SOC & managed services
What we build
Designing and building a complete security operations centre on Splunk Enterprise Security and Splunk SOAR is our core business.
- Collection and normalisationSources are ingested then brought to a common model, without which nothing correlates.
- Detection use casesMapped to MITRE ATT&CK, so coverage can be measured rather than assumed.
- Automation playbooksThe repetitive steps of triage and response, carried out by SOAR.
- Operational dashboardsWhat the team looks at daily, and what management reads.
- Skills transferTo the teams taking over: a SOC nobody else can run has not been delivered.
What we are offering to operate
We offer a managed-services proposition, drawing on the experience of the SOCs we build for our clients.
- MSPDay-to-day administration of your Splunk platform, keeping it in operational condition, a service desk, continuous value creation from your data.
- MSSPRunning your SOC: security alert handling, from qualification through investigation to remediation recommendations.