
Security Operations continuous protection for your digital assets.
Security events centralised in one view instead of scattered across log files. We consolidate your logs in a SIEM, keep an eye on the situation and respond within agreed service hours, as a managed service at a fixed monthly price.
Managed Security as a Service.
A SIEM shows what really happens in your systems, instead of burying it in log files.
One service that brings your security events together.
Centralised log management
Logs from firewall, servers, endpoints and cloud come together in one place, searchable and correlated.
SIEM operation
We run the SIEM, maintain the rules and reduce false positives, so noise turns into usable signals.
Monitoring
Security events on the network and on endpoints are evaluated on an ongoing basis, not only after the fact.
Threat intelligence
Current threat information feeds into detection, so known attack patterns stand out.
Response per SLA
For critical incidents we respond within the agreed service hours and align the next steps with you.
Transparent reporting
Periodic reports show the situation and trends in a form that management understands too.
SIEM and log management with proven tools.
We run what fits you, commercial or open source.
Whether Splunk as an established SIEM platform or Wazuh as an open-source alternative, we pick the tool to match your needs and budget. We evaluate firewall logs with the Forti-Analyzer, and add Graylog for broad log centralisation.
- Splunk or Wazuh as the SIEM, depending on requirements and budget.
- Forti-Analyzer for evaluating your Fortinet firewalls.
- Graylog for efficient centralisation of distributed log files.
- Connect existing sources instead of rebuilding everything.
Scalable as a subscription, at a fixed monthly price.
Basic
Centralised log management as an entry point.
- Log centralisation (Graylog)
- Firewall evaluation (Forti-Analyzer)
- Periodic reporting
- Response during business hours
Standard
SIEM operation with active evaluation.
- Everything in Basic
- SIEM operation (Splunk or Wazuh)
- Threat intelligence integrated
- Monthly reports + review
- Response per SLA
Extended
For higher requirements and evidence needs.
- Everything in Standard
- Extended detection rules
- Incident documentation
- Individual SLA times
- Point of contact for audits
What clients ask about managed security.
You receive monitoring and SIEM operation as an ongoing service at a fixed monthly price, instead of building up tools, know-how and staff yourself. We run the platform, evaluate the events and respond within the agreed service hours.
No, we deliberately do not run a classic, permanently staffed 24/7 SOC. Monitoring runs continuously, while active handling and response happen within the agreed SLA times. For most SMEs this is the sensible and affordable approach.
As a SIEM, Splunk or the open-source alternative Wazuh, depending on your needs. We evaluate firewall logs with the Forti-Analyzer, and use Graylog for broad centralisation of log files. We connect existing sources rather than replacing everything.
In our two Swiss data centres (ZRH-01 and ZRH-02). As our own provider with cloud in Switzerland, we keep your security-relevant data in the country.
Who evaluates your security logs today?
If the answer is "no one, really", we should talk. We show you what a fitting SIEM and centralised log management could look like for you.