24/7 SOC and NOC

Attacks do not keep office hours. Our Security Operations Center (SOC) collects logs from your systems, analyses them with SIEM and XDR tools and responds to suspicious events immediately, not the next morning. In parallel, the Network Operations Center (NOC) watches the network and servers so that an outage is fixed before users notice it. Both centres run in Slovenia, inside our company, with data that never leaves the EU. We set them up in 2024, building on a security team that has worked since 2008 (Blue team) and 2010 (Red team).

What the SOC watches and how it acts

NOC: infrastructure monitoring

Onboarding in four steps

  1. 01

    Assessment and scope

    We inventory systems, log sources and critical processes and define what the SOC must see and when to act.

  2. 02

    Connecting the sources

    We deploy agents and log forwarders and connect firewalls, Microsoft 365 and key applications.

  3. 03

    Rules and go-live

    For two to three weeks we tune the rules to remove false alarms; then we agree the escalation procedure and go to 24/7 monitoring.

  4. 04

    Reporting and improvement

    A monthly report, a quarterly review with your management and continuous addition of new sources and rules.

Frequently asked questions

What is the difference between a SOC and a NOC?

The SOC looks for attacks and security incidents: intrusions, malware, account misuse. The NOC keeps things running: availability, performance and faults of the network and servers. With us they work together, so the same event is seen from both sides.

Where is our data processed?

In Slovenia, in our SOC in Maribor and in our data centre. Logs never leave the EU and only named analysts have access to them, in line with ISO 27001.

How quickly do you respond to an incident?

An analyst responds to a critical alert immediately, 24 hours a day; first measures such as isolating a device or blocking an account are taken without waiting. Escalation to you and notifications are defined in the response plan.

Does the SOC help with NIS2 compliance?

Yes. NIS2 and the Slovenian ZInfV-1 act require incident detection, reporting within set deadlines and evidence of measures. The SOC provides this as a service, with reports you can submit to the supervisory authority.

What do we need to get started?

A list of systems and a contact person for access. We install the agents and forwarders; most clients are under monitoring within three to four weeks of signing.

Can the SOC work alongside our existing IT provider?

Yes. The SOC is a standalone service; we agree with your provider who carries out the measures after an alert. If we take over the maintenance as well, monitoring and fault resolution are in the same hands.

Let's see what your SOC needs to watch

Send us a list of systems and the number of users; within a week we prepare the monitoring scope and price.