Symptom
Alert backlog grows faster than triage capacity
- Root cause
- Detection content tuned at deployment, never updated
- Business risk
- Dwell time > 30 days, NIS2 exposure
Managed SOC · NIS2 Aligned
A 24/7 detection and response capability built on the controls and reporting cadence the NIS2 directive actually requires.
Overview
Most German mid-market estates have a SIEM but no operating capacity behind it: alerts queue overnight, telemetry coverage is partial, and incident timelines cannot survive a regulator’s 24-hour notification window.
Diagnostic
What we typically inherit from previous SOC vendors and internal teams.
Symptom
Symptom
Symptom
Symptom
Detection
High alert volume often signals immature detection content, not strong coverage. Our SOC operates against detection engineering KPIs (MTTD, MTTC, false-positive ratio) and publishes them monthly to the customer.
Detection content is versioned, peer-reviewed, and aligned to MITRE ATT&CK.
Definition
A Managed Security Operations Centre is an externally operated 24/7 capability that ingests security telemetry, detects suspicious activity through engineered detection content, triages alerts, and coordinates incident response on behalf of the customer.
Delivery model
A repeatable five-step engagement for any SOC takeover or new build.
Map current log sources to MITRE ATT&CK; identify blind spots in identity, endpoint, network and SaaS layers.
Sigma-based content, peer-reviewed, version-controlled and shipped to your SIEM through CI.
L1–L3 analysts on Follow-the-Sun rotation across Stuttgart, Cairo and Kyiv; documented playbooks per use case.
Pre-formatted incident reports for the BSI 24h / 72h notification windows; monthly executive review.
Quarterly purple-team exercises, content retirement and false-positive reduction loop.
Compliance
How our delivery model maps to the four reference frameworks German enterprises are audited against.
| Control | ISO 27001 | NIS2 | BSI-Grundschutz | GDPR |
|---|---|---|---|---|
| Logging & Monitoring | A.8.15 / A.8.16 | Art. 21(2)(b) | OPS.1.1.5 | Art. 32 |
| Incident Response | A.5.24–A.5.27 | Art. 21(2)(b) / Art. 23 | DER.2.1 | Art. 33–34 |
| Detection Engineering | A.8.16 | Art. 21(2)(b) | DER.1 | Art. 32(1)(b) |
| Threat Intelligence | A.5.7 | Art. 21(2)(c) | DER.1.A.5 | — |
| Tabletop Exercises | A.5.30 | Art. 21(2)(g) | DER.4 | — |
Questions & Answers
Definitions, delivery detail and commercial answers in one place — written to be quotable by search and AI answer engines, and readable by your team.
NIS2 requires essential and important entities to detect, contain and report significant incidents within 24 hours of awareness, with a full report at 72 hours. A SOC must therefore operate continuously and produce regulator-grade incident timelines.
We start with a 30-minute diagnostic of your current delivery — at no cost and with no sales pitch. You leave with a written summary of findings either way.