Skip to content
Contact
Monitoring workstation with multiple screens, symbolic of SIEM and centralised log management
Managed Security as a Service · SIEM

Security Operations continuous protection for your digital assets.

Security events centralised in one view instead of scattered across log files. We consolidate your logs in a SIEM, keep an eye on the situation and respond within agreed service hours, as a managed service at a fixed monthly price.

Managed Security as a Service.
A SIEM shows what really happens in your systems, instead of burying it in log files.

Modelmanaged service · fixed monthly price
PlatformSIEM: Splunk
Log centralisationForti-Analyzer · Graylog
Responseper agreed SLA
Datain two CH data centres (ZRH-01/02)
Reportingperiodic + on request
Scope of service

One service that brings your security events together.

Centralised log management

Logs from firewall, servers, endpoints and cloud come together in one place, searchable and correlated.

SIEM operation

We run the SIEM, maintain the rules and reduce false positives, so noise turns into usable signals.

Monitoring

Security events on the network and on endpoints are evaluated on an ongoing basis, not only after the fact.

Threat intelligence

Current threat information feeds into detection, so known attack patterns stand out.

Response per SLA

For critical incidents we respond within the agreed service hours and align the next steps with you.

Transparent reporting

Periodic reports show the situation and trends in a form that management understands too.

What we work with

SIEM and log management with proven tools.

SplunkFortinetGraylog
Efficient centralisation

We run what fits you, commercial or open source.

With Splunk we rely on an established SIEM platform, and add the open-source tool Graylog for broad log centralisation. We evaluate firewall logs with the Forti-Analyzer, and pick the tools to match your needs and budget.

  • Splunk as an established SIEM platform.
  • Forti-Analyzer for evaluating your Fortinet firewalls.
  • Graylog for efficient centralisation of distributed log files.
  • Connect existing sources instead of rebuilding everything.
Discuss the setup
SIEM and log management: security analyst reviewing logs and dashboards on multiple monitors
Packages

Scalable as a subscription, at a fixed monthly price.

Basic

on requestper month

Centralised log management as an entry point.

  • Log centralisation (Graylog)
  • Firewall evaluation (Forti-Analyzer)
  • Periodic reporting
  • Response during business hours
Request a quote

Extended

on requestper month

For higher requirements and evidence needs.

  • Everything in Standard
  • Extended detection rules
  • Incident documentation
  • Individual SLA times
  • Point of contact for audits
Request a quote
Frequently asked

What clients ask about managed security.

You receive monitoring and SIEM operation as an ongoing service at a fixed monthly price, instead of building up tools, know-how and staff yourself. We run the platform, evaluate the events and respond within the agreed service hours.

No, we deliberately do not run a classic, permanently staffed 24/7 SOC. Monitoring runs continuously, while active handling and response happen within the agreed SLA times. For most SMEs this is the sensible and affordable approach.

As a SIEM we use Splunk. We evaluate firewall logs with the Forti-Analyzer, and use the open-source tool Graylog for broad centralisation of log files. We connect existing sources rather than replacing everything.

In our two Swiss data centres (ZRH-01 and ZRH-02). As our own provider with cloud in Switzerland, we keep your security-relevant data in the country.

Related services

Visibility is the start, protection the goal.

Who evaluates your security logs today?

If the answer is "no one, really", we should talk. We show you what a fitting SIEM and centralised log management could look like for you.