Seven services, one operating model. Most organisations do not need all seven at once. They need to know which one answers the problem in front of them, and what comes next to it.
These are not standalone line items. They form one cycle, and most customers enter it somewhere in the middle.
Each has its own page covering scope, method and what you receive.
Round-the-clock detection, triage and response. An analyst stops the incident, not just logs it.
OpenZero Trust, identity management and PKI. A design you can still operate in ten years.
OpenCloud hardening, Infrastructure as Code and resilient operations across environments.
OpenSIEM, XDR and SOAR: architecture, detection content and fewer false positives.
OpenPenetration testing, red team and TLPT. Evidence that controls work, not that they exist.
OpenThreat hunting, intelligence and risk analysis. We look for what detection does not see yet.
OpenSenior capacity embedded in your team, for a project or for a standing role.
OpenSame operations, different evidence requirement. Each framework has a page mapping its obligations onto these services.
Straight answers to what clients ask us most.
A SOC is a function; MDR is a way to buy it. A SOC (Security Operations Center) is the team and process that continuously monitors security events and acts on them. MDR (Managed Detection and Response) means an external provider runs that function for you, response included rather than alerting only. The difference from a classic MSSP is exactly that response: an MSSP typically sends the alert, MDR stops the incident.
Most customers start with one. Usually SOC and MDR, because continuous monitoring is an obligation that cannot be deferred, or a penetration test, because a counterparty demands it. The rest are added based on what the first one surfaces. We do not try to sell all seven at once.
We operate it. Every service includes a running system: tuned detection, a staffed shift, playbooks, tests. Documentation is delivered as evidence of what is running, not instead of it.
Yes, and they are mapped to them. Act 264/2025 requires incident detection and reporting, risk management, testing of measures, technical and organisational controls, and supply-chain management. The NIS2 page maps each of those obligations onto a specific service.
SOC and MDR onboarding usually takes weeks rather than months, because we deploy as infrastructure as code. The exact time depends on how many log sources are connected and what condition they are in. A penetration test is scheduled against the scope and the deadline you need to evidence.
Tell us what you are dealing with. We will say which service covers it, including when you do not need it from us.