NIS2 makes security oversight a management responsibility — but the organization has no real detection: no SIEM, no audit trails, no incident path. It needs provable security monitoring and a working SOC, and it wants its own team to run it.
Building blocks
The result: a working SOC the organization owns — provable control, NIS2-defensible, ISO 27001 / BSI-ready, run by a trained in-house team. →
Talk to us
What each stakeholder is really asking
CEO
How exposed are we under NIS2 right now?
If you have no detection, no audit trails and no incident path, ‘we hadn’t gotten to it’ is itself a finding — and the liability sits with the board, not just IT. A working SOC turns that exposure into a defensible, provable posture. →
SecurityIs NIS2 really the board's problem, not IT's?
Yes — NIS2 makes cyber oversight an explicit management duty, with personal liability for senior leadership in scope. You can delegate the work, not the accountability. A named function with evidence is what discharges it. →
Rent-a-Security-OfficerWhat does a breach actually cost us versus this?
A material breach runs into the millions in direct cost, plus reputation damage that takes years to undo. A working SOC lowers both the probability and the blast radius — and proves due care if the worst happens.
CFO
Won't a SIEM and a SOC blow the budget?
Not this way — a self-hosted
Security & Observability Platform replaces per-gigabyte SaaS billing (which grows with your data) with a fixed infrastructure cost, and a fractional CISO instead of a full-time hire. Predictable, scaled to your real risk.
SaaS SIEMs bill per gigabyte — how do we avoid runaway cost?
By self-hosting: the platform is a fixed infrastructure cost, not per-gigabyte ingestion that grows with your logs. You can retain more, not less, without a bill shock.
Do we need to hire a full security team for this?
No — a fractional
CISO provides the leadership, we stand up the SOC and train your existing people. You scale to a full team only if and when it is justified.
CIO
How does monitoring slot into what we run, and who operates it?
Standards-based ingestion (syslog, agents, APIs) across endpoints, servers, network and cloud — additive, no rebuild. We design the SOC roles and train your team to run it; you own the detection and the data. →
ConsultingWill deploying agents and collectors disrupt production?
Minimal — lightweight agents plus standard syslog/API ingestion, rolled out estate by estate. It is additive monitoring, not a change to your running systems.
Cloud, on-prem and containers — can one system cover it all?
Yes — detection spans endpoints, servers, network, cloud workloads and containers in one searchable index, so you get one pane instead of five disconnected tools. →
Security & Observability PlatformCISO
Will this actually make control provable, or just look busy?
Provable is the whole point: a measurable
OSSTMM baseline, SIEM/XDR detection, retained searchable evidence and a tested incident path, under an ISO 27001 / BSI ISMS — certification-ready and audit-defensible. The function you are accountable for, with the evidence to back it.
How fast will we actually detect something?
Real-time — rule- and signature-based with MITRE ATT&CK mapping plus behavioural anomalies, alerting into your incident path. The OSSTMM baseline tells you, honestly, what you can and cannot yet see. →
SecurityWill this get us through an ISO 27001 / NIS2 audit?
It is built for it: documented controls, retained searchable evidence and a tested incident path under an ISO 27001/BSI ISMS — certification-ready, and the evidence is there when the auditor asks.
Project lead
What is the delivery plan and timeline?
Phased: OSSTMM assessment → monitoring stood up → perimeter hardened → ISMS → SOC handover (the steps below). Burndown/Gantt, a milestone per phase, and first detections live early — visible risk reduction in weeks.
When do we get the first real detection?
Early — monitoring stands up in the first build phase (see the Gantt), so you have live detections and dashboards before the ISMS paperwork is finished. Risk drops from the start, not at the end.
How do we phase this without boiling the ocean?
Assess → stand up monitoring → harden the perimeter → ISMS → SOC handover. Each phase is a milestone with its own value; you do not wait for the whole programme to benefit.
In-house architect
We run our own infrastructure — will this fit it, or fight it?
It fits: self-hosted on your infrastructure, open and tool-neutral, feeding from your existing systems rather than replacing them. We integrate with your architecture and hand it over documented. →
Rent-an-Enterprise-ArchitectIs this another agent and console we can't see inside?
No — it is open-source-based and self-hosted, and the data and dashboards are yours. You can inspect rules, queries and retention and tune them. No black box, no per-seat analytics licence. →
Security & Observability PlatformWho owns the detection content and tuning long-term?
You do — we design the SOC, write the initial rules and train your team to own and tune them. The detection logic is yours to read and change. →
Rent-an-Enterprise-ArchitectHow it runs, end to end
flowchart LR
A["Idea: NIS2 is a board duty"] --> B["Measure it (OSSTMM)"]
B --> C["Build monitoring (SIEM/XDR)"]
C --> D["Harden the perimeter"]
D --> E["Operate under an ISMS"]
E --> F["Handover: your SOC, your team"]Indicative phasing (not a commitment)
gantt
dateFormat YYYY-MM-DD
axisFormat %b
section Assess
OSSTMM assessment :a1, 2026-01-05, 2w
section Build
SIEM and XDR :a2, after a1, 5w
Harden perimeter :a3, after a2, 3w
section Operate
ISMS :a4, after a3, 4w
SOC handover :a5, after a4, 3w