Skip to content
An operations room: staff at consoles facing a wall of screens, each watching a different feed.

Services

Managed Services

Detection, response and operations, run for you around the clock.

Detection, response and operations, run for you around the clock.

A mid-size company cannot staff a security operations centre, and should not have to. What it needs is someone watching, someone who answers at three in the morning, and someone who makes sure the monthly work — patches, scans, cost reviews, control evidence — actually happens.

We run detection through a partner SOC under our supervision, with the alerts triaged by people who know your estate, and we keep the response side ready: an incident plan that exists before the incident, playbooks that have been exercised, and a forensics team on call.

The same retainer covers the operations nobody has time for. Vulnerability management with real deadlines, cloud security and compliance checks that run continuously, and FinOps so the cloud bill goes down rather than up. One contract, one contact, a monthly report your board can read.

Managed Services

SOC management

Continuous detection, threat intelligence and vulnerability watch, with a named analyst on the other end.

  • Managed SOC and MDRTypical duration: RecurringDelivered with a qualified partner

    Round-the-clock detection and response delivered white label with a PDIS-qualified partner, with use cases written for your environment and a named escalation path.

    You receive

    • Detection use-case catalogue
    • Log source onboarding plan
    • Escalation and response runbooks
    • Monthly detection performance review
  • Vulnerability scanningTypical duration: Recurring

    Authenticated scans of your external and internal estate on a fixed cadence, with findings deduplicated, prioritised by exploitability and assigned.

    You receive

    • Monthly scan cycle with owners and deadlines
    • Trend report by asset class
    • Exceptions register
  • Incident managementTypical duration: Recurring

    A named on-call contact, a ticket that is opened within minutes, and a process that takes an alert from detection to closure with the record an insurer or regulator will ask for.

    You receive

    • Incident register and severity model
    • Response times per severity, reported monthly
    • Post-incident reviews
  • Threat intelligence and attack-surface monitoringTypical duration: Recurring

    Continuous watch on what is exposed in your name: domains, certificates, leaked credentials and third-party breaches, filtered to what is worth acting on.

    You receive

    • External attack surface inventory
    • Credential leak monitoring
    • Sector threat briefings
    • Monthly actionable alert digest
  • Dark web monitoringTypical duration: Recurring

    Watching the markets and leak sites for your domains, credentials, brand and executives, with an alert and a recommended action when something surfaces.

    You receive

    • Monitored terms and sources agreed with you
    • Alerts within a working day of exposure
    • Quarterly exposure summary
  • Anti-phishing serviceTypical duration: Recurring

    Detection and takedown of sites impersonating you, a reporting button for your staff, and the mail-authentication records that stop your domain being spoofed.

    You receive

    • SPF, DKIM and DMARC at enforcement
    • Takedown requests handled for you
    • Monthly figures on reported and blocked mail
  • Vulnerability managementTypical duration: Recurring

    A continuous cycle with defined scan coverage, risk-based prioritisation and service levels for remediation, reported in terms the executive committee can act on.

    You receive

    • Scanning coverage and schedule
    • Risk-based prioritisation model
    • Remediation SLAs by severity
    • Monthly reporting pack

CERT and incident response

Plans that exist before the incident, and a team that answers when it happens.

  • Incident response plan and playbooksTypical duration: 5–12 days

    A response plan with named roles, decision thresholds and the regulatory notification clocks already built in, plus playbooks for the scenarios you will actually face.

    You receive

    • Incident response plan and severity scale
    • Playbooks for ransomware, fraud, data breach
    • Regulatory notification timelines
    • Contact and escalation matrix
  • Incident response and forensicsTypical duration: On callDelivered with a qualified partner

    On-call response with a PRIS-qualified partner: containment first, then evidence preservation, root cause, and the report your insurer and regulator will ask for.

    You receive

    • Containment and eradication support
    • Forensic analysis and timeline
    • Root cause report
    • Post-incident hardening plan
  • Threat huntingTypical duration: 5–10 days

    A hypothesis-driven search through your telemetry for the intruder your tools did not flag, run by an analyst, ending in findings or in evidence of absence.

    You receive

    • Hunt plan with hypotheses and data sources
    • Findings with indicators and containment steps
    • Detection rules added for what was found
  • Malware analysisTypical duration: 2–5 days

    Static and dynamic analysis of a sample found on your estate: what it does, what it talks to, what it took, and the indicators to block it everywhere else.

    You receive

    • Analysis report with behaviour and indicators
    • Detection and blocking rules
    • Advice on scope of compromise

Managed operations

Security, cost and compliance work that has to run every month, run for you.

  • Managed DevSecOps retainerTypical duration: Recurring

    A standing engineering capacity that keeps the pipeline, the guardrails and the evidence working as your platform changes, with a named engineer and a monthly review.

    You receive

    • Named engineer and agreed capacity
    • Pipeline and guardrail maintenance
    • Finding triage and remediation support
    • Monthly review and roadmap
  • FinOpsTypical duration: 10–25 days

    Cost allocation, commitment strategy, rightsizing and waste elimination, typically returning fifteen to thirty per cent of the bill within the first quarter.

    You receive

    • Cost allocation and tagging model
    • Rightsizing and commitment plan
    • Savings tracker with measured results
    • Monthly FinOps reporting
  • Continuous cloud security and complianceTypical duration: Recurring

    Posture management that runs every day and reports in the language of your control framework, so cloud evidence for ISO 27001 or SOC 2 is produced automatically.

    You receive

    • Continuous control monitoring
    • Compliance dashboards per framework
    • Drift and exception workflow
    • Automated evidence export

NIS2 Ready

From applicability to a defensible compliance position, with the governance duties covered.

Duration
8–12 weeks
Price
€18,000 to €35,000
excl. VAT, indicative

Discuss this pack — NIS2 Ready

White-label SOC and MDR

Delivered with a qualified partner

Detection and response around the clock, delivered with a PDIS-qualified partner, with detection use cases written for your environment and a single point of contact on our side.

What is included

  • 24/7 monitoring and triage
  • Detection use cases for your stack
  • Containment actions by agreement
  • Monthly detection performance review
  • Escalation to incident response
SOC

Discuss this service — White-label SOC and MDR

Vulnerability and attack-surface management

Continuous scanning of what you own and what is exposed in your name, with findings filtered, prioritised and tracked to closure rather than published as a raw list.

What is included

  • Internal and external scanning
  • External attack surface discovery
  • Risk-based prioritisation
  • Remediation tracking against SLAs
  • Monthly reporting
SOCOffensive

Discuss this service — Vulnerability and attack-surface management

Managed DevSecOps

Standing engineering capacity that keeps pipelines, guardrails and compliance evidence working as your platform changes, with a named engineer and a monthly review.

What is included

  • Named engineer and agreed capacity
  • Pipeline and guardrail maintenance
  • Finding triage and remediation support
  • Compliance evidence upkeep
  • Monthly review and roadmap
SOCAssessment

Discuss this service — Managed DevSecOps

Managed FinOps

Continuous cost management: allocation kept accurate, commitments managed, waste removed each month, and savings reported as measured figures.

What is included

  • Cost allocation upkeep
  • Commitment and discount management
  • Monthly rightsizing actions
  • Anomaly detection and alerts
  • Measured savings reporting
SOCAssessment

Discuss this service — Managed FinOps

Be ready in thirty days

Crisis-ready in 30 days gives you a tested incident plan, the playbooks, and the exercise that proves they work.