The question they asked,
and what was really going on.
Below is what a customer asked in each situation, what turned out to sit underneath that question, and what it eventually delivered. The first question is rarely the real problem: whoever asks for more monitoring is usually missing coherence. No names are attached, because our customers have not given permission for that.
Four engagements currently running.
No names and no logos: our customers have not given permission for that, and we do not ask for it unprompted. What you can read here is how the collaboration works and which part we take on.
MDR and SOC on top of our platform.
A security company delivers MDR and 24/7 SOC services to its own customers, running them on our multi-tenant managed SIEM platform. We keep the platform standing, scaling and properly separated per tenant. That keeps their analysts on detection logic and operations instead of on maintenance. Our role here is supporting; we are not a SOC.
Migration to a managed platform.
A service provider moved its own Splunk environment onto our managed platform service. Platform operations now sit with us, so their team can keep its attention on monitoring the services they deliver themselves. That is where their time is worth most, not in upgrades and capacity planning.
From platform to internal service.
A long-running partnership through professional services. The Splunk platform was already there; the task was turning it into an internal service colleagues across the organisation can build on. That is a matter of design, but just as much of ownership, agreements and connecting to what the business wants to know.
Operations and 24/7 response for critical infrastructure.
Professional services combined with 24/7 incident response on security infrastructure that cannot go down. Alongside operations we build knowledge within their own team, the goal is that they can do more themselves, not that they come to depend on us.
Would you like to speak to one of them? Just ask. We will put the question to them rather than put their name on a website.
The new cybersecurity act.
The subject we currently get the most questions about, and the one most organisations start on later than is wise.
“Our policy is in order” .
A manufacturer had the policy document ready, the roles assigned and the measures described. Then a customer asked: show me what happened during that incident in March.
They could not. Not because nothing had happened, but because the timeline was spread across four systems and the OT side was not measured at all. The reconstruction took three weeks, and the result was a story rather than evidence.
What it became: one timeline across IT and OT, reading along at the boundary between office and production. The next question was answered within a day.
What NIS2 asks of you technicallyCompliance is policy, proving it is engineering.
We do not make you compliant, that is about people and practice. We make sure you can show what happened. That is the part organisations get stuck on.
Questions we hear more than once.
Not customer stories but patterns: situations that come up so often they stand apart from any one organisation. Recognise one and you already know what the conversation is about.
Four teams, four dashboards, one waiting customer.
The question was more monitoring. What sat underneath: every team watched its own layer and nobody saw the chain. It became one timeline per transaction, and recovery time halved because searching got shorter.
Who accessed this record.
The question came from the data protection officer. What sat underneath: access logging that existed but was not searchable. It became an audit trail where that question is answered in seconds.
The auditor arrives in November.
Every year the same: three weeks of work to demonstrate what had happened all year. It became a standard report that runs throughout the year. The audit took four days.
This figure is wrong.
Two departments reported different availability for the same service. What sat underneath: two definitions of the word outage. It became one definition in the platform.
We are not allowed to touch that.
The production environment was invisible because intervening is not allowed. It became reading along at the boundary. Zero interventions in the process.
Why does our licence grow every year.
The question was cost saving. What sat underneath: nobody knew which source caused which volume. It became insight per source and per department, and a supplier conversation that rested on figures for the first time.
Then this is the right moment.
You do not need a project to call. Most engagements start with someone who could not demonstrate one thing and wondered whether that would get worse.
Bring one question that keeps slipping: an incident you cannot reconstruct, a figure that gets disputed, an audit question that returns every year.
Book that conversationThese stories are anonymised .
Our customers are not named here, and that stays that way until they give permission themselves. Want to speak to a reference? Ask, and we arrange a conversation rather than a logo on a website.
Three things that keep coming back.
The first question is rarely the problem.
Someone asking for more monitoring is usually missing coherence. Someone asking to cut costs is usually missing insight. That is why every engagement starts with a question rather than a quote.
The evidence has to be there already.
Anything reconstructed afterwards is a story. What was recorded at the moment itself is evidence. That difference is not legal but technical, and it cannot be made up later.
Starting small works better.
One customer process, one source, one question. Anyone who wants everything at once is still taking inventory six months later.
Which question keeps slipping at your organisation?.
One incident, one figure or one audit question is enough to start.