Managed detection & response

A SOC staffed by analysts, not a ticket queue

We ingest your telemetry, write detection content against your own estate, and a person reads everything that survives correlation. Coverage is continuous and nothing leaves the European Union.

0% Availability over 24 months
0 min Median time to detect
0 Analysts on rotation
0 Alerts triaged outside the EU
The stack

Four layers, one accountable team

Each layer produces something you can inspect: a log source list, a rule repository, a triage record, a hunt write-up.

01

Ingest

Endpoint, identity, network, cloud control plane and the application logs that matter. We take what you already emit before proposing anything new.

  • EDR and endpoint telemetry
  • Identity provider sign-in logs
  • Firewall and egress flow records
  • Cloud audit trails
  • Application and database logs
02

Detect

Detection content written against your estate, version-controlled and reviewed. Vendor defaults are a starting point, never the deliverable.

  • Custom rules mapped to ATT&CK
  • Behavioural baselines per host
  • Egress volume anomaly tracking
  • Identity impossible-travel logic
  • Monthly rule efficacy review
03

Triage

A human reads every alert that survives correlation. You receive incidents with context and a recommendation, not a queue to work through.

  • Analyst triage inside 11 minutes, median
  • Enrichment before escalation
  • False-positive tuning fed back to detection
  • One escalation channel, agreed with you
04

Hunt

Every month the team works a hypothesis against your data rather than waiting for a rule to fire. Findings feed straight back into detection.

  • Hypothesis-driven, not alert-driven
  • Written up whether or not anything is found
  • New detections shipped from each cycle
  • Quarterly review with your team
Included

What the retainer covers

One price. No per-alert billing, no per-seat surprises when you hire.

See pricing
  • Named lead analyst who knows your architecture
  • Detection engineering, not vendor default rules
  • Monthly threat-hunting cycle with written output
  • Incident response engaged within 30 minutes
  • Quarterly posture report written for a board
  • SecNumCloud-qualified sovereign hosting
  • Runbook co-written with your on-call team
  • Annual tabletop exercise included
FAQ

Before you ask

Do we have to replace our existing tooling?

No. We work with the EDR, SIEM and identity provider you already run. Where we recommend a change it is written up with the reasoning and the cost, and it is your decision.

What happens at 3am?

An analyst on the European rotation picks it up. There is no offshore first line and no automated triage standing in for a person. If the severity warrants it, you get a phone call, not an email.

How long is onboarding?

Four to six weeks for a typical estate. Weeks one and two are log source integration, weeks three and four are detection content and baselining, weeks five and six run in parallel with your existing arrangement before cutover.

Can we see the detection rules?

Yes. Your detection content lives in a repository you have read access to. You are not renting visibility into your own estate.