Co-managed SOC
Your SIEM
Our services
With the Co-Managed SOC, you receive our full SOC service for pre-defined cases or time periods. We integrate our Google SecOps SOAR platform and can get started straight away. No matter which SIEM you use, we’ll be up and running in no time. This allows us to provide you with targeted operational support, exactly as you need it – either for a specific number of cases or at specific times, e.g. from 7 pm.
Use cases for co-managed SOCs
'Co-managed' then means
relevant when ...
... you have a security infrastructure with a SIEM component and wish to continue managing its operation and licensing yourself.
... you need support with analysing security events and responding to them. On a regular basis, on-call or during an incident.
The prerequisite is that you have in-house SIEM expertise; otherwise, the independent operation of the SIEM platform cannot be guaranteed. If you do not have this, the Managed SOC is the more suitable service for you.
Immediate clarity on all security events
We are your co-pilot
our services
We bring depth and clarity to your security events – without the need for a major integration project. We complement, integrate and support your operations. No change of tools or platforms, no ‘black box’ service. Shared responsibility with a full managed SOC service within a defined framework. This includes:
Detection of relevant security events
Analysis & prioritisation of alerts
Support with response & containment
Continuous improvement of rules & playbooks
Our co-managed SOC complements existing security departments where operational depth and responsiveness are lacking, without compromising data sovereignty or architecture. Through our ‘bring-your-own SIEM’ approach, we offer maximum flexibility and ensure operational depth whilst maintaining clear lines of responsibility.
Philip Schildein
Chief Technology Officer
How we implement this technically
Easy integration
Low complexity
We access the normalised data from the SIEM and process it within our SOC architecture. This is cloud-native, meaning that the data is only processed, but not stored or retained. Data sovereignty is therefore maintained. Simple setup:
We access the existing SIEM technology and retrieve the data from it
Integration with the suresecure SOC architecture
Google SecOps SOAR as the analysis and automation layer
In this way, we very simply achieve a very high level of analytical depth, thereby increasing cyber resilience.
Bring your own SIEM
Co-managed SOC
Service modules
Security Monitoring
Monitoring of safety-related activities in accordance with the agreed framework. Either on the basis of time periods, criticality or case packages.
Quick onboarding
Get up and running quickly with cloud-native infrastructure and achieve operational efficiency within a few days. Transition managers provide support right through to the service launch.
ISO-certified processes
Our Managed SOC is ISO 27001 certified. This reduces risks in the supply chain and supports internal governance, compliance and audit requirements.
Automation thanks to SOAR
Analysis and response steps are carried out automatically via playbooks. This speeds up incident handling, reduces the amount of manual work required and ensures consistent responses in the event of an emergency.
Detection Engineering
We develop bespoke custom detections that are tailored precisely to your specific infrastructure. This enables us to identify exactly the patterns that are truly relevant in your environment.
Threat Intelligence
Security events are enriched with up-to-date threat intelligence. This makes it easier to categorise, prioritise and deal with incidents in a targeted manner.
Active Response
In an emergency, we are on standby immediately and respond without delay. This shortens decision-making processes and reduces the time taken to contain an attack.
SOC & AI
Whether it’s AI support in our processes or fully-fledged SOC agents: we’re always on a level playing field with the attacker groups.
