Skip to content
Ciberseg
Flagship service · 24×7

A Security Operations Centre, run for you.

Central security monitoring and incident management for IT and OT infrastructures — around the clock. Our analysts detect, validate and respond to threats in your environment so your team can focus on the business. Vendor-independent, ISO 27001-aligned, with data residency you control.

  • Real-time detection and correlation of security events
  • Alert validation and prioritisation by experienced SOC analysts
  • Incident analysis, escalation and SLA-based response
  • Modern SIEM and threat-intelligence technologies
  • Regular reporting and continuous security improvement
Illustrative SOC view
What the SOC does

Central monitoring and response — around the clock.

Central security monitoring and incident management for IT and OT infrastructures — around the clock. Our analysts detect, validate and respond to threats in your environment so your team can focus on the business. Vendor-independent, ISO 27001-aligned, with data residency you control.

Real-time detection and correlation of security events

Alert validation and prioritisation by experienced SOC analysts

Incident analysis, escalation and SLA-based response

Modern SIEM and threat-intelligence technologies

Regular reporting and continuous security improvement

Detection & protection

Detection and protection services.

Six managed capabilities plugging directly into your SOC environment — each vendor-validated, MITRE-mapped, and operated by our analysts around the clock.

Managed EDR

Endpoint Detection & Response

24/7 endpoint monitoring with automated detection and isolation of compromised systems, plus threat hunting mapped to MITRE ATT&CK.

Microsoft Defender · SentinelOne · CrowdStrike


  • Automated isolation of compromised endpoints
  • Threat hunting via MITRE ATT&CK
  • Per-endpoint, flexible tiering

Managed NDR

Network Detection & Response

AI-driven analysis of network traffic that surfaces lateral movement, zero-day activity and command-and-control — including OT/ICS protocols.

Passive · OT/ICS: Modbus, S7, OPC-UA


  • Detects lateral movement & C2 traffic
  • Shadow-IT and cloud-communication visibility
  • NIS2 & KRITIS compliance support

Managed Vulnerability Assessment

VAS

Continuous, risk-based scanning correlated by SOC analysts so you fix what actually matters, in the right order.

Qualys · Tenable · CVSS / EPSS


  • Continuous agent- & network-based scanning
  • Risk-based prioritisation by analysts
  • Remediation tracking in the SOC dashboard

Darknet Intelligence

Dark-web & brand monitoring

Detection of stolen credentials, leaked data and exposed domains across the dark web, with actionable alerts and optional executive monitoring.

Cyble Threat Intelligence Platform


  • Stolen-credential & data-leak detection
  • Brand & domain exposure monitoring
  • Executive monitoring add-on available

Privileged Access Management

PAM

Centralised control of access to critical systems, with session recording, just-in-time access and MFA — closing the door on insider threats and privilege misuse.

Session recording · JIT · MFA


  • Just-in-time access & password vaulting
  • Session monitoring & real-time analysis
  • Audit evidence for ISO 27001 & NIS2

Ransomware Resilience

AI prevention & auto-recovery

AI-based detection and blocking before encryption occurs, with automated file rollback and self-healing for affected systems.

Halcyon-powered · NIS2 / DORA / TISAX


  • Pre-encryption detection & autonomous blocking
  • Automated file rollback & self-healing
  • No backups or ransom payments required
Response when it matters

Response when it matters.

When an incident lands, speed is everything. Our response capabilities are designed to contain, analyse and recover — measured in minutes, not hours.

Incident Response

Aligned with NIST & ISO 27035

24/7 access to experienced IR specialists for rapid assessment, containment, forensic analysis and recovery — with documented lessons learned.


  • Immediate assessment & containment
  • Forensics & root-cause determination
  • Technical, organisational & comms support
  • Retainer packages: 25 hrs (Basic) / 50 hrs (Enterprise)

First Response

Containment in minutes, not hours

Playbook-driven immediate actions for P1/P2 incidents — endpoint isolation, account lockout and firewall activation — seamlessly integrated into the Managed SOC.


  • Up to 5 custom playbooks per client
  • Endpoint isolation, account lockout, firewall rules
  • 24×7 for critical & high incidents
Deployment models

Four deployment models. One team.

No single vendor owns your security. Choose the stack that fits your budget, your existing estate and your data-residency requirements — we operate them all.

