§ 01Overview
Threat Detection & Response
Detection systems are built by engineers with offensive experience, and incident response is led by senior responders. Detection is tuned to your environment and the threats targeting your industry.
§ 02What's included
What the service covers.
Engage any item on its own, or combine them into a single engagement.
01
Managed detection and response (MDR)
Continuous monitoring with detections tuned to your environment and the threats relevant to your industry.
02
Incident response retainer
Pre-agreed terms and a guaranteed response window, defined before an incident occurs.
03
Digital forensics (DFIR)
Forensic investigation that establishes what happened, the extent of the damage, and what steps to take.
04
Compromise assessment
A targeted review of the environment to establish whether there are signs of active or past compromise.
05
Threat hunting
Proactive, hypothesis-driven hunting for threats that have bypassed automated detection.
06
Detection engineering
We build and tune detection rules and hand them over documented, in a form your team can maintain.
07
Threat intelligence
Intelligence on the actors and techniques targeting your industry, fed directly into your detection rules.
§ 03How we approach it
A clear methodology, every time.
1
Onboarding and baseline
We connect your telemetry and establish what normal looks like in your environment.
2
Detection and triage
High-fidelity rules and analyst-led triage, so alerts stay relevant.
3
Response and containment
When an incident is confirmed, we contain the attack, investigate, and lead the recovery.
4
Analysis and improvement
After every incident we update the detections and recommend measures that reduce the likelihood of recurrence.
Independent and vendor-neutral. We don't resell the tools we test.
Our only product is expertise and evidence, so our advice has no agenda but yours.
Independent
Vendor-neutral. No licences to sell, no conflicts of interest.
Senior-led
Every engagement is run by senior engineers, not handed to a queue.
Evidence-led
Reproducible findings and documented proof, not severity labels.
Regulator-ready
Built to satisfy NIS2, DORA, ISO 27001, and GDPR by design.
FAQ
Questions, answered
What is detection engineering?
Building and tuning detection rules adapted to your environment and the real threats targeting it, while removing rules that generate large volumes of false positives. Such alerts erode the team's trust in the system and slow the response to real incidents.
Do we keep the detections you build?
Yes. All rules are documented and handed over to you, in a form your team can review and continue to maintain.
Who leads the response when an incident happens?
A senior incident responder, with a contracted response time. After every incident we update the detections and recommend improvements.
Do you replace our SOC or work with it?
Both models are possible. We can build detection and response from the ground up or strengthen the capability your team already operates.