Detection without follow-up
is theatre.
We build and run the SIEM and the detection logic, so your analysts get to detection and follow-up instead of platform maintenance. Out-of-the-box detections produce alerts nobody acts on; the work is in tuning them to your environment and measuring whether a detection still fires. We are not a SOC, we are the layer underneath it.
Detection without follow-up is theatre.
Many SIEM implementations start with out-of-the-box detections. Those do not know your environment, produce false positives, and are mostly switched off within six months.
- We build and run the SIEM platform and the data flows beneath it
- Detections built for your environment, tested for false positives before going live
- Your MDR and 24/7 SOC can run on our platform, your own, or a partner’s
- Every quarter we add what is needed and remove what no longer works
We are not a SOC.
And we say so. Our role is supporting: the platform, the data quality and the detection logic are ours, so a SOC analyst can spend time on detection and operations rather than on the platform underneath.
If you have your own SOC, it simply runs on our environment. If you do not, we work with partners who deliver it. We are not tied to one party, so the choice stays yours.
Detection logic that keeps working.
Sources in order.
Without complete, normalised data every detection is a guess. We start with what comes in and whether it holds up.
Detections tuned to your environment.
Tested for false positives before they go live. A rule that fires wrongly every day costs you more than it returns.
Follow-up assigned.
Who looks at it, within what time, and what does that person then do? Agreed before the first alert arrives.
Cleaned up every quarter.
Whatever returns nothing goes out, even if it took work to build. Otherwise the number of rules grows until nobody trusts them.
What customers hereusually ask first.
Do you run a 24/7 SOC?
No, we are supporting. We build and manage the SIEM and the detection logic, so a SOC analyst spends their time on detection and operations instead of on the platform. Your MDR and 24/7 SOC can run on our environment: your own SOC, or one run by a partner. If you do not one, we put you in touch with parties we work with. We are not tied to a single one.
We already have a SIEM. Do we start over?
Rarely. The problem usually sits in the data underneath and in detections nobody trusts any more. You can repair that without replacing the platform.
How does this relate to audit trail?
They share the same events. Security looks forward at what is going wrong, audit trail looks back at what happened. Set up both and you do the work once.
Can you help during an incident?
With the investigation: the timeline, the sources, what happened when. The decisions and the communication stay with you or with your SOC party.
Which detection would you not trust today?.
That is usually a good place to start. Bring one and we will look at where it goes wrong.