Service · Cybersecurity

SOC monitoring

Your firewall, EDR and Microsoft 365 write thousands of events a day, and as a rule nobody reads them. Typically the logs are only opened once the damage is done, as part of the post-mortem. Monitoring turns that order around: suspicious signals are spotted while the intruder is still looking around the network, not once the server has been encrypted.

24/7
on Premium or 24/7 IT support
Correlation
across many systems
Playbooks
who does what, and when
Lessons learned
after every incident

Included in this service

Watching only pays off when there are protective tools and proper logging underneath. Those come first; the observation layer sits on top. We will not sell a SOC to a company that has not yet switched on a second factor for sign-ins.

Talk the scope through with an engineer

Data sources

Firewalls, EDR, sign-in records from Entra ID, the audit trail in Microsoft 365, domain controllers, file servers and your key business applications.

Correlation

Individual events look harmless; together they spell an attack: a login from an unfamiliar country, a new rule forwarding mail outside and hundreds of SharePoint files pulled down, all inside sixty minutes.

Detection rules

Detections shaped around how your company works, backed by the MITRE ATT&CK catalogue of adversary techniques.

Response

Blocking an account, isolating a computer, revoking sessions and tokens. All according to a playbook with permissions agreed upfront.

Post-incident review

The route in, what the intruder did, what data might be gone, and which changes stop a repeat.

Notifications

Help preparing the technical part of an incident report for the relevant CSIRT, and of a breach notification to the Polish data protection authority when personal data is involved. Your company submits the report.

How we work together

How long connection takes depends on the number of sources, and most of the work goes on adapting detections to how you operate.

01

Source review

We establish which of your systems log anything worthwhile, for how long it is retained and where the blind spots are.

02

Connection

Everything flows into one platform, for example Microsoft Sentinel, and is converted to a shared schema.

03

Tuning

For the first few weeks we cut out false positives. Without that, genuine signals drown in noise and people stop reacting.

04

Operations

Continuous oversight, response by playbook, a periodic report and regular rule reviews.

Watching is pointless if nobody is allowed to act. In the middle of the night the analyst on shift can see the intrusion yet has no mandate to pull the server, and the manager who could decide has muted their phone. When we connect you, we write down who holds decision rights, how to reach them, and which steps we can take without waiting for permission.

Questions and answers

The basics: a second factor on sign-ins, antivirus or EDR run from one place, unneeded ports shut and backups that ransomware cannot reach. Watching an unprotected environment is little more than observing a break-in as it happens.

Work out what a day of downtime and a leak of customer data would cost. In an office where IT mostly means email and documents, solid safeguards and backups are usually enough. For a factory or a web shop, the service can earn back its cost the first time it catches an attack early.

Someone you nominate who can order systems to be stopped. That is for management to settle, not the technicians, and it must be agreed before we go live. You may also authorise us in advance for certain moves, such as disabling a hijacked account.

NIS2 and the KSC act set short, multi-stage deadlines for reporting significant incidents by the organisations they cover. Confirm with a lawyer which duties apply to your company. Breaches involving personal data must reach the data protection authority within 72 hours. We prepare the chronology and technical facts; you remain the party that submits.

Let us talk about monitoring

Tell us which systems are critical to you and what an hour of downtime costs. You will get a straight answer on whether a SOC makes sense now or the fundamentals need attention first.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.