The suresecure team in three customised ‘Security Roles’ T-shirts in front of a stadium – IT security experts

Co-managed SOC

Your SIEM
Our services

With the Co-Managed SOC, you receive our full SOC service for pre-defined cases or time periods. We integrate our Google SecOps SOAR platform and can get started straight away. No matter which SIEM you use, we’ll be up and running in no time. This allows us to provide you with targeted operational support, exactly as you need it – either for a specific number of cases or at specific times, e.g. from 7 pm.

Use cases for co-managed SOCs

'Co-managed' then means
relevant when ...

  • ... you have a security infrastructure with a SIEM component and wish to continue managing its operation and licensing yourself.

  • ... you need support with analysing security events and responding to them. On a regular basis, on-call or during an incident.

The prerequisite is that you have in-house SIEM expertise; otherwise, the independent operation of the SIEM platform cannot be guaranteed. If you do not have this, the Managed SOC is the more suitable service for you.

A smiling Suresecure employee at the stadium

Immediate clarity on all security events

We are your co-pilot
our services

We bring depth and clarity to your security events – without the need for a major integration project. We complement, integrate and support your operations. No change of tools or platforms, no ‘black box’ service. Shared responsibility with a full managed SOC service within a defined framework. This includes:

  • Detection of relevant security events

  • Analysis & prioritisation of alerts

  • Support with response & containment

  • Continuous improvement of rules & playbooks

Image: Google Co-Managed SOC – Detect, Analyse, Respond
Philipp Schildein, Chief Technology Officer, suresecure

Our co-managed SOC complements existing security departments where operational depth and responsiveness are lacking, without compromising data sovereignty or architecture. Through our ‘bring-your-own SIEM’ approach, we offer maximum flexibility and ensure operational depth whilst maintaining clear lines of responsibility.

Philip Schildein

Chief Technology Officer

How we implement this technically

Easy integration
Low complexity

We access the normalised data from the SIEM and process it within our SOC architecture. This is cloud-native, meaning that the data is only processed, but not stored or retained. Data sovereignty is therefore maintained. Simple setup:

  • We access the existing SIEM technology and retrieve the data from it

  • Integration with the suresecure SOC architecture

  • Google SecOps SOAR as the analysis and automation layer

In this way, we very simply achieve a very high level of analytical depth, thereby increasing cyber resilience.

Screenshot from a co-managed SOC’s system

Bring your own SIEM

Co-managed SOC
Service modules

Security Monitoring

Monitoring of safety-related activities in accordance with the agreed framework. Either on the basis of time periods, criticality or case packages.

Quick onboarding

Get up and running quickly with cloud-native infrastructure and achieve operational efficiency within a few days. Transition managers provide support right through to the service launch.

ISO-certified processes

Our Managed SOC is ISO 27001 certified. This reduces risks in the supply chain and supports internal governance, compliance and audit requirements.

Automation thanks to SOAR

Analysis and response steps are carried out automatically via playbooks. This speeds up incident handling, reduces the amount of manual work required and ensures consistent responses in the event of an emergency.

Detection Engineering

We develop bespoke custom detections that are tailored precisely to your specific infrastructure. This enables us to identify exactly the patterns that are truly relevant in your environment.

Threat Intelligence

Security events are enriched with up-to-date threat intelligence. This makes it easier to categorise, prioritise and deal with incidents in a targeted manner.

Active Response

In an emergency, we are on standby immediately and respond without delay. This shortens decision-making processes and reduces the time taken to contain an attack.

SOC & AI

Whether it’s AI support in our processes or fully-fledged SOC agents: we’re always on a level playing field with the attacker groups.

Co-managed SOC

Excellent service
Market-leading technologies

Your trusted adviser

Jannik Lindemann

Account Executive