Vulnerability Check Basic
Uncover security gaps within 48 hours. A fast overview of potential weaknesses in your IT infrastructure.
ViewPackages & Subscriptions
Firewalls and antivirus report what they recognise. They are basic equipment, not a defence. What they do not recognise — a valid login at the wrong hour, a service account that suddenly starts working through file shares — is only noticed if somebody is watching. And watching at the moment it happens, not on Monday morning.
The starting point
That is exactly what a Security Operations Center is for: bringing together events from across the network, separating the ordinary from the notable, and acting when it matters. Every day of the year, at every hour. The effort involved is considerable — and the reason most companies never get their own SOC into operation.
SOC as a Service means we run it for you. Sensors in your environment, analysis on our side, escalation along rules agreed in advance. If you would rather share the monitoring with your own team than hand it over entirely, SOC Co-Managed is the model that fits.

The finding
The plan usually starts out ambitious and fails in three places. The first is staffing. A SOC running shifts needs eight to ten analysts to cover nights, holidays and sick leave. The market barely supplies those people at present, and anyone who finds them competes for them against corporate salaries.
The second is the technology. Licensing a SIEM is the easy part. Tuning it so that it genuinely knows your environment is months of work — and that work does not stop, because the environment keeps changing.
The third only shows up in operation. A poorly tuned system reports tens of thousands of events a day, almost all of them harmless. After a few weeks nobody reads them closely any more. The term for this is alert fatigue. It does not describe a loss of comfort but the state in which the one alert that counts disappears among the rest.

An alert nobody reads is not an alert.
The approach
We place sensors in your network, on your endpoints and in your cloud environments, and bring the events together in our own operation. Correlation runs through Strider, our own monitoring layer. Unusual behaviour is assessed by NeoI, which holds what it observes against what is normal in your environment.
Whatever emerges from that as an incident is judged by an analyst. Automatic countermeasures — isolating a system through Talion, for instance — are only set up where you explicitly want them, and we record in writing beforehand under what conditions they apply. Tools remove noise. The decision on a countermeasure is made by a person. What we see, and what became of it, you can follow in Sightadel — not only in the monthly report.
What this expressly is not: a replacement for your IT department. Running systems and securing them are different jobs with opposing goals — one optimises for availability and smooth operation, the other for control and scepticism. We take on the second.

The benefit
infrastructure, applications and databases are monitored on shifts, 365 days a year. An incident on a Saturday evening is handled on the Saturday evening.
you pay a fixed amount instead of licences, hardware, recruitment and training. Whether that works out cheaper for you than your own SOC, we work through beforehand using your numbers — a blanket percentage helps nobody.
an internal team only ever sees the attacks aimed at its own company. We see the patterns across many customers and carry them over into your detection.
reports and logs for GDPR, NIS2, ISO 27001 and sector-specific requirements are available on demand in Sightadel. That is documentation to support an audit — not a certification.
rolling out sensors and setting baseline rules takes weeks, not years. Fine tuning then continues during operation.
new sites, additional cloud instances, changed processes — coverage is extended without stopping the running operation.
The process
Security is not a state you buy but one that somebody holds. The operation therefore runs in six steps that interlock:
we record what exists — network, endpoints, identities, cloud. What is not recorded is not monitored either. That is why this step comes first and not as an afterthought.
sensors and log sources are connected, baseline rules set, known false positives cleared away. Only after that is a report worth reading.
events come together in real time. Sign-ins, processes and data flows are checked against what is normal in your environment, not against a generic list.
analysts pursue specific hypotheses instead of only reacting to alerts. An attacker using nothing but legitimate tools often triggers not a single one.
on a confirmed incident the agreed procedure applies — contain, cut off, inform. Who calls whom and when is settled before the phone rings.
you receive reports on incidents and anomalies. What we learn goes back into monitoring as a rule — otherwise the analysis was not worth the work.
From practice
Attackers do not pick at random. They often know a sector's weak points better than the companies in it do. The three constellations below describe typical starting positions of the kind we meet regularly in these sectors — not individual cases of particular customers.

Starting position 1
The expectation is usually that attackers want to intercept transfers. More often it is the documents they are after: credit assessments, transaction histories, dossiers. Those allow pressure to be applied not only to the company itself but to its customers as well.
The way in rarely runs through a flaw in the software. Employee credentials have often been circulating for years from old third-party leaks. Whoever signs in with them is using a valid identity — to the firewall that is an ordinary login.
The only thing that carries here is the deviation: timing, origin, the order in which things are accessed. If an account signs in at three in the morning from another country and then works through file shares that do not match its role, that is the finding — not the sign-in itself.
Highly sensitive data under strict regulatory requirements.
A small internal IT team that is not staffed at weekends and on holidays.
An attacker moving with correct credentials who triggers no signature at all.
Starting position 2
When a company grows fast, the attack surface grows with it: new servers, new cloud instances, new colleagues. In the rush, shadow IT and open configurations appear. New staff are particularly exposed to targeted phishing because they cannot yet judge what an internal process normally looks like.
The target is usually not the customer database but control over the shop infrastructure — and the moment with the greatest leverage is the busiest trading period.
What matters here is less the detection than the inventory: whatever is added today has to reach monitoring today. Taking stock is therefore not a one-off step at the beginning but part of the running operation. How resilient the human factor is alongside it, a security awareness training settles faster than any assumption.
An infrastructure that changes faster than the documentation can follow.
Phishing campaigns aimed at staff who have no routine yet.
The requirement that securing it must not slow the business down.
Starting position 3
Law firms hold material that is tightly guarded everywhere else: unpublished transactions, patent filings, case files. For attackers the firm is frequently the more convenient route to a corporation's data — an attack through the supply chain rather than against the actual target.
What makes it harder is that partners hold far-reaching access rights and often work while travelling. Anyone who gains access in such an environment tends to stay undetected for a long time.
The measure here is dwell time: not how quickly an alert fires, but how long somebody can move around unnoticed. That is precisely what active hunting is aimed at — and at making sure privileged access stays monitored even when it is used from the road.
Client data whose disclosure means not just fines but the end of the mandates.
Practically no internal resources for a security operation of their own.
Mobile and hybrid working that largely takes place outside the office network.
In closing
A system is only ever as good as the people operating it. With us you do not end up in a general hotline. Your SOC manager knows your environment, leads the response in an emergency, and translates what happened technically into a form you can work with in your own organisation — for the management board as much as for an auditor.
If an incident is already under way and you have no contract with us yet, Instant Response is the right way in. Everything else can be settled afterwards.

FAQ
An in-house SOC means your own hardware, your own licences and above all your own staff on shifts — realistically eight to ten analysts to cover nights, weekends and holidays. With SOC as a Service we provide the technology, the operation and the shift; you keep authority over your systems and define what may happen in an emergency.
Detection runs around the clock and handling starts immediately. We do not make a blanket promise in minutes, though — response times by severity are set out in the contract. What is actually achievable depends on your environment and on which countermeasures you allow us to automate in advance. We tell you that before the contract is signed, not after.
Yes. We monitor on-premises infrastructure, hybrid setups and pure cloud environments. Which specific services can be connected is settled during the inventory — with some providers the limiting factor is the scope of the log data they make available, not our tooling.
Yes, because they are two different jobs. Your IT team keeps systems running so people can work; security operations means restricting, checking and doubting. Anyone responsible for both at once will, in case of doubt, decide in favour of operations — and that is understandable. If your team should take part in the monitoring rather than hand it over, SOC Co-Managed is the right shape.
We supply the evidence an audit needs: logs, incident reports, proof that the monitoring is effective — for GDPR, NIS2, ISO 27001 and sector-specific requirements. Meeting the requirements is ultimately your company's job, not a service provider's. We supply the part that relates to security operations, and we tell you which gaps remain alongside it.
We analyse metadata: connections, sign-ins, process behaviour, log files. We do not read the contents of emails or documents. Exactly what is collected is set out in the contract and the data processing agreement; analysis stays within the agreed frame.
Especially there, because the threshold is staffing, not technology. A company with 80 employees cannot staff a shift but is attacked just the same. Scope scales with the environment; if the effort does not pay off for you, we say so in the initial conversation.
With an inventory of your environment. Sensors are then rolled out and baseline rules set, without interrupting your running operation. A calibration phase follows in which false positives are cleared away — only after that is the monitoring sharp. That usually takes a few weeks, depending on how well your environment is documented.
Packages & Subscriptions
Uncover security gaps within 48 hours. A fast overview of potential weaknesses in your IT infrastructure.
ViewMonthly modules, quarterly phishing simulations, on-site workshops: a year-long programme instead of a yearly session —…
ViewHow red teaming realistically uncovers vulnerabilities, strengthens cyber resilience and helps companies meet DORA and …
ViewAn external CISO on a flexible subscription: ISO 27001 guidance, ISMS implementation, corporate security oversight, SOC…
ViewAn external CISO (vCISO) strengthens your IT security strategically and flexibly — with ISO 27001 consulting, complianc…
ViewWhy a strategic ISMS based on ISO/IEC 27001 is essential today. How companies reduce cyber risk and meet NIS2 requireme…
ViewContact
Talk to us before somebody else does. The first conversation is free and we reply the same business day.