All models run on infrastructure managed by Ciberseg, with full EU data residency and zero dependency on a single technology vendor.

A

Open-source SOC

Small organisations · cost-sensitive

A fully open-source stack (Wazuh SIEM, Shuffle SOAR, DFIR-IRIS, MISP) self-hosted by Ciberseg — zero licensing cost, complete data control.

  • Wazuh + Shuffle + DFIR-IRIS + MISP
  • Zero SIEM licensing cost
  • Self-hosted, EU data residency
B

Microsoft Sentinel-native

Microsoft-centric estates

For clients already invested in Microsoft Sentinel and Defender. We operate within your Azure tenant via Lighthouse — you keep ownership of the SIEM.

  • Azure Lighthouse delegation
  • Microsoft Defender & Sentinel
  • You own the SIEM, we run it
C

Managed SOC + RMM (KMU 100+)

SMEs · 100–500 users

SIEM and endpoint governance bundled as one service — combining Wazuh detection with NinjaOne RMM for Windows-centric mid-market organisations.

  • Wazuh + NinjaOne RMM
  • Detection + endpoint management
  • Built for 100–500 users
D

Enterprise SOC

Enterprises · 500+ users

High-availability detection at scale: a clustered Wazuh deployment with Suricata NDR and Velociraptor DFIR for complex hybrid environments.

  • Clustered, high-availability SIEM
  • Suricata NDR + Velociraptor DFIR
  • Tier 2/3 hunting at scale
Managed SOC pricing

Transparent, scalable SOC pricing.

Three tiers designed for the scale you are today and the ambition you have tomorrow. All tiers include 24×7 shift operations and a dedicated Security Delivery Manager.

Basic

€2,990month

+ €3 / user / month


P1 MTTR SLA
60 min
Log sources
5 native log sources
Retention
90-day retention
  • 24×7 shift operation
  • Alert validation & prioritisation
  • Dedicated Security Delivery Manager
  • Monthly report
  • Quarterly review (Jour Fixe)
Get started with Basic
Most popular

Professional

€3,990month

+ €3 / user / month


P1 MTTR SLA
30 min
Log sources
10 native log sources
Retention
90-day retention
  • Everything in Basic
  • Faster 30-minute P1 SLA
  • Expanded log-source coverage
  • Threat-intelligence correlation
  • Use-case tuning & detection engineering
Get started with Professional

Enterprise

€5,990month

+ €3 / user / month


P1 MTTR SLA
15 min
Log sources
15 native log sources
Retention
90-day retention
  • Everything in Professional
  • Fastest 15-minute P1 SLA
  • OT / ICS & hybrid coverage
  • Custom playbooks & first response
  • Compliance evidence (ISO 27001, NIS2)
Get started with Enterprise

Reference end-customer rates. Add-ons: First Response (+€2/user/mo), German-language operation (+€500/mo), additional log sources on request. Volume discounts apply.

Service-level agreements

Service-level agreements.

Our SLAs are contractually binding. Every priority class has a defined response window and an escalation path — no ambiguity, no excuses.

PriorityMeaningBasicProfessionalEnterprise
P1 — CriticalActive breach / business-critical impact60 min30 min15 min
P2 — HighConfirmed threat, contained scope4 h2 h1 h
P3 — MediumSuspicious activity, needs analysis8 h4 h2 h
P4 — LowInformational / hygiene findingsNext business day8 h4 h

MTTR = Mean Time To Respond · SLAs measured from alert validation to first analyst action

How it works

How onboarding and operations work.

From initial scoping to continuous operations, every engagement follows a clear, repeatable lifecycle — so you know exactly where you are at every stage.

  1. 01

    Scoping

    Define assets, threat model and rules of engagement together with your team.

  2. 02

    Discovery

    Automated scanning and manual reconnaissance to map the real attack surface.

  3. 03

    Exploitation

    Controlled attack simulation to confirm which vulnerabilities are genuinely exploitable.

  4. 04

    Reporting

    Prioritised findings with CVSS scores, business impact and clear remediation steps.

  5. 05

    Remediation

    Guided fix support and re-testing to confirm every issue is closed for good.

Ready to activate your SOC?

Protect your organisation — starting this week.

Our onboarding team can have you live in the SOC within days. No long procurement cycles, no complex setup. Book a consultation and we will scope your environment the same day.

Always watching. Always protecting. Always ahead.