Skip to content
IT Security Operations
Managed Detection & Response

Detect. Stop. Explain.

A security operations centre in Germany, staffed around the clock, that detects threats on your endpoints and in your cloud, contains them and reconstructs what happened. Vendor-independent: we operate the solution you already have in place.

24/7
staffed operation
Vendor-independent
no product lock-in
Germany
data and team
Forensics
included when it counts

Why a SOC?

Detection is not a product you buy but an operation somebody has to run.

Attacks do not keep office hours

Encryption tends to start at night, at weekends and over public holidays — exactly when nobody is watching the console. An alert at 3am only helps if somebody assesses it at 3am.

An alert without assessment is not protection

Endpoint solutions report a lot. Without someone to tell a false positive from the early stage of an attack, alert fatigue sets in — and the one hit that matters disappears in the noise.

An in-house SOC ties up people permanently

Round-the-clock operation means shift work, holiday and sickness cover, and constant training. For most mid-sized companies that is not a budget question but a labour-market one.

NIS2 and ISO 27001 ask for evidence

What is required is not only that you installed something, but that you detect, assess and respond to incidents — documented in a way that can be followed. Running a SOC produces exactly that as a by-product.

Vendor-independent

We do not arrive with a product you have to buy.

Many providers sell the platform along with the SOC — and the recommendation lands on their own product remarkably often. We earn on the operation, not on licences. That changes what we are able to advise.

Your solution, our operation

We work with the EDR or XDR platform running in your environment. Existing investments are preserved; switching platforms is not a precondition for working together.

No SIEM of your own required

We bring the analysis platform. If you already run one, we integrate with it rather than standing a second environment up next to it.

Product-neutral advice

If you have nothing in place yet, our recommendation follows your environment and your requirements — not a vendor partnership.

No licence margin

We earn on the operation, not on reselling licences. That leaves our recommendation without a second, hidden motive.

What our SOC does

Six building blocks that together make the difference between watching and acting.

Staffed SOC operation

Around the clock, 365 days a year, with our own team. Nothing passed down an outsourcing chain, no anonymous ticket queue.

Analysis of your telemetry

We run the endpoint and cloud solution you use and assess its findings ourselves — with a second opinion rather than automatic forwarding.

Containment within agreed limits

When it counts we isolate affected endpoints, lock accounts and sessions and stop lateral movement across the network — within the limits you set beforehand.

Threat hunting

Deliberate searching for anomalies in your telemetry that no rule triggered on. This is what finds the attacks that go out of their way to stay quiet.

Digital forensics

Once something has happened: evidence collection, timeline reconstruction and preservation with an unbroken chain of custody — prepared to hold up in court.

Reporting and maturity

Regular service reviews with trend lines, maturity recommendations and a traceable rationale for where an investment actually pays off.

How we get started

From the first conversation to live operation — with no surprises when it counts.

01

Scoping

Which systems matter, which reporting lines apply, who is reachable when it counts — and how far we may act without asking first.

02

Connection

Telemetry from your endpoints, servers and cloud services is connected. Existing solutions are adopted, not replaced.

03

Baseline

We observe your environment to separate normal behaviour from suspicious behaviour. Without this step, any SOC mostly produces noise at first.

04

Operation

Detection, assessment by an analyst and containment within the agreed limits — documented and traceable.

05

Handover to incident response

If an alert becomes an incident, our IR team takes over with the context already gathered. The handover point is fixed in advance.

06

Service review

Going through it together on a regular basis: what happened, what worked, and where the next investment is worth making.

Managed detection and response is not SIEM outsourcing

The difference is not the technology but the question of who is allowed to act when it counts.

Comparison of managed detection and response with classic SIEM outsourcing
  Our MDR Classic SIEM outsourcing
Who assesses the alert An analyst with incident experience Often a rule, then the customer
Authority to act Containment within contractually defined limits The notification is forwarded, action happens in-house
Tooling lock-in Vendor-independent, your existing solution Often tied to the provider platform
Where the analysts sit Our own team in Germany Frequently a multi-stage outsourcing chain
Forensics Part of the service Commissioned separately
Reporting Service review with maturity recommendation Alert statistics

What you get

  • A service report with trend lines rather than a bare alert count
  • A traceable history of every assessed alert
  • Jointly agreed playbooks for the most common scenarios
  • A maturity recommendation with a reasoned order of priority
  • An emergency contact chain that is genuinely reachable when it counts
  • A defined handover point to incident response

If it happens anyway

A SOC lowers the chance that an alert turns into damage — it does not rule it out. For the real thing, the same team is ready, and it already knows your environment.

Frequently asked questions

Are you tied to a particular vendor?
No. We do not sell a security product and we earn nothing on licences. We operate the EDR or XDR platform you already have in place and evaluate its telemetry. If you do not have one yet, we advise product-neutrally, based on your environment, your compliance requirements and your budget — not on a partnership.
Do we need our own SIEM?
No. We bring the analysis platform with us. If you already run a SIEM, we integrate with it and work inside your environment rather than standing up a second one alongside. Both are possible — which makes more sense is something we settle during scoping.
Who decides whether an endpoint gets isolated?
You do, in the contract. Either we act autonomously within clearly defined limits — in which case we isolate a compromised endpoint immediately, without an escalation loop. Or we reach you through an agreed on-call channel and act only once you approve. We put those limits in writing so nobody has to improvise when it counts.
Where is our data processed?
In Germany. Telemetry, analysis and retention stay in German data centres, and the analysts are our own people — nothing is passed down an outsourcing chain. That is precisely why we run the SOC ourselves rather than buying it in.
What does onboarding look like?
First we agree scope, systems and reporting lines. Then we connect the telemetry and observe your environment for a while to tell normal behaviour from suspicious behaviour — without that baseline, any SOC mostly produces false alarms in its first weeks. Only then does live operation start, with agreed playbooks.
What happens when an alert turns into a real incident?
Our incident response team takes over — with the same context, the same logs and the same timeline the SOC has already gathered. The handover point is defined in advance so no time is lost re-establishing the basics.
What does running the SOC cost?
Cost depends on the number and type of connected systems, the scope of action you want us to have, and the retention period. After a free scoping call you receive a quote with a clearly bounded scope. Licence costs for your endpoint solution are not included — those stay with you and your vendor.

You can watch it yourself — or let us do it.

We run security operations for mid-sized companies and public authorities. Let us talk about your environment — without a product recommendation in our bag.

Arrange a SOC call

How we work with you

We treat every engagement as a long-term partnership rather than a one-off delivery. Our approach is organised into four clear phases so that you always know what happens when, who owns which responsibility and which outcomes you can expect.

1. Free initial conversation

We learn about your starting position, your goals and the constraints you operate under. In 30 to 45 minutes we check whether our offering fits your situation, outline possible paths and answer your questions – no obligation attached.

2. Structured assessment

We capture the current state systematically – technically, organisationally and in regulatory terms. You receive a prioritised assessment that clearly names strengths, gaps and action areas and forms the basis for a robust offer.

3. Delivery with a dedicated lead

A senior lead guides you through the delivery with clear milestones, transparent effort and cost planning and a weekly status. All results are documented and remain fully owned by you.

4. Continuous operations & review

After project close, we stay alongside you in operations – via managed-service components, regular reviews, action tracking and proactive recommendations on new threats, regulatory changes or technology shifts.