Connecting sources
Entra ID and Microsoft 365, firewall and VPN, domain controllers and key servers, EDR alerts, and where needed the web shop and cloud platforms. Collected in Microsoft Sentinel or a comparable platform with storage in the EU.
Not every log is equally valuable. We begin with the sources that reveal the most attacks and add others step by step.
Entra ID and Microsoft 365, firewall and VPN, domain controllers and key servers, EDR alerts, and where needed the web shop and cloud platforms. Collected in Microsoft Sentinel or a comparable platform with storage in the EU.
Rules for common attack patterns such as impossible travel, new mailbox rules, privilege escalation or mass deletion, supplemented by rules for your particular set-up.
Every alert is reviewed by an analyst: false positive, harmless explanation or real incident. False positives lead to a rule adjustment so they do not return.
Pre-agreed actions such as disabling an account, ending sessions or isolating a device, combined with notifying your designated contacts.
In a serious incident, support with containment, evidence preservation and recovery, and preparation of the details needed for a report to CERT.at, to the authority responsible for NIS2 or to the Data Protection Authority where that is required.
A monthly report with alerts, incidents, trends and recommendations, written so management can follow it.
A SOC needs a few weeks to learn your environment. In that time a flood of messages becomes a useful early-warning system.
Agreeing sources, coverage hours, contacts and the actions we may take without asking first.
Setting up log forwarding, checking completeness, first rules in observation mode.
Two to four weeks of tuning: what is normal for you and which alerts are noise. After that the false-positive rate drops sharply.
Ongoing monitoring, response according to the playbook, a monthly report and a review of rules and sources every six months.
The time between intrusion and damage is your most valuable resource. Days often pass between the first suspicious sign-in and the encryption of the servers. If someone sees the traces and acts in that window, you are spared the restore from backup and the difficult conversations with customers and authorities.
Our standard coverage is Monday to Friday, 8:00-17:00 Austrian time, with automatic actions for clear-cut cases at any hour. Premium includes standby outside those hours. The right level depends on how long your business can tolerate an incident going unnoticed.
Yes, because you detect incidents early and have the necessary details to hand quickly. The duty to report and its deadlines follow from NIS2 and the Austrian rules implementing it, and your company submits the report to the competent authority itself. We prepare the technical information. Whether an incident is reportable is something you decide together with your legal adviser.
On a platform with storage in the EU, for example an Azure workspace in a European region. Logs contain personal data, so access, retention periods and the data processing agreement are settled from the outset.
No. You need contacts who are authorised to make decisions in an emergency, such as taking a server offline. Monitoring, triage and technical response are handled by us remotely.
Tell us your size, systems and the coverage you have in mind. We will propose sources and a scope that fit your business.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.