers hiding in your network — see Threat Hunting.
Recommendations based on detected incidents and regular reports for IT and the management board.
A direct line to our analysts at any time, for questions, escalations and reporting suspicious events.
Our team
The first line, watching alerts around the clock.
Experienced analysts who handle confirmed incidents.
The most senior specialists for complex cases.
Benefits
Continuous monitoring and incident handling are at the heart of modern regulations. Our SOC helps you detect incidents early enough to meet the 24-hour and 72-hour reporting deadlines of NIS2 / KSC 2.0, supports the ICT incident management requirements of DORA and provides the monitoring activities expected by ISO 27001.
A 30-minute call with a security engineer — we'll outline the log sources, scope and ballpark budget, with no sales pitch.
Questions and answers
A SOC is a team of security analysts, supported by technology such as SIEM and threat intelligence, that monitors an organization's IT environment around the clock, detects threats and responds to security incidents.
A SIEM is a technology that collects and correlates logs and generates alerts. A SOC is the service built around it: the people who analyze those alerts, investigate incidents, respond to them and keep improving detection. A SIEM without a SOC produces alerts that nobody acts on.
For critical incidents, our analysts start handling the incident within 15 minutes of detection — at any time of day, on weekends and holidays. Response times for other priorities are defined in the contract.
It responds. Our analysts investigate every confirmed incident and take containment actions according to procedures agreed with you — for example isolating a host or blocking an account — and coordinate the next steps with your IT team.
Practically any source of logs: Linux and Windows servers, Active Directory and identity systems, Microsoft 365, firewalls and network devices, cloud and virtualization platforms, web applications, databases and endpoint protection. We agree the list of sources during onboarding.
No. We run the service on our own compute clusters, as SIEM as a Service or a dedicated SIEM, and maintain the logs and archives for you. There are no licensing costs on your side.
The price depends mainly on the number and type of monitored sources and the volume of data, and is billed according to utilization. After a short call we prepare a proposal with scope and pricing within 48 hours.
Yes. Both regulations require organizations to detect, handle and report incidents within tight deadlines. The SOC provides the monitoring, incident handling and documentation you need — and our audit team can check the rest of your compliance.
We agree the scope and response procedures, connect your log sources, learn what normal activity looks like in your environment and tune the rules to reduce false positives. Once tuned, the environment is under full 24/7/365 monitoring, with regular reports.
No. A SOC is most often used by medium and large enterprises, but because the service is shared and billed by use, it is also affordable for smaller organizations that cannot build their own security team.
Related services
First step
30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.
A proposal with scope and pricing within 48 hours of the call.
Go to contact