SOC.MDRManaged Security

    SOC & MDR

    We watch your systems around the clock and stop an attack before it turns into downtime or a data breach. Evidence for NIS2, DORA and ZoKB audits arrives finished, ready to hand to the auditor.

    Why Kybit SOC & MDR

    Detection, response and reporting are run by senior analysts on live production stacks.

    01

    Senior-led Triage

    Tier-2 and Tier-3 analysts own every high-severity alert from triage to closure. The analyst who picks it up is the one who closes it.

    02

    Proprietary SOAR Orchestration

    Our SOAR engine runs L1 and L2 triage in seconds. A senior analyst picks the alert up at the containment step. MTTD p95 under 15 minutes, MTTR p95 under 60 minutes.

    03

    Hard SLAs

    Detection MTTD < 15 min p95, response MTTR < 60 min p95 for critical incidents. Escalation paths are written into the contract.

    04

    Privacy-First Local LLM

    Alert enrichment runs on an air-gapped LLM on our own hardware. Customer context and threat intelligence stay inside our infrastructure.

    Capabilities

    Four tiers, from 24/7 monitoring to an incident response retainer. One operating model behind all of them.

    01

    24/7 SOC Monitoring

    • Continuous log + telemetry ingestion across endpoints, network, identity, cloud
    • Real-time alert triage with a computed severity score
    • Behavioural analytics and anomaly detection on identity + endpoint telemetry
    • Every shift hand-off is written down before the next shift takes over
    • Quarterly tuning to reduce false positives without lowering coverage
    02

    Managed Detection & Response

    • Detect, contain, eradicate, report. Kybit owns the whole lifecycle
    • Active containment authority on agreed asset classes (with MFA-gated kill-switch)
    • MITRE ATT&CK-mapped detection content reviewed quarterly
    • Playbooks written for your environment and reviewed with your IT lead
    • Monthly written report with findings mapped to ISMS objectives
    03

    Threat Hunting

    • Every hunt starts from a written hypothesis
    • Coverage gap analysis vs current MITRE ATT&CK matrix
    • Every hunt outcome is turned into detection content
    • Adversary emulation aligned to threats relevant to your sector
    • Annual purple-team retest with regression on prior findings
    04

    Incident Response Retainer

    • Retainer guarantees an on-call senior responder within 60 min
    • Forensic acquisition + analysis (Velociraptor, KAPE, host triage)
    • Containment + eradication coordination with your IT and legal teams
    • Notification support for NIS2 / GDPR / DORA timelines
    • Post-incident report + remediation roadmap, signed
    Onboarding

    Onboarding in 14 days. No three-month analysis projects.

    Traditional integrators spend months in workshops. We build the infrastructure, parse the logs and tune the detections straight away. A standardised process that brings you in line with NIS2 inside two weeks.

    1. Days 1–2

      Analysis and threat model

      • Mapping the network and identifying critical assets.

      • The threat model is built for your business and your technology. We do not work from generic templates.

    2. Days 3–5

      Architecture and data ingestion

      • Connecting to your existing SIEM/EDR, or rolling out Wazuh agents if you are starting from a green field.

      • Bringing up our ingestion hubs, which act as a local cache and provide a secure mTLS tunnel for shipping logs to our SOC.

    3. Days 6–10

      Parsing and detection content

      • The phase that genuinely takes the longest. We normalise the data flows and write custom parsers for your specific technology.

      • Detection rules go live, mapped directly to the current MITRE ATT&CK matrix.

    4. Days 11–14

      Tuning and the live SOC portal

      • Hard rule tuning against your real traffic to filter out false positives. 24/7 monitoring and contractual SLAs go live (MTTD < 15 min).

      • You do not just get a monthly PDF report. You get live access to the client SOC portal, where you can see the state of the detections and our analysts at work.

    Operating Stack

    We operate the SIEM, XDR and DFIR tools you already run. If you are still choosing, we tell you what we would run ourselves.

    • Wazuh
    • KybitNexus
    • MISP
    • Microsoft Defender for Endpoint
    • SentinelOne
    • Velociraptor
    • Microsoft Sentinel
    FAQ

    Frequently asked questions

    Straight answers to what clients ask us most.

    A SOC (Security Operations Center) is the function that collects telemetry, correlates it and decides what is a real attack. Its output is a triaged alert handed to the customer. MDR (Managed Detection and Response) also takes the intervention itself, isolating an endpoint or killing a session, without waiting for your team to pick up the phone. The difference shows in the metric written into the contract. A SOC is measured on time to triage, MDR on time to contain, which is MTTR. Kybit runs both as one service, targeting MTTD p95 under 15 minutes and MTTR p95 under 60 minutes. Czech law calls both a managed security service in Act No. 264/2025 Coll., Section 18(1).

    Days to a few weeks. Source connection and detection content are both driven by Infrastructure as Code, so we collect the first telemetry on the day we get access. What is left of the timeline is your side approving access and network paths.

    We are vendor-agnostic. Our Agentic SOC runs on our own SOAR, so we are not tied to a catalogue of ready-made connectors and write missing integrations ourselves, usually within days. The point is to get value out of the stack you already own without a migration.

    Target: MTTD p95 under 15 minutes, MTTR p95 under 60 minutes. Exact figures are locked in the SLA based on telemetry coverage, risk profile and the on-call expectations of your environment.

    Act No. 264/2025 Coll. requires an initial report within 24 hours of detecting a cybersecurity incident, and within 72 hours a notification adding the first assessment and any indicators of compromise (Section 16(1) and 16(3)). Inside those windows MDR supplies the incident timeline and impact classification from telemetry we already collect. We file on the NÚKIB portal together with you.

    Yes, that is the common setup. MDR takes 24/7 monitoring and first response, your team stays on operations and change. Detections and SOAR playbooks live in your Git, so you can read our work commit by commit.

    Add a real SOC to your business

    Talk to a senior responder. You get the operating model and a written SLA. No discovery-call deck.