Skip to content
GlabIT
GlabIT

Monitoring · detection · response

SOC and managed detection

SOC services in Romania for endpoints, identity, cloud and networks: monitoring, detection, triage and response, with coverage and authority set by contract.

In one sentence

Monitoring of your endpoints, identities, cloud and network with detections mapped to MITRE ATT&CK, human triage of escalated alerts, and a response path agreed before the first incident — with round-the-clock coverage available under a contracted coverage model.

Who it is for

  • Organisations that need to evidence monitoring and incident-handling capability (NIS2, DORA, ISO/IEC 27001, cyber insurance)
  • Companies with logs and an EDR licence, but nobody watching them at 03:00
  • IT teams who get alerts and want a second pair of eyes to say "this one matters, this one does not"
  • Groups spread across Italy, Romania and elsewhere who need incident communication in more than one language

What is included

  • Telemetry onboarding. Endpoint detection and response, identity provider sign-in and audit logs, Microsoft 365 / Google Workspace, cloud control plane (Azure, AWS, GCP), email security, firewalls and VPN. We tell you which sources give the best coverage per euro and start there.
  • Detection engineering. A catalogue of detections mapped to MITRE ATT&CK, tuned to your environment. New detections are added from threat intelligence relevant to your sector and geography, and from what testing engagements teach us about your estate.
  • Human triage. Analysts review escalated alerts, gather context and decide. You receive cases with evidence, not raw alerts.
  • Response. Containment actions per your written runbooks and authorisation, from account disablement and endpoint isolation to coordination with your IT provider, plus incident communication support in English, Italian or Romanian.
  • Reporting. Regular service reports and incident reports designed to support your NIS2/DORA notification process and insurer requests; regulators and your counsel determine sufficiency, and notification remains your responsibility.

Coverage model

The layers are separate and named in the contract: automated collection and detection run continuously; staffed human triage is provided by our in-house analysts during working hours and, where contracted, by a partner security operations centre outside them; escalation goes to named GlabIT engineers; response actions on your systems follow written runbooks and your authorisation. Round-the-clock coverage is therefore available under a contracted coverage model; we do not present it as an unconditional standing fact. Response times per severity are agreed per engagement and written into the contract — we do not publish a single number here because the right one depends on your estate and what you allow us to do without asking. Partner identity, location and data-processing terms are disclosed in the service agreement and data processing agreement.

Stack

Our core detection platform is Wazuh (SIEM/XDR: log collection, file-integrity monitoring, vulnerability detection, endpoint agents), complemented by detection content and tooling we build ourselves for the sources and scenarios Wazuh does not cover out of the box. Where you already run an EDR or a cloud-native SIEM, we integrate rather than replace.

Where the SOC fits

Monitoring is the operate stage. Companies usually arrive here after an assessment or penetration test has shown what needs watching, and combine it with CaaS for the day-to-day security work that stops incidents happening in the first place.

Deliverables

What you receive

  • Onboarded telemetry

    Endpoints, identity provider, cloud audit logs, email security and network edge connected, tuned and verified end-to-end — with a coverage map of what we can and cannot see.

  • Detection catalogue

    The rules and analytics we run for you, each mapped to MITRE ATT&CK techniques, with the coverage gaps written down rather than hidden.

  • Alert triage and case notes

    Every escalated alert comes with what happened, the evidence, what we did and what we recommend. No "please investigate" tickets.

  • Incident reports

    A timeline, root cause, impact, containment actions and follow-ups within an agreed number of days of closure — designed to support your regulatory and insurer processes (sufficiency is for them to judge).

  • Service report

    At the contracted cadence — alert volumes, escalations, mean time to detect and respond as we measure them, tuning changes and coverage improvements.

  • Runbooks

    Agreed response actions for the common scenarios — compromised account, ransomware precursor, data exfiltration signal — rehearsed with your team.

Engagement model

How it runs

Model
Subscription per monitored estate; the coverage model (automated collection, staffed triage windows, escalation, response authority) and response times are written into the contract.
Typical timeline
Onboarding and tuning depend on the sources and the size of the estate and are set in the proposal; monitoring then runs per the contracted coverage.
  1. 01

    Scope

    Which sources, which crown jewels, who we call, in what language, and what we are allowed to do without asking first.

  2. 02

    Onboard and tune

    Connect telemetry, baseline normal, kill noise. We do not go live on your incidents until the false-positive rate is acceptable to both of us.

  3. 03

    Monitor and respond

    Coverage per the contracted model. Escalations to named contacts, containment per written runbook and client authorisation, incident reports after.

  4. 04

    Improve

    Regular tuning and periodic coverage reviews against ATT&CK. New sources and detections as your estate changes.

FAQ

Questions a sceptical CISO asks

Is it really round-the-clock? Who is watching at night?

Round-the-clock coverage is available under a contracted coverage model, not assumed. Automated collection and alerting run continuously; staffed triage outside our working hours is delivered together with a partner security operations centre; escalation, response decisions and communication with you stay with GlabIT engineers. The exact staffed windows, partner involvement, escalation path and response times per severity are written into your contract — that is the source of truth, not this page.

Which tools do you use?

Wazuh is our core platform, extended with our own detection content and tooling. Where you already own an EDR or SIEM licence, we usually build on it rather than replace it.

Do you take action on our systems, or only tell us?

Both are possible, and the line is agreed in advance. Typical arrangement — we isolate an endpoint or disable an account for defined scenarios without waiting; anything wider needs your named contact to approve.

How do you measure detection coverage?

Every detection is mapped to MITRE ATT&CK techniques and we show you the matrix, including the gaps. Where agreed, coverage is validated with purple-team exercises so the map reflects what actually fires, not what a vendor sheet says.

We are small. Is a SOC overkill?

For most companies under about 100 people, CaaS with sensible logging and an incident retainer is the better first step. We will say so if that is your case.

Know when it happens, not when it hits the news

We scope monitoring around what actually matters in your estate and tell you plainly what coverage you would get. Start with a call.