ServicesOperations, not slideware

    Cybersecurity services

    Seven services, one operating model. Most organisations do not need all seven at once. They need to know which one answers the problem in front of them, and what comes next to it.

    Operations, not slideware

    How they fit together

    These are not standalone line items. They form one cycle, and most customers enter it somewhere in the middle.

    Design
    Security Architecture and Cloud Automation decide what the environment should look like: segmentation, identity, PKI, infrastructure as code.
    Build
    Security Engineering turns that into detection you can operate. SIEM, XDR and SOAR, with detection content that has an author and a version.
    Run
    SOC and MDR hold the round-the-clock shift. Threat Operations hunts what detection has no rule for yet.
    Prove
    Offensive Security demonstrates it all works. Penetration tests and red team are evidence, not a formality.
    Staff
    Team Augmentation fills the gap when you need the role covered before you can hire it.
    Compliance

    The regulations this covers

    Same operations, different evidence requirement. Each framework has a page mapping its obligations onto these services.

    FAQ

    Frequently asked questions

    Straight answers to what clients ask us most.

    A SOC is a function; MDR is a way to buy it. A SOC (Security Operations Center) is the team and process that continuously monitors security events and acts on them. MDR (Managed Detection and Response) means an external provider runs that function for you, response included rather than alerting only. The difference from a classic MSSP is exactly that response: an MSSP typically sends the alert, MDR stops the incident.

    Most customers start with one. Usually SOC and MDR, because continuous monitoring is an obligation that cannot be deferred, or a penetration test, because a counterparty demands it. The rest are added based on what the first one surfaces. We do not try to sell all seven at once.

    We operate it. Every service includes a running system: tuned detection, a staffed shift, playbooks, tests. Documentation is delivered as evidence of what is running, not instead of it.

    Yes, and they are mapped to them. Act 264/2025 requires incident detection and reporting, risk management, testing of measures, technical and organisational controls, and supply-chain management. The NIS2 page maps each of those obligations onto a specific service.

    SOC and MDR onboarding usually takes weeks rather than months, because we deploy as infrastructure as code. The exact time depends on how many log sources are connected and what condition they are in. A penetration test is scheduled against the scope and the deadline you need to evidence.

    Not sure where to start?

    Tell us what you are dealing with. We will say which service covers it, including when you do not need it from us.