Skip to content
Ciberseg
Flagship service · 24×7

A Security Operations Centre, run for you.

Central security monitoring and incident management for IT and OT infrastructures — around the clock. Our analysts detect, validate and respond to threats in your environment so your team can focus on the business. Vendor-independent, ISO 27001-aligned, with data residency you control.

  • Real-time detection and correlation of security events
  • Alert validation and prioritisation by experienced SOC analysts
  • Incident analysis, escalation and SLA-based response
  • Modern SIEM and threat-intelligence technologies
  • Regular reporting and continuous security improvement
Illustrative SOC view
What the SOC does

Central monitoring and response — around the clock.

Central security monitoring and incident management for IT and OT infrastructures — around the clock. Our analysts detect, validate and respond to threats in your environment so your team can focus on the business. Vendor-independent, ISO 27001-aligned, with data residency you control.

Real-time detection and correlation of security events

Alert validation and prioritisation by experienced SOC analysts

Incident analysis, escalation and SLA-based response

Modern SIEM and threat-intelligence technologies

Regular reporting and continuous security improvement

Detection & protection

Detection and protection services.

Six managed capabilities plugging directly into your SOC environment — each vendor-validated, MITRE-mapped, and operated by our analysts around the clock.

Managed EDR

Endpoint Detection & Response

24/7 endpoint monitoring with automated detection and isolation of compromised systems, plus threat hunting mapped to MITRE ATT&CK.

Microsoft Defender · SentinelOne · CrowdStrike


  • Automated isolation of compromised endpoints
  • Threat hunting via MITRE ATT&CK
  • Per-endpoint, flexible tiering

Managed NDR

Network Detection & Response

AI-driven analysis of network traffic that surfaces lateral movement, zero-day activity and command-and-control — including OT/ICS protocols.

Passive · OT/ICS: Modbus, S7, OPC-UA


  • Detects lateral movement & C2 traffic
  • Shadow-IT and cloud-communication visibility
  • NIS2 & KRITIS compliance support

Managed Vulnerability Assessment

VAS

Continuous, risk-based scanning correlated by SOC analysts so you fix what actually matters, in the right order.

Qualys · Tenable · CVSS / EPSS


  • Continuous agent- & network-based scanning
  • Risk-based prioritisation by analysts
  • Remediation tracking in the SOC dashboard

Darknet Intelligence

Dark-web & brand monitoring

Detection of stolen credentials, leaked data and exposed domains across the dark web, with actionable alerts and optional executive monitoring.

Cyble Threat Intelligence Platform


  • Stolen-credential & data-leak detection
  • Brand & domain exposure monitoring
  • Executive monitoring add-on available

Privileged Access Management

PAM

Centralised control of access to critical systems, with session recording, just-in-time access and MFA — closing the door on insider threats and privilege misuse.

Session recording · JIT · MFA


  • Just-in-time access & password vaulting
  • Session monitoring & real-time analysis
  • Audit evidence for ISO 27001 & NIS2

Ransomware Resilience

AI prevention & auto-recovery

AI-based detection and blocking before encryption occurs, with automated file rollback and self-healing for affected systems.

Halcyon-powered · NIS2 / DORA / TISAX


  • Pre-encryption detection & autonomous blocking
  • Automated file rollback & self-healing
  • No backups or ransom payments required
Response when it matters

Response when it matters.

When an incident lands, speed is everything. Our response capabilities are designed to contain, analyse and recover — measured in minutes, not hours.

Incident Response

Aligned with NIST & ISO 27035

24/7 access to experienced IR specialists for rapid assessment, containment, forensic analysis and recovery — with documented lessons learned.


  • Immediate assessment & containment
  • Forensics & root-cause determination
  • Technical, organisational & comms support
  • Retainer packages: 25 hrs (Basic) / 50 hrs (Enterprise)

First Response

Containment in minutes, not hours

Playbook-driven immediate actions for P1/P2 incidents — endpoint isolation, account lockout and firewall activation — seamlessly integrated into the Managed SOC.


  • Up to 5 custom playbooks per client
  • Endpoint isolation, account lockout, firewall rules
  • 24×7 for critical & high incidents
Deployment models

Four deployment models. One team.

No single vendor owns your security. Choose the stack that fits your budget, your existing estate and your data-residency requirements — we operate them all.

All models run on infrastructure managed by Ciberseg, with full EU data residency and zero dependency on a single technology vendor.

01

Stellar Stack

AEGYS × Stellar Cyber
Base price
SIEM / XDR
Stellar Cyber Open XDR
NDR sensor
AEGYS Pulse NDR included
  • Open XDR and NDR on one platform
  • NDR sensor included in the package price
  • AI-assisted threat detection
  • Lowest complexity for SMEs
  • GDPR-compliant, data stored in Germany
02

Wazuh Stack

Open-source SIEM
Base price
SIEM / XDR
Wazuh SIEM/XDR
NDR sensor
AEGYS Pulse NDR (add-on)
  • No licence cost — full service margin
  • SIEM + XDR + FIM + vulnerability management
  • Can be self-hosted in Germany
  • No vendor lock-in
  • Largest open-source SIEM community
03

Sentinel Stack

Microsoft Azure SIEM
+30 % on the package price
SIEM / XDR
Microsoft Sentinel
NDR sensor
AEGYS Pulse NDR (add-on)
  • Native Microsoft 365 and Azure integration
  • AI analytics with Microsoft Copilot
  • SOAR and automation out of the box
  • Pay-as-you-go licensing model
  • Ideal for Microsoft 365 environments
04

Splunk Stack

Enterprise SIEM
+50 % on the package price
SIEM / XDR
Splunk Enterprise Security
NDR sensor
AEGYS Pulse NDR (add-on)
  • Market leader with the largest ecosystem
  • 180-day log retention as standard
  • Deepest search and analysis
  • PCI DSS, HIPAA and SOX out of the box
  • Dedicated premium support team
Managed SOC pricing

Transparent, scalable SOC pricing.

Three tiers designed for the scale you are today and the ambition you have tomorrow. All tiers include 24×7 shift operations and a dedicated Security Delivery Manager.

Starter

Entry

€149month
Covers
5–10 end users
SOC hours
8×5
P1 response
6 h

Business

Popular

€349month
Covers
11–50 end users
SOC hours
8×5
P1 response
4 h
Recommended

Professional

Recommended

€749month
Covers
51–250 end users
SOC hours
8×5
P1 response
4 h

Professional+

Scale

€1,495month
Covers
251–1,000 end users
SOC hours
24×5
P1 response
2 h

Enterprise

Enterprise

€2,995month
Covers
1,001–2,000 end users
SOC hours
24×7
P1 response
2 h

All prices are net and exclude VAT. The AEGYS Pulse NDR sensor is supplied as a loan unit and returned at the end of the contract. Add-on prices scale with the agreed user and asset counts. Quotations are subject to a setup fee based on effort.

Full pricing, add-ons and SLA
Service-level agreements

Service-level agreements.

Our SLAs are contractually binding. Every priority class has a defined response window and an escalation path — no ambiguity, no excuses.

Service-level agreements.
SLA criterionStarterBusinessProfessionalProfessional+Enterprise
AvailabilityMeasured per calendar month99.0 %99.5 %99.9 %99.9 %99.99 %
First response P1Standard per package. The First Response add-on brings this to under 30 minutes from Professional+6 h4 h4 h2 h2 h
Escalation to customer P1Until reseller notificationNext business day8 h4 h2 h2 h
Reporting cadencePDF by e-mailMonthlyMonthlyWeeklyWeeklyWeekly
SOC operating hoursMon–Fri 08:00–17:00, or around the clock8×58×58×524×524×7
Data storageGDPR-compliant, no third countryGermanyGermanyGermanyGermanyGermany
GDPR data processing agreementArticle 28 GDPRIncludedIncludedIncludedIncludedIncluded
NIS2 documentationEvidence-ready for authorities and auditsBaselineChecklistFullFullFull
SLA penalty (max.)On a demonstrated SLA breach, capped at 30 % of the monthly charge5 %/h, max. 30 %5 %/h, max. 30 %5 %/h, max. 30 %5 %/h, max. 30 %5 %/h, max. 30 %
Contract termTerminable quarterly; renews automatically by a further year unless cancelled one month before expiry12 months12 months12 months12 months12 months

Above 2,000 end users the SLA is negotiated individually. All prices are net and exclude VAT.

How it works

How onboarding and operations work.

From initial scoping to continuous operations, every engagement follows a clear, repeatable lifecycle — so you know exactly where you are at every stage.

  1. 01

    Scoping

    Define assets, threat model and rules of engagement together with your team.

  2. 02

    Discovery

    Automated scanning and manual reconnaissance to map the real attack surface.

  3. 03

    Exploitation

    Controlled attack simulation to confirm which vulnerabilities are genuinely exploitable.

  4. 04

    Reporting

    Prioritised findings with CVSS scores, business impact and clear remediation steps.

  5. 05

    Remediation

    Guided fix support and re-testing to confirm every issue is closed for good.

Ready to activate your SOC?

Protect your organisation — starting this week.

Our onboarding team can have you live in the SOC within days. No long procurement cycles, no complex setup. Book a consultation and we will scope your environment the same day.

Always watching. Always protecting. Always ahead.