SOCaaS
Security Operations Center
Tools do not stop attacks. People watching tools stop attacks. Our analysts watch your estate around the clock from our own operations centre, and the alert that matters reaches a human within minutes rather than sitting in a queue until Monday.
Why an outsourced SOC
Running a security operations centre in-house means three shifts, a SIEM, a threat-intelligence subscription and analysts who leave for better offers. For every organisation in Slovenia short of a bank, the numbers do not work. What does work is buying the watch and keeping the decisions: we see the estate, you keep control of it.
What you get
- Continuous collection and correlation across endpoints, servers, network and identity
- Honeypots placed inside your network, so an intruder trips something that has no business being touched
- Named analysts who learn your estate, not a rotating queue
- Escalation you agreed in advance, with someone reachable at three in the morning
- Monthly reporting written for a board, and the evidence log an auditor asks for
HOW IT WORKS
From first call to steady state
-
Analysis of your stack
We look at what you already own before selling you anything. Most estates have more capability switched off than switched on.
-
Onboarding plan
A dated plan showing what is connected in which week, so nobody is surprised and nothing is half-monitored for a month.
-
Baselining
The system learns what normal looks like in your organisation specifically. Generic thresholds are why most alerting is ignored.
-
Threat hunting
Before monitoring begins we go looking for what is already there. It is not unusual to find it.
-
Monitoring and response
Watching users, data, endpoints and servers, and stopping the incident at the stage where stopping it is still cheap.
WHAT THIS ANSWERS
The obligations this covers
This is not a marketing claim. Each of these regimes names the requirement that this service is the answer to, and the page behind it says which clause.
Who this is for. Organisations with more than about fifty staff, anyone designated an essential or important entity, and anyone who has already had a scare.
THE REGION, COUNTED
Slovenia's ransomware figure is the one nobody had to report
Serbia has required every operator of a critical ICT system to file a return on every incident since 2020. In Slovenia the equivalent duty reached roughly a thousand organisations only on 19 June 2025. Put the two ransomware counts beside each other and the gap is not the attack rate — it is who was obliged to count.
A few hundred obliged Serbian operators found 1.7× more ransomware than the whole of Slovenia recorded. And across the second half of 2025, nine sectors covered by ZInfV-1 — drinking water, waste water, postal, waste, chemicals, manufacturing, digital providers, space and managed ICT — recorded zero incidents between them. That is not a quiet half-year. It is a half-year nobody was counting. ENISA names under-reporting as one reason the impact of ransomware is documented in so few cases across the EU, and since 19 June 2025 not counting is no longer an option: the incident you never recorded is still the one you answer for.
- 21.5% of EU enterprises suffered consequences from an ICT security incident in a single year.
- 81.1% of cybercrime incidents against EU organisations in ENISA's latest threat landscape were ransomware.
- 328.9 M port scans against Serbia's critical operators in 2025 — three times the 2024 figure.
- −71% fall in ransomware that got through those operators, 168 to 48, while attack volume tripled. That is what being watched buys.
THE COUNTER-ARGUMENT
“Slovenia has one of the lowest incident rates in the EU.”
It does, on paper. Eurostat puts Slovenian enterprises at 11.6% reporting consequences from an ICT security incident against an EU average of 21.5% — second-lowest of the twenty-seven, behind only Austria.
In the same window SI-CERT handled 6,196 incidents against 4,587 the year before — a 35% rise — and nine ZInfV-1 sectors recorded none at all. A survey measures what a company noticed and chose to say. A response centre measures what somebody actually had to work on. When the two disagree by that margin the difference is not the threat. It is the visibility, and visibility is the part you can buy.
None of this is abstract. Ransomware took down the passenger information system at Split Airport, halting take-offs and landings until every flight was suspended. In November 2023 it reached Holding Slovenske elektrarne, which generates about 60% of Slovenia's electricity. Sources: URSIV / SI-CERT, Nacionalni CERT RS, ENISA Threat Landscape 2025, Eurostat, HSE.
THE REST OF IT
Delivered by the same team
Start with a conversation, not a quote
Tell us what you run and what you are being asked to prove. We will say what this would involve at your size, and whether you need it at all.