Cyber Security

Managed Security Services (MSSP / SOC)

ONGSEC takes on uninterrupted 24/7 cyber security monitoring for your organisation. With our own SOC infrastructure and SIEM solutions we detect, analyse and respond to threats in real time. The service can be structured as fully …

SIEMSOAR24/7 monitoringUse-case developmentKPI dashboard
01

SIEM and Log Management

  • SIEM deployment, sizing and architecture design (Logsign, IBM QRadar, Wazuh and equivalents)
  • Log source integration: servers, network devices, security products, applications, cloud, databases
  • Log normalisation, enrichment and addition of asset/user context
  • Correlation rules and development of organisation-specific use cases
  • Anomaly detection with user and entity behaviour analytics (UEBA)
  • Matching threat intelligence feeds with the SIEM
  • Log retention, archiving and integrity protection for regulatory compliance
  • False positive reduction work and a rule maintenance cycle
02

Automation and Response (SOAR)

24/7 monitoring and incident management.

  • Incident enrichment and automated pre-analysis workflows
  • Playbook development: quarantine, account lockout, IP blocking, ticket creation
  • Two-way integration with ticketing and service management systems
  • Bringing automated response decisions under control with approval mechanisms
  • Tiered analyst structure (L1 triage, L2 analysis, L3 specialist) and shift organisation
  • Real-time threat monitoring, alert triage and severity rating
  • Incident lifecycle management: detection, validation, containment, eradication, recovery, lessons learned
  • Escalation matrix and a direct communication channel with executives during a crisis
  • Threat hunting: hypothesis-driven proactive search activity
  • Engagement of the forensics team in large-scale incidents
03

Managed Security Products

  • Managed EDR / EPP: policy management, alert analysis, quarantine decisions
  • Managed firewall / WAF: rule changes, version management, health checks
  • Managed PAM and IGA: account lifecycle, entitlement review campaigns
  • Managed DLP: policy tuning, violation analysis, user notification workflow
  • Managed vulnerability management: periodic scanning, prioritisation, closure tracking
  • Managed e-mail security and phishing simulation programme
04

Reporting and Performance Indicators

  • Weekly operational report: alert volume, incident distribution, open actions
  • Monthly executive summary: risk trend, critical incidents, recommendations
  • Measurement of mean time to detect (MTTD) and mean time to respond (MTTR)
  • MITRE ATT&CK coverage report and tracking of detection gaps
  • Preparation of evidence packages for audit and compliance processes
  • Quarterly service review meetings and improvement plan
05

Threat Hunting

Rather than waiting for alerts, we search on hypotheses: “if this technique ran here, where would the trace be?”

  • Hypothesis generation based on MITRE ATT&CK techniques
  • Trace hunting across log and endpoint telemetry
  • Turning findings into new detection rules
  • Reporting of detection gaps
  • A periodic hunting programme and scope expansion
06

Hardening and Secure Configuration (CIS Benchmark)

Default configuration is not secure. Servers, network devices and databases are hardened against a baseline.

  • Selection of a CIS Benchmark / DISA STIG baseline
  • Current-state compliance scan and deviation list
  • Phased hardening with application impact testing
  • Continuous monitoring of configuration drift
  • Making it permanent through automation (Ansible / GPO)
  • Periodic compliance report and audit evidence

Typical deliverables

  • Weekly operational report
  • Monthly executive summary
  • Incident reports
  • KPI dashboard

Let us define the scope together

A short discovery call is enough to identify the slice of this portfolio you actually need.

Request a quote

Get started

Let us talk about your project.

The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.

Fill in the enquiry form

WhatsApp