Skip to content
An operations room: staff at consoles facing a wall of screens, each watching a different feed.

Services

Managed Services

Detection, response and operations, run for you around the clock.

Detection, response and operations, run for you around the clock.

A mid-size company cannot staff a security operations centre, and should not have to. What it needs is someone watching, someone who answers at three in the morning, and someone who makes sure the monthly work — patches, scans, cost reviews, control evidence — actually happens.

We run detection through a partner SOC under our supervision, with the alerts triaged by people who know your estate, and we keep the response side ready: an incident plan that exists before the incident, playbooks that have been exercised, and a forensics team on call.

The same retainer covers the operations nobody has time for. Vulnerability management with real deadlines, cloud security and compliance checks that run continuously, and FinOps so the cloud bill goes down rather than up. One contract, one contact, a monthly report your board can read.

Managed Services

SOC management

Continuous detection, threat intelligence and vulnerability watch, with a named analyst on the other end.

  • Managed SOC and MDRTypical duration: RecurringDelivered with a qualified partner

    Round-the-clock detection and response delivered white label with a PDIS-qualified partner, with use cases written for your environment and a named escalation path.

    You receive

    • Detection use-case catalogue
    • Log source onboarding plan
    • Escalation and response runbooks
    • Monthly detection performance review
  • Threat intelligence and attack-surface monitoringTypical duration: Recurring

    Continuous watch on what is exposed in your name: domains, certificates, leaked credentials and third-party breaches, filtered to what is worth acting on.

    You receive

    • External attack surface inventory
    • Credential leak monitoring
    • Sector threat briefings
    • Monthly actionable alert digest
  • Vulnerability managementTypical duration: Recurring

    A continuous cycle with defined scan coverage, risk-based prioritisation and service levels for remediation, reported in terms the executive committee can act on.

    You receive

    • Scanning coverage and schedule
    • Risk-based prioritisation model
    • Remediation SLAs by severity
    • Monthly reporting pack

CERT and incident response

Plans that exist before the incident, and a team that answers when it happens.

  • Incident response plan and playbooksTypical duration: 5–12 days

    A response plan with named roles, decision thresholds and the regulatory notification clocks already built in, plus playbooks for the scenarios you will actually face.

    You receive

    • Incident response plan and severity scale
    • Playbooks for ransomware, fraud, data breach
    • Regulatory notification timelines
    • Contact and escalation matrix
  • Incident response and forensicsTypical duration: On callDelivered with a qualified partner

    On-call response with a PRIS-qualified partner: containment first, then evidence preservation, root cause, and the report your insurer and regulator will ask for.

    You receive

    • Containment and eradication support
    • Forensic analysis and timeline
    • Root cause report
    • Post-incident hardening plan
  • Business continuity and disaster recoveryTypical duration: 10–25 days

    Business impact analysis, continuity strategy and a recovery plan that has been tested, not just written, with the cyber scenario treated as a first-class case.

    You receive

    • Business impact analysis
    • Continuity and recovery strategy
    • Disaster recovery runbooks
    • Test plan and exercise results

Managed operations

Security, cost and compliance work that has to run every month, run for you.

  • Managed DevSecOps retainerTypical duration: Recurring

    A standing engineering capacity that keeps the pipeline, the guardrails and the evidence working as your platform changes, with a named engineer and a monthly review.

    You receive

    • Named engineer and agreed capacity
    • Pipeline and guardrail maintenance
    • Finding triage and remediation support
    • Monthly review and roadmap
  • FinOpsTypical duration: 10–25 days

    Cost allocation, commitment strategy, rightsizing and waste elimination, typically returning fifteen to thirty per cent of the bill within the first quarter.

    You receive

    • Cost allocation and tagging model
    • Rightsizing and commitment plan
    • Savings tracker with measured results
    • Monthly FinOps reporting
  • Continuous cloud security and complianceTypical duration: Recurring

    Posture management that runs every day and reports in the language of your control framework, so cloud evidence for ISO 27001 or SOC 2 is produced automatically.

    You receive

    • Continuous control monitoring
    • Compliance dashboards per framework
    • Drift and exception workflow
    • Automated evidence export

NIS2 Ready

From applicability to a defensible compliance position, with the governance duties covered.

Duration
8–12 weeks
Price
€18,000 to €35,000
excl. VAT, indicative

Discuss this pack — NIS2 Ready

White-label SOC and MDR

Delivered with a qualified partner

Detection and response around the clock, delivered with a PDIS-qualified partner, with detection use cases written for your environment and a single point of contact on our side.

What is included

  • 24/7 monitoring and triage
  • Detection use cases for your stack
  • Containment actions by agreement
  • Monthly detection performance review
  • Escalation to incident response
SOC

Discuss this service — White-label SOC and MDR

Vulnerability and attack-surface management

Continuous scanning of what you own and what is exposed in your name, with findings filtered, prioritised and tracked to closure rather than published as a raw list.

What is included

  • Internal and external scanning
  • External attack surface discovery
  • Risk-based prioritisation
  • Remediation tracking against SLAs
  • Monthly reporting
SOCOffensive

Discuss this service — Vulnerability and attack-surface management

Managed DevSecOps

Standing engineering capacity that keeps pipelines, guardrails and compliance evidence working as your platform changes, with a named engineer and a monthly review.

What is included

  • Named engineer and agreed capacity
  • Pipeline and guardrail maintenance
  • Finding triage and remediation support
  • Compliance evidence upkeep
  • Monthly review and roadmap
SOCCloud

Discuss this service — Managed DevSecOps

Managed FinOps

Continuous cost management: allocation kept accurate, commitments managed, waste removed each month, and savings reported as measured figures.

What is included

  • Cost allocation upkeep
  • Commitment and discount management
  • Monthly rightsizing actions
  • Anomaly detection and alerts
  • Measured savings reporting
SOCCloud

Discuss this service — Managed FinOps

Be ready in thirty days

Crisis-ready in 30 days gives you a tested incident plan, the playbooks, and the exercise that proves they work.