Detect. Stop. Explain.
A security operations centre in Germany, staffed around the clock, that detects threats on your endpoints and in your cloud, contains them and reconstructs what happened. Vendor-independent: we operate the solution you already have in place.
Why a SOC?
Detection is not a product you buy but an operation somebody has to run.
Attacks do not keep office hours
Encryption tends to start at night, at weekends and over public holidays — exactly when nobody is watching the console. An alert at 3am only helps if somebody assesses it at 3am.
An alert without assessment is not protection
Endpoint solutions report a lot. Without someone to tell a false positive from the early stage of an attack, alert fatigue sets in — and the one hit that matters disappears in the noise.
An in-house SOC ties up people permanently
Round-the-clock operation means shift work, holiday and sickness cover, and constant training. For most mid-sized companies that is not a budget question but a labour-market one.
NIS2 and ISO 27001 ask for evidence
What is required is not only that you installed something, but that you detect, assess and respond to incidents — documented in a way that can be followed. Running a SOC produces exactly that as a by-product.
We do not arrive with a product you have to buy.
Many providers sell the platform along with the SOC — and the recommendation lands on their own product remarkably often. We earn on the operation, not on licences. That changes what we are able to advise.
Your solution, our operation
We work with the EDR or XDR platform running in your environment. Existing investments are preserved; switching platforms is not a precondition for working together.
No SIEM of your own required
We bring the analysis platform. If you already run one, we integrate with it rather than standing a second environment up next to it.
Product-neutral advice
If you have nothing in place yet, our recommendation follows your environment and your requirements — not a vendor partnership.
No licence margin
We earn on the operation, not on reselling licences. That leaves our recommendation without a second, hidden motive.
What our SOC does
Six building blocks that together make the difference between watching and acting.
Staffed SOC operation
Around the clock, 365 days a year, with our own team. Nothing passed down an outsourcing chain, no anonymous ticket queue.
Analysis of your telemetry
We run the endpoint and cloud solution you use and assess its findings ourselves — with a second opinion rather than automatic forwarding.
Containment within agreed limits
When it counts we isolate affected endpoints, lock accounts and sessions and stop lateral movement across the network — within the limits you set beforehand.
Threat hunting
Deliberate searching for anomalies in your telemetry that no rule triggered on. This is what finds the attacks that go out of their way to stay quiet.
Digital forensics
Once something has happened: evidence collection, timeline reconstruction and preservation with an unbroken chain of custody — prepared to hold up in court.
Reporting and maturity
Regular service reviews with trend lines, maturity recommendations and a traceable rationale for where an investment actually pays off.
How we get started
From the first conversation to live operation — with no surprises when it counts.
Scoping
Which systems matter, which reporting lines apply, who is reachable when it counts — and how far we may act without asking first.
Connection
Telemetry from your endpoints, servers and cloud services is connected. Existing solutions are adopted, not replaced.
Baseline
We observe your environment to separate normal behaviour from suspicious behaviour. Without this step, any SOC mostly produces noise at first.
Operation
Detection, assessment by an analyst and containment within the agreed limits — documented and traceable.
Handover to incident response
If an alert becomes an incident, our IR team takes over with the context already gathered. The handover point is fixed in advance.
Service review
Going through it together on a regular basis: what happened, what worked, and where the next investment is worth making.
Managed detection and response is not SIEM outsourcing
The difference is not the technology but the question of who is allowed to act when it counts.
| Our MDR | Classic SIEM outsourcing | |
|---|---|---|
| Who assesses the alert | An analyst with incident experience | Often a rule, then the customer |
| Authority to act | Containment within contractually defined limits | The notification is forwarded, action happens in-house |
| Tooling lock-in | Vendor-independent, your existing solution | Often tied to the provider platform |
| Where the analysts sit | Our own team in Germany | Frequently a multi-stage outsourcing chain |
| Forensics | Part of the service | Commissioned separately |
| Reporting | Service review with maturity recommendation | Alert statistics |
What you get
- A service report with trend lines rather than a bare alert count
- A traceable history of every assessed alert
- Jointly agreed playbooks for the most common scenarios
- A maturity recommendation with a reasoned order of priority
- An emergency contact chain that is genuinely reachable when it counts
- A defined handover point to incident response
If it happens anyway
A SOC lowers the chance that an alert turns into damage — it does not rule it out. For the real thing, the same team is ready, and it already knows your environment.
Frequently asked questions
- Are you tied to a particular vendor?
- No. We do not sell a security product and we earn nothing on licences. We operate the EDR or XDR platform you already have in place and evaluate its telemetry. If you do not have one yet, we advise product-neutrally, based on your environment, your compliance requirements and your budget — not on a partnership.
- Do we need our own SIEM?
- No. We bring the analysis platform with us. If you already run a SIEM, we integrate with it and work inside your environment rather than standing up a second one alongside. Both are possible — which makes more sense is something we settle during scoping.
- Who decides whether an endpoint gets isolated?
- You do, in the contract. Either we act autonomously within clearly defined limits — in which case we isolate a compromised endpoint immediately, without an escalation loop. Or we reach you through an agreed on-call channel and act only once you approve. We put those limits in writing so nobody has to improvise when it counts.
- Where is our data processed?
- In Germany. Telemetry, analysis and retention stay in German data centres, and the analysts are our own people — nothing is passed down an outsourcing chain. That is precisely why we run the SOC ourselves rather than buying it in.
- What does onboarding look like?
- First we agree scope, systems and reporting lines. Then we connect the telemetry and observe your environment for a while to tell normal behaviour from suspicious behaviour — without that baseline, any SOC mostly produces false alarms in its first weeks. Only then does live operation start, with agreed playbooks.
- What happens when an alert turns into a real incident?
- Our incident response team takes over — with the same context, the same logs and the same timeline the SOC has already gathered. The handover point is defined in advance so no time is lost re-establishing the basics.
- What does running the SOC cost?
- Cost depends on the number and type of connected systems, the scope of action you want us to have, and the retention period. After a free scoping call you receive a quote with a clearly bounded scope. Licence costs for your endpoint solution are not included — those stay with you and your vendor.
You can watch it yourself — or let us do it.
We run security operations for mid-sized companies and public authorities. Let us talk about your environment — without a product recommendation in our bag.
Arrange a SOC callHow we work with you
We treat every engagement as a long-term partnership rather than a one-off delivery. Our approach is organised into four clear phases so that you always know what happens when, who owns which responsibility and which outcomes you can expect.
1. Free initial conversation
We learn about your starting position, your goals and the constraints you operate under. In 30 to 45 minutes we check whether our offering fits your situation, outline possible paths and answer your questions – no obligation attached.
2. Structured assessment
We capture the current state systematically – technically, organisationally and in regulatory terms. You receive a prioritised assessment that clearly names strengths, gaps and action areas and forms the basis for a robust offer.
3. Delivery with a dedicated lead
A senior lead guides you through the delivery with clear milestones, transparent effort and cost planning and a weekly status. All results are documented and remain fully owned by you.
4. Continuous operations & review
After project close, we stay alongside you in operations – via managed-service components, regular reviews, action tracking and proactive recommendations on new threats, regulatory changes or technology shifts.