What is included
- Telemetry onboarding. Endpoint detection and response, identity provider sign-in and audit logs, Microsoft 365 / Google Workspace, cloud control plane (Azure, AWS, GCP), email security, firewalls and VPN. We tell you which sources give the best coverage per euro and start there.
- Detection engineering. A catalogue of detections mapped to MITRE ATT&CK, tuned to your environment. New detections are added from threat intelligence relevant to your sector and geography, and from what testing engagements teach us about your estate.
- Human triage. Analysts review escalated alerts, gather context and decide. You receive cases with evidence, not raw alerts.
- Response. Containment actions per your written runbooks and authorisation, from account disablement and endpoint isolation to coordination with your IT provider, plus incident communication support in English, Italian or Romanian.
- Reporting. Regular service reports and incident reports designed to support your NIS2/DORA notification process and insurer requests; regulators and your counsel determine sufficiency, and notification remains your responsibility.
Coverage model
The layers are separate and named in the contract: automated collection and detection run continuously; staffed human triage is provided by our in-house analysts during working hours and, where contracted, by a partner security operations centre outside them; escalation goes to named GlabIT engineers; response actions on your systems follow written runbooks and your authorisation. Round-the-clock coverage is therefore available under a contracted coverage model; we do not present it as an unconditional standing fact. Response times per severity are agreed per engagement and written into the contract — we do not publish a single number here because the right one depends on your estate and what you allow us to do without asking. Partner identity, location and data-processing terms are disclosed in the service agreement and data processing agreement.
Stack
Our core detection platform is Wazuh (SIEM/XDR: log collection, file-integrity monitoring, vulnerability detection, endpoint agents), complemented by detection content and tooling we build ourselves for the sources and scenarios Wazuh does not cover out of the box. Where you already run an EDR or a cloud-native SIEM, we integrate rather than replace.
Where the SOC fits
Monitoring is the operate stage. Companies usually arrive here after an assessment or penetration test has shown what needs watching, and combine it with CaaS for the day-to-day security work that stops incidents happening in the first place.