Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Managed SOC & MDR

Organizations that need to detect and handle security incidents continuously without an in-house monitoring team.

Last updatedAugust 22, 2026

The problem this solves

Your security alerts are only handled during business hours, or pile up unqualified. Hiring and rostering a team of 6 to 8 analysts for round-the-clock coverage is an annual cost that is hard to justify on its own.

What's included

Log collection and correlation across your technical sources

Endpoint and server monitoring

Network-level threat detection

Alert qualification and false-positive reduction

SLA-based notification, tiered by criticality

First- and second-level investigation of qualified incidents

Monthly monitoring report

Custom detection rules built using our PIBD methodology

Frameworks applied

MITRE ATT&CKMITRE D3FENDNIST SP 800-61r2SigmaSTIX/TAXII

Deliverables

Monthly monitoring report

Qualified incident sheets

Deployed detection-rules registry

MITRE ATT&CK coverage table

Quarterly security posture review

Ongoing service, renewable contractual engagement

Typical duration

Client prerequisites

  • Access to relevant log sources (firewalls, servers, endpoints, critical applications)
  • A designated technical contact, reachable within the agreed on-call windows
  • A minimal crisis-management procedure on the client side, even informal
  • Formal authorization to collect and process the logs concerned

Frequently asked questions

Does the service include 24/7 coverage?

Coverage (8/5, extended, or 24/7) is defined with the client based on the criticality of the monitored systems and available budget. It is not a single fixed mode.

What happens concretely when an alert is qualified as a real incident?

You are notified per the agreed SLA, with an incident sheet detailing the nature of the threat, affected systems, and recommended actions. Remediation on your systems remains yours or is covered under a dedicated service.

Do we need a SIEM in place before subscribing?

No. We can work with your existing tooling or propose a solution as an option depending on your environment.

What is the PIBD methodology mentioned for detection rules?

PIBD is our proprietary methodology for designing and prioritizing detection rules. It is described in full on our dedicated approach page.

How is SOC performance measured?

Through contractual indicators (notification delays, false-positive rate, MITRE ATT&CK coverage) reviewed at each quarterly review.

Get in touch