Service · IT security

SOC monitoring

An attack nearly always leaves traces long before files are encrypted or money moves to a stranger’s account. A sign-in from an unusual country at three in the morning, a new forwarding rule in the bookkeeper’s mailbox, a service account suddenly granted admin rights, a surge of failed VPN logins. Each of these traces sits in a different log: Entra ID, Exchange Online, the firewall, the domain controller. On their own they look harmless; together they tell a story. A security operations centre, or SOC, brings those logs together, searches them for patterns and responds when something is off. For a large corporation that means a dedicated team working shifts. For an SME with 20 to 200 staff it is neither affordable nor necessary. We offer SOC monitoring sized to your organisation: clearly defined sources, tuned detection rules and response steps agreed with you in advance.

Central logs
from cloud, network, servers and endpoints
Detection rules
tuned to your environment
Response steps
agreed with you beforehand
Retention
long enough for forensic analysis

Everything this covers

Not every log is equally valuable. We begin with the sources that reveal the most attacks and add others step by step.

Settle the details with an engineer

Connecting sources

Entra ID and Microsoft 365, firewall and VPN, domain controllers and key servers, EDR alerts, and where needed the web shop and cloud platforms. Collected in Microsoft Sentinel or a comparable platform with storage in the EU.

Detection rules

Rules for common attack patterns such as impossible travel, new mailbox rules, privilege escalation or mass deletion, supplemented by rules for your particular set-up.

Alert triage

Every alert is reviewed by an analyst: false positive, harmless explanation or real incident. False positives lead to a rule adjustment so they do not return.

Response

Pre-agreed actions such as disabling an account, ending sessions or isolating a device, combined with notifying your designated contacts.

Incident handling

In a serious incident, support with containment, evidence preservation and recovery, and preparation of the details needed for a report to CERT.at, to the authority responsible for NIS2 or to the Data Protection Authority where that is required.

Reporting

A monthly report with alerts, incidents, trends and recommendations, written so management can follow it.

Our working method

A SOC needs a few weeks to learn your environment. In that time a flood of messages becomes a useful early-warning system.

01

Planning

Agreeing sources, coverage hours, contacts and the actions we may take without asking first.

02

Onboarding

Setting up log forwarding, checking completeness, first rules in observation mode.

03

Learning phase

Two to four weeks of tuning: what is normal for you and which alerts are noise. After that the false-positive rate drops sharply.

04

Steady state

Ongoing monitoring, response according to the playbook, a monthly report and a review of rules and sources every six months.

The time between intrusion and damage is your most valuable resource. Days often pass between the first suspicious sign-in and the encryption of the servers. If someone sees the traces and acts in that window, you are spared the restore from backup and the difficult conversations with customers and authorities.

Frequently asked questions

Our standard coverage is Monday to Friday, 8:00-17:00 Austrian time, with automatic actions for clear-cut cases at any hour. Premium includes standby outside those hours. The right level depends on how long your business can tolerate an incident going unnoticed.

Yes, because you detect incidents early and have the necessary details to hand quickly. The duty to report and its deadlines follow from NIS2 and the Austrian rules implementing it, and your company submits the report to the competent authority itself. We prepare the technical information. Whether an incident is reportable is something you decide together with your legal adviser.

On a platform with storage in the EU, for example an Azure workspace in a European region. Logs contain personal data, so access, retention periods and the data processing agreement are settled from the outset.

No. You need contacts who are authorised to make decisions in an emergency, such as taking a server offline. Monitoring, triage and technical response are handled by us remotely.

See the attack coming instead of finding it afterwards

Tell us your size, systems and the coverage you have in mind. We will propose sources and a scope that fit your business.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.