Skip to content

Cyber Security

Seeing it, deciding fast, containing it

Telemetry, detection engineering, triage and response - plus the unglamorous operational hygiene that decides whether an intrusion becomes an incident. Built around a data pipeline you control, so coverage and cost are engineering decisions rather than licence accidents.

What we deliver

Services in this focus area

Every engagement is scoped to your environment - deploy a single capability or the full stack.

  1. 01

    SOC Design, Build & Operating Model

    On-PremCloudHybridAdviseBuild

    A detection and response function sized to your risk, your telemetry and your headcount reality.

    • Operating model, tiering, shift and escalation design
    • Telemetry strategy, platform architecture and integration map
    • Runbooks, quality metrics and maturity roadmap
  2. 02

    SIEM Engineering & Data Pipeline

    On-PremCloudHybridBuild

    A platform that ingests what matters, at a cost you modelled before signing.

    • Log source onboarding, parsing and normalisation to a common schema
    • Detection content engineering and use-case backlog management
    • Tiered routing to hot, warm and archive storage with replay capability
  3. 03

    Managed Detection & Response

    On-PremCloudHybridRun

    Round-the-clock analysis with contracted containment authority, not alert forwarding.

    • 24×7 monitoring, triage and investigation to agreed service levels
    • Pre-authorised containment actions with documented decision rights
    • Monthly threat review, coverage reporting and tuning cycle
  4. 04

    Security Automation & Response Orchestration

    On-PremCloudHybridBuildRun

    Automate the repetitive majority of triage so analysts spend their time on the cases that need judgement.

    • Playbook design for the highest-volume alert classes
    • Bidirectional integration across ticketing, identity, endpoint and cloud
    • Human-in-the-loop approval gates on destructive or wide-blast actions
  5. 05

    EDR / XDR Deployment & Management

    On-PremCloudHybridBuildRun

    Endpoint telemetry and containment that reaches every host, including the ones nobody inventoried.

    • Rollout, policy tuning and coverage assurance against the asset inventory
    • Custom detection authoring and exclusion governance
    • Ongoing management with isolation and remediation response
  6. 06

    Detection Engineering & Detection-as-Code

    On-PremCloudHybