Deutsch

Packages & Subscriptions

SOC as a Service

Firewalls and antivirus report what they recognise. They are basic equipment, not a defence. What they do not recognise — a valid login at the wrong hour, a service account that suddenly starts working through file shares — is only noticed if somebody is watching. And watching at the moment it happens, not on Monday morning.

01

The starting point

Attacks Do Not Keep Office Hours

That is exactly what a Security Operations Center is for: bringing together events from across the network, separating the ordinary from the notable, and acting when it matters. Every day of the year, at every hour. The effort involved is considerable — and the reason most companies never get their own SOC into operation.

SOC as a Service means we run it for you. Sensors in your environment, analysis on our side, escalation along rules agreed in advance. If you would rather share the monitoring with your own team than hand it over entirely, SOC Co-Managed is the model that fits.

A wide ring of closely spaced pillars on dark ground, unbroken at every point. One short section of the ring is brightly lit; the rest glows faintly.
02

The finding

Why an In-House SOC Rarely Materialises

The plan usually starts out ambitious and fails in three places. The first is staffing. A SOC running shifts needs eight to ten analysts to cover nights, holidays and sick leave. The market barely supplies those people at present, and anyone who finds them competes for them against corporate salaries.

The second is the technology. Licensing a SIEM is the easy part. Tuning it so that it genuinely knows your environment is months of work — and that work does not stop, because the environment keeps changing.

The third only shows up in operation. A poorly tuned system reports tens of thousands of events a day, almost all of them harmless. After a few weeks nobody reads them closely any more. The term for this is alert fatigue. It does not describe a loss of comfort but the state in which the one alert that counts disappears among the rest.

A vast field of hundreds of identical dark blocks. Exactly one of them stands slightly taller and is brightly lit — barely noticeable among the others.

An alert nobody reads is not an alert.

03

The approach

What SOC as a Service Actually Means

We place sensors in your network, on your endpoints and in your cloud environments, and bring the events together in our own operation. Correlation runs through Strider, our own monitoring layer. Unusual behaviour is assessed by NeoI, which holds what it observes against what is normal in your environment.

Whatever emerges from that as an incident is judged by an analyst. Automatic countermeasures — isolating a system through Talion, for instance — are only set up where you explicitly want them, and we record in writing beforehand under what conditions they apply. Tools remove noise. The decision on a countermeasure is made by a person. What we see, and what became of it, you can follow in Sightadel — not only in the monthly report.

What this expressly is not: a replacement for your IT department. Running systems and securing them are different jobs with opposing goals — one optimises for availability and smooth operation, the other for control and scepticism. We take on the second.

Many fine traces of light converge from above, pass through three horizontal filter planes and leave the frame below as a single bright line.

The benefit

What You Get Out of It

Continuous coverage

infrastructure, applications and databases are monitored on shifts, 365 days a year. An incident on a Saturday evening is handled on the Saturday evening.

Predictable cost

you pay a fixed amount instead of licences, hardware, recruitment and training. Whether that works out cheaper for you than your own SOC, we work through beforehand using your numbers — a blanket percentage helps nobody.

Experience from many environments

an internal team only ever sees the attacks aimed at its own company. We see the patterns across many customers and carry them over into your detection.

Evidence for audits

reports and logs for GDPR, NIS2, ISO 27001 and sector-specific requirements are available on demand in Sightadel. That is documentation to support an audit — not a certification.

Short time to operation

rolling out sensors and setting baseline rules takes weeks, not years. Fine tuning then continues during operation.

Grows with you

new sites, additional cloud instances, changed processes — coverage is extended without stopping the running operation.

The process

How the Operation Runs

Security is not a state you buy but one that somebody holds. The operation therefore runs in six steps that interlock:

  1. 01

    Inventory

    we record what exists — network, endpoints, identities, cloud. What is not recorded is not monitored either. That is why this step comes first and not as an afterthought.

  2. 02

    Connection

    sensors and log sources are connected, baseline rules set, known false positives cleared away. Only after that is a report worth reading.

  3. 03

    Monitoring

    events come together in real time. Sign-ins, processes and data flows are checked against what is normal in your environment, not against a generic list.

  4. 04

    Looking rather than waiting

    analysts pursue specific hypotheses instead of only reacting to alerts. An attacker using nothing but legitimate tools often triggers not a single one.

  5. 05

    Response

    on a confirmed incident the agreed procedure applies — contain, cut off, inform. Who calls whom and when is settled before the phone rings.

  6. 06

    Feedback

    you receive reports on incidents and anomalies. What we learn goes back into monitoring as a rule — otherwise the analysis was not worth the work.

04

From practice

Three Starting Positions, Three Routes In

Attackers do not pick at random. They often know a sector's weak points better than the companies in it do. The three constellations below describe typical starting positions of the kind we meet regularly in these sectors — not individual cases of particular customers.

Three tall dark towers of different shapes stand side by side in a wide hall. Each has exactly one narrow opening, and each opening sits at a different height.

Starting position 1

Financial Services: The Access Nobody Notices

The expectation is usually that attackers want to intercept transfers. More often it is the documents they are after: credit assessments, transaction histories, dossiers. Those allow pressure to be applied not only to the company itself but to its customers as well.

The way in rarely runs through a flaw in the software. Employee credentials have often been circulating for years from old third-party leaks. Whoever signs in with them is using a valid identity — to the firewall that is an ordinary login.

The only thing that carries here is the deviation: timing, origin, the order in which things are accessed. If an account signs in at three in the morning from another country and then works through file shares that do not match its role, that is the finding — not the sign-in itself.

01

Highly sensitive data under strict regulatory requirements.

02

A small internal IT team that is not staffed at weekends and on holidays.

03

An attacker moving with correct credentials who triggers no signature at all.

Starting position 2

E-Commerce: Growth Outpacing the Safeguards

When a company grows fast, the attack surface grows with it: new servers, new cloud instances, new colleagues. In the rush, shadow IT and open configurations appear. New staff are particularly exposed to targeted phishing because they cannot yet judge what an internal process normally looks like.

The target is usually not the customer database but control over the shop infrastructure — and the moment with the greatest leverage is the busiest trading period.

What matters here is less the detection than the inventory: whatever is added today has to reach monitoring today. Taking stock is therefore not a one-off step at the beginning but part of the running operation. How resilient the human factor is alongside it, a security awareness training settles faster than any assumption.

01

An infrastructure that changes faster than the documentation can follow.

02

Phishing campaigns aimed at staff who have no routine yet.

03

The requirement that securing it must not slow the business down.

Starting position 3

Law Firms: The Detour Through the Supplier

Law firms hold material that is tightly guarded everywhere else: unpublished transactions, patent filings, case files. For attackers the firm is frequently the more convenient route to a corporation's data — an attack through the supply chain rather than against the actual target.

What makes it harder is that partners hold far-reaching access rights and often work while travelling. Anyone who gains access in such an environment tends to stay undetected for a long time.

The measure here is dwell time: not how quickly an alert fires, but how long somebody can move around unnoticed. That is precisely what active hunting is aimed at — and at making sure privileged access stays monitored even when it is used from the road.

01

Client data whose disclosure means not just fines but the end of the mandates.

02

Practically no internal resources for a security operation of their own.

03

Mobile and hybrid working that largely takes place outside the office network.

05

In closing

Who Your Contact Is Here

A system is only ever as good as the people operating it. With us you do not end up in a general hotline. Your SOC manager knows your environment, leads the response in an emergency, and translates what happened technically into a form you can work with in your own organisation — for the management board as much as for an auditor.

If an incident is already under way and you have no contract with us yet, Instant Response is the right way in. Everything else can be settled afterwards.

Two heavy dark beams cross in front of a concrete wall. A narrow bright seam lights up exactly along the line where they touch.

FAQ

Frequently asked questions

What is the difference between an in-house SOC and SOC as a Service?

An in-house SOC means your own hardware, your own licences and above all your own staff on shifts — realistically eight to ten analysts to cover nights, weekends and holidays. With SOC as a Service we provide the technology, the operation and the shift; you keep authority over your systems and define what may happen in an emergency.

How quickly do you respond if we are attacked?

Detection runs around the clock and handling starts immediately. We do not make a blanket promise in minutes, though — response times by severity are set out in the contract. What is actually achievable depends on your environment and on which countermeasures you allow us to automate in advance. We tell you that before the contract is signed, not after.

Does the service cover cloud environments as well?

Yes. We monitor on-premises infrastructure, hybrid setups and pure cloud environments. Which specific services can be connected is settled during the inventory — with some providers the limiting factor is the scope of the log data they make available, not our tooling.

We already have an IT department. Does this still make sense?

Yes, because they are two different jobs. Your IT team keeps systems running so people can work; security operations means restricting, checking and doubting. Anyone responsible for both at once will, in case of doubt, decide in favour of operations — and that is understandable. If your team should take part in the monitoring rather than hand it over, SOC Co-Managed is the right shape.

Does this satisfy our compliance requirements?

We supply the evidence an audit needs: logs, incident reports, proof that the monitoring is effective — for GDPR, NIS2, ISO 27001 and sector-specific requirements. Meeting the requirements is ultimately your company's job, not a service provider's. We supply the part that relates to security operations, and we tell you which gaps remain alongside it.

What do you see of our data?

We analyse metadata: connections, sign-ins, process behaviour, log files. We do not read the contents of emails or documents. Exactly what is collected is set out in the contract and the data processing agreement; analysis stays within the agreed frame.

Is this worth it below corporate scale?

Especially there, because the threshold is staffing, not technology. A company with 80 employees cannot staff a shift but is attacked just the same. Scope scales with the environment; if the effort does not pay off for you, we say so in the initial conversation.

How do we start?

With an inventory of your environment. Sensors are then rolled out and baseline rules set, without interrupting your running operation. A calibration phase follows in which false positives are cleared away — only after that is the monitoring sharp. That usually takes a few weeks, depending on how well your environment is documented.

Packages & Subscriptions

More in this area

Vulnerability Check Basic

Uncover security gaps within 48 hours. A fast overview of potential weaknesses in your IT infrastructure.

View

Security Awareness Training

Monthly modules, quarterly phishing simulations, on-site workshops: a year-long programme instead of a yearly session —…

View

Red Teaming

How red teaming realistically uncovers vulnerabilities, strengthens cyber resilience and helps companies meet DORA and …

View

vCISO

An external CISO on a flexible subscription: ISO 27001 guidance, ISMS implementation, corporate security oversight, SOC…

View

External CISO

An external CISO (vCISO) strengthens your IT security strategically and flexibly — with ISO 27001 consulting, complianc…

View

ISMS Implementation

Why a strategic ISMS based on ISO/IEC 27001 is essential today. How companies reduce cyber risk and meet NIS2 requireme…

View

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.