Security Monitoring & NIS2 — from assessment to a working SOC and certification readiness

An organization under NIS2 stands up real security monitoring — a self-hosted SIEM/XDR, hardened perimeter, and an ISO 27001 / BSI ISMS — from an OSSTMM assessment to a working SOC and a trained in-house team.

Delivery with your own team

NIS2 makes security oversight a management responsibility — but the organization has no real detection: no SIEM, no audit trails, no incident path. It needs provable security monitoring and a working SOC, and it wants its own team to run it.

Building blocks

LayerWhat we deploy / do
Detection & responseSecurity & Observability Platform (SIEM/XDR)
PerimeterSovereign Edge Firewall · Abusive HTTP Watch · Certificate Authority
PeopleSecurity Officer · DPO
DisciplinesSecurity · Digital Sovereignty

The result: a working SOC the organization owns — provable control, NIS2-defensible, ISO 27001 / BSI-ready, run by a trained in-house team. → Talk to us

What each stakeholder is really asking

CEO

How exposed are we under NIS2 right now?
If you have no detection, no audit trails and no incident path, ‘we hadn’t gotten to it’ is itself a finding — and the liability sits with the board, not just IT. A working SOC turns that exposure into a defensible, provable posture. → Security
Is NIS2 really the board's problem, not IT's?
Yes — NIS2 makes cyber oversight an explicit management duty, with personal liability for senior leadership in scope. You can delegate the work, not the accountability. A named function with evidence is what discharges it. → Rent-a-Security-Officer
What does a breach actually cost us versus this?
A material breach runs into the millions in direct cost, plus reputation damage that takes years to undo. A working SOC lowers both the probability and the blast radius — and proves due care if the worst happens.

CFO

Won't a SIEM and a SOC blow the budget?
Not this way — a self-hosted Security & Observability Platform replaces per-gigabyte SaaS billing (which grows with your data) with a fixed infrastructure cost, and a fractional CISO instead of a full-time hire. Predictable, scaled to your real risk.
SaaS SIEMs bill per gigabyte — how do we avoid runaway cost?
By self-hosting: the platform is a fixed infrastructure cost, not per-gigabyte ingestion that grows with your logs. You can retain more, not less, without a bill shock.
Do we need to hire a full security team for this?
No — a fractional CISO provides the leadership, we stand up the SOC and train your existing people. You scale to a full team only if and when it is justified.

CIO

How does monitoring slot into what we run, and who operates it?
Standards-based ingestion (syslog, agents, APIs) across endpoints, servers, network and cloud — additive, no rebuild. We design the SOC roles and train your team to run it; you own the detection and the data. → Consulting
Will deploying agents and collectors disrupt production?
Minimal — lightweight agents plus standard syslog/API ingestion, rolled out estate by estate. It is additive monitoring, not a change to your running systems.
Cloud, on-prem and containers — can one system cover it all?
Yes — detection spans endpoints, servers, network, cloud workloads and containers in one searchable index, so you get one pane instead of five disconnected tools. → Security & Observability Platform

CISO

Will this actually make control provable, or just look busy?
Provable is the whole point: a measurable OSSTMM baseline, SIEM/XDR detection, retained searchable evidence and a tested incident path, under an ISO 27001 / BSI ISMS — certification-ready and audit-defensible. The function you are accountable for, with the evidence to back it.
How fast will we actually detect something?
Real-time — rule- and signature-based with MITRE ATT&CK mapping plus behavioural anomalies, alerting into your incident path. The OSSTMM baseline tells you, honestly, what you can and cannot yet see. → Security
Will this get us through an ISO 27001 / NIS2 audit?
It is built for it: documented controls, retained searchable evidence and a tested incident path under an ISO 27001/BSI ISMS — certification-ready, and the evidence is there when the auditor asks.

Project lead

What is the delivery plan and timeline?
Phased: OSSTMM assessment → monitoring stood up → perimeter hardened → ISMS → SOC handover (the steps below). Burndown/Gantt, a milestone per phase, and first detections live early — visible risk reduction in weeks.
When do we get the first real detection?
Early — monitoring stands up in the first build phase (see the Gantt), so you have live detections and dashboards before the ISMS paperwork is finished. Risk drops from the start, not at the end.
How do we phase this without boiling the ocean?
Assess → stand up monitoring → harden the perimeter → ISMS → SOC handover. Each phase is a milestone with its own value; you do not wait for the whole programme to benefit.

In-house architect

We run our own infrastructure — will this fit it, or fight it?
It fits: self-hosted on your infrastructure, open and tool-neutral, feeding from your existing systems rather than replacing them. We integrate with your architecture and hand it over documented. → Rent-an-Enterprise-Architect
Is this another agent and console we can't see inside?
No — it is open-source-based and self-hosted, and the data and dashboards are yours. You can inspect rules, queries and retention and tune them. No black box, no per-seat analytics licence. → Security & Observability Platform
Who owns the detection content and tuning long-term?
You do — we design the SOC, write the initial rules and train your team to own and tune them. The detection logic is yours to read and change. → Rent-an-Enterprise-Architect

How it runs, end to end

flowchart LR
    A["Idea: NIS2 is a board duty"] --> B["Measure it (OSSTMM)"]
    B --> C["Build monitoring (SIEM/XDR)"]
    C --> D["Harden the perimeter"]
    D --> E["Operate under an ISMS"]
    E --> F["Handover: your SOC, your team"]
  • The idea — NIS2 is a board duty

    Under NIS2, insufficient cyber governance is a management liability — and ‘we hadn’t gotten to it’ is itself a finding. The organization needs real detection and a defensible posture. See Security.
  • Measure it (OSSTMM)

    A fractional Security Officer runs a measurable OSSTMM assessment — what is exposed, what is controlled, what is a real gap — producing a baseline to track, not a checklist. A DPO covers the GDPR overlap.
  • Build the monitoring (SIEM/XDR)

    The self-hosted Security & Observability Platform goes in: detection across endpoints, servers, network and cloud, with alerting, audit trails and dashboards the organization owns — no per-gigabyte SaaS.
  • Harden the perimeter

    A Sovereign Edge Firewall (default-deny, segmented), Abusive HTTP Watch on the web edge, and an internal Certificate Authority close the obvious doors.
  • Operate under an ISMS

    A lean ISO 27001 / BSI Grundschutz ISMS turns the monitoring into governance: documented controls, retained evidence, a tested incident path — certification-ready if a tender or customer needs it.
  • Handover — your SOC, your team

    We design the roles, train the security team and hand over the running SOC. The organization can prove control to auditors, insurers and regulators — on its own. See Consulting.

Indicative phasing (not a commitment)

gantt
    dateFormat YYYY-MM-DD
    axisFormat %b
    section Assess
    OSSTMM assessment   :a1, 2026-01-05, 2w
    section Build
    SIEM and XDR        :a2, after a1, 5w
    Harden perimeter    :a3, after a2, 3w
    section Operate
    ISMS                :a4, after a3, 4w
    SOC handover        :a5, after a4, 3w