CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

SOCaaS

Security Operations Center

Tools do not stop attacks. People watching tools stop attacks. Our analysts watch your estate around the clock from our own operations centre, and the alert that matters reaches a human within minutes rather than sitting in a queue until Monday.

Why an outsourced SOC

Running a security operations centre in-house means three shifts, a SIEM, a threat-intelligence subscription and analysts who leave for better offers. For every organisation in Slovenia short of a bank, the numbers do not work. What does work is buying the watch and keeping the decisions: we see the estate, you keep control of it.

What you get

  • Continuous collection and correlation across endpoints, servers, network and identity
  • Honeypots placed inside your network, so an intruder trips something that has no business being touched
  • Named analysts who learn your estate, not a rotating queue
  • Escalation you agreed in advance, with someone reachable at three in the morning
  • Monthly reporting written for a board, and the evidence log an auditor asks for

HOW IT WORKS

From first call to steady state

  1. Analysis of your stack

    We look at what you already own before selling you anything. Most estates have more capability switched off than switched on.

  2. Onboarding plan

    A dated plan showing what is connected in which week, so nobody is surprised and nothing is half-monitored for a month.

  3. Baselining

    The system learns what normal looks like in your organisation specifically. Generic thresholds are why most alerting is ignored.

  4. Threat hunting

    Before monitoring begins we go looking for what is already there. It is not unusual to find it.

  5. Monitoring and response

    Watching users, data, endpoints and servers, and stopping the incident at the stage where stopping it is still cheap.

WHAT THIS ANSWERS

The obligations this covers

This is not a marketing claim. Each of these regimes names the requirement that this service is the answer to, and the page behind it says which clause.

Who this is for. Organisations with more than about fifty staff, anyone designated an essential or important entity, and anyone who has already had a scare.

THE REGION, COUNTED

Slovenia's ransomware figure is the one nobody had to report

Serbia has required every operator of a critical ICT system to file a return on every incident since 2020. In Slovenia the equivalent duty reached roughly a thousand organisations only on 19 June 2025. Put the two ransomware counts beside each other and the gap is not the attack rate — it is who was obliged to count.

SLOVENIA · 2025 29 ransomware incidents recorded in the entire country — every sector, every reporter, the national total.
SERBIA · 2025 48 ransomware incidents from the designated critical operators alone — organisations that have had to file a return on every incident since 2020.

A few hundred obliged Serbian operators found 1.7× more ransomware than the whole of Slovenia recorded. And across the second half of 2025, nine sectors covered by ZInfV-1 — drinking water, waste water, postal, waste, chemicals, manufacturing, digital providers, space and managed ICT — recorded zero incidents between them. That is not a quiet half-year. It is a half-year nobody was counting. ENISA names under-reporting as one reason the impact of ransomware is documented in so few cases across the EU, and since 19 June 2025 not counting is no longer an option: the incident you never recorded is still the one you answer for.

  • 21.5% of EU enterprises suffered consequences from an ICT security incident in a single year.
  • 81.1% of cybercrime incidents against EU organisations in ENISA's latest threat landscape were ransomware.
  • 328.9 M port scans against Serbia's critical operators in 2025 — three times the 2024 figure.
  • −71% fall in ransomware that got through those operators, 168 to 48, while attack volume tripled. That is what being watched buys.

THE COUNTER-ARGUMENT

“Slovenia has one of the lowest incident rates in the EU.”

It does, on paper. Eurostat puts Slovenian enterprises at 11.6% reporting consequences from an ICT security incident against an EU average of 21.5% — second-lowest of the twenty-seven, behind only Austria.

In the same window SI-CERT handled 6,196 incidents against 4,587 the year before — a 35% rise — and nine ZInfV-1 sectors recorded none at all. A survey measures what a company noticed and chose to say. A response centre measures what somebody actually had to work on. When the two disagree by that margin the difference is not the threat. It is the visibility, and visibility is the part you can buy.

None of this is abstract. Ransomware took down the passenger information system at Split Airport, halting take-offs and landings until every flight was suspended. In November 2023 it reached Holding Slovenske elektrarne, which generates about 60% of Slovenia's electricity. Sources: URSIV / SI-CERT, Nacionalni CERT RS, ENISA Threat Landscape 2025, Eurostat, HSE.

Start with a conversation, not a quote

Tell us what you run and what you are being asked to prove. We will say what this would involve at your size, and whether you need it at all.

Get in touch +386 51 249 533