Data sources
Firewalls, EDR, sign-in records from Entra ID, the audit trail in Microsoft 365, domain controllers, file servers and your key business applications.
Watching only pays off when there are protective tools and proper logging underneath. Those come first; the observation layer sits on top. We will not sell a SOC to a company that has not yet switched on a second factor for sign-ins.
Firewalls, EDR, sign-in records from Entra ID, the audit trail in Microsoft 365, domain controllers, file servers and your key business applications.
Individual events look harmless; together they spell an attack: a login from an unfamiliar country, a new rule forwarding mail outside and hundreds of SharePoint files pulled down, all inside sixty minutes.
Detections shaped around how your company works, backed by the MITRE ATT&CK catalogue of adversary techniques.
Blocking an account, isolating a computer, revoking sessions and tokens. All according to a playbook with permissions agreed upfront.
The route in, what the intruder did, what data might be gone, and which changes stop a repeat.
Help preparing the technical part of an incident report for the relevant CSIRT, and of a breach notification to the Polish data protection authority when personal data is involved. Your company submits the report.
How long connection takes depends on the number of sources, and most of the work goes on adapting detections to how you operate.
We establish which of your systems log anything worthwhile, for how long it is retained and where the blind spots are.
Everything flows into one platform, for example Microsoft Sentinel, and is converted to a shared schema.
For the first few weeks we cut out false positives. Without that, genuine signals drown in noise and people stop reacting.
Continuous oversight, response by playbook, a periodic report and regular rule reviews.
Watching is pointless if nobody is allowed to act. In the middle of the night the analyst on shift can see the intrusion yet has no mandate to pull the server, and the manager who could decide has muted their phone. When we connect you, we write down who holds decision rights, how to reach them, and which steps we can take without waiting for permission.
The basics: a second factor on sign-ins, antivirus or EDR run from one place, unneeded ports shut and backups that ransomware cannot reach. Watching an unprotected environment is little more than observing a break-in as it happens.
Work out what a day of downtime and a leak of customer data would cost. In an office where IT mostly means email and documents, solid safeguards and backups are usually enough. For a factory or a web shop, the service can earn back its cost the first time it catches an attack early.
Someone you nominate who can order systems to be stopped. That is for management to settle, not the technicians, and it must be agreed before we go live. You may also authorise us in advance for certain moves, such as disabling a hijacked account.
NIS2 and the KSC act set short, multi-stage deadlines for reporting significant incidents by the organisations they cover. Confirm with a lawyer which duties apply to your company. Breaches involving personal data must reach the data protection authority within 72 hours. We prepare the chronology and technical facts; you remain the party that submits.
Tell us which systems are critical to you and what an hour of downtime costs. You will get a straight answer on whether a SOC makes sense now or the fundamentals need attention first.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.