Cyber Security
Managed Security Services (MSSP / SOC)
ONGSEC takes on uninterrupted 24/7 cyber security monitoring for your organisation. With our own SOC infrastructure and SIEM solutions we detect, analyse and respond to threats in real time. The service can be structured as fully …
Scope of service
What we do under this heading
SIEM and Log Management
SIEM deployment, sizing and architecture design (Logsign, IBM QRadar, Wazuh and equivalents); Log source integration: …
VIEWAutomation and Response (SOAR)
24/7 monitoring and incident management.…
VIEWManaged Security Products
Managed EDR / EPP: policy management, alert analysis, quarantine decisions; Managed firewall / WAF: rule changes, vers…
VIEWReporting and Performance Indicators
Weekly operational report: alert volume, incident distribution, open actions; Monthly executive summary: risk trend, c…
VIEWThreat Hunting
Rather than waiting for alerts, we search on hypotheses: “if this technique ran here, where would the trace be?”…
VIEWHardening and Secure Configuration (CIS Benchmark)
Default configuration is not secure. Servers, network devices and databases are hardened against a baseline.…
VIEWSIEM and Log Management
- SIEM deployment, sizing and architecture design (Logsign, IBM QRadar, Wazuh and equivalents)
- Log source integration: servers, network devices, security products, applications, cloud, databases
- Log normalisation, enrichment and addition of asset/user context
- Correlation rules and development of organisation-specific use cases
- Anomaly detection with user and entity behaviour analytics (UEBA)
- Matching threat intelligence feeds with the SIEM
- Log retention, archiving and integrity protection for regulatory compliance
- False positive reduction work and a rule maintenance cycle
Automation and Response (SOAR)
24/7 monitoring and incident management.
- Incident enrichment and automated pre-analysis workflows
- Playbook development: quarantine, account lockout, IP blocking, ticket creation
- Two-way integration with ticketing and service management systems
- Bringing automated response decisions under control with approval mechanisms
- Tiered analyst structure (L1 triage, L2 analysis, L3 specialist) and shift organisation
- Real-time threat monitoring, alert triage and severity rating
- Incident lifecycle management: detection, validation, containment, eradication, recovery, lessons learned
- Escalation matrix and a direct communication channel with executives during a crisis
- Threat hunting: hypothesis-driven proactive search activity
- Engagement of the forensics team in large-scale incidents
Managed Security Products
- Managed EDR / EPP: policy management, alert analysis, quarantine decisions
- Managed firewall / WAF: rule changes, version management, health checks
- Managed PAM and IGA: account lifecycle, entitlement review campaigns
- Managed DLP: policy tuning, violation analysis, user notification workflow
- Managed vulnerability management: periodic scanning, prioritisation, closure tracking
- Managed e-mail security and phishing simulation programme
Reporting and Performance Indicators
- Weekly operational report: alert volume, incident distribution, open actions
- Monthly executive summary: risk trend, critical incidents, recommendations
- Measurement of mean time to detect (MTTD) and mean time to respond (MTTR)
- MITRE ATT&CK coverage report and tracking of detection gaps
- Preparation of evidence packages for audit and compliance processes
- Quarterly service review meetings and improvement plan
Threat Hunting
Rather than waiting for alerts, we search on hypotheses: “if this technique ran here, where would the trace be?”
- Hypothesis generation based on MITRE ATT&CK techniques
- Trace hunting across log and endpoint telemetry
- Turning findings into new detection rules
- Reporting of detection gaps
- A periodic hunting programme and scope expansion
Hardening and Secure Configuration (CIS Benchmark)
Default configuration is not secure. Servers, network devices and databases are hardened against a baseline.
- Selection of a CIS Benchmark / DISA STIG baseline
- Current-state compliance scan and deviation list
- Phased hardening with application impact testing
- Continuous monitoring of configuration drift
- Making it permanent through automation (Ansible / GPO)
- Periodic compliance report and audit evidence
On this page
Typical deliverables
- Weekly operational report
- Monthly executive summary
- Incident reports
- KPI dashboard
Let us define the scope together
A short discovery call is enough to identify the slice of this portfolio you actually need.
Request a quoteRelated services
What usually runs alongside this
Cyber Security Products and Implementation Services
Requirements analysis, PoC, architecture, deployment and handover for security products from endpoint to cloud.
EXPLORE Cyber SecurityPenetration Testing, Red Teaming and Digital Forensics
Methodology-driven penetration testing, red team operations, digital forensics and incident response.
EXPLORE Cyber SecurityOT / ICS and Industrial System Security
Passive visibility, segmentation and IEC 62443 compliance work in industrial control system environments.
EXPLOREGet started
Let us talk about your project.
The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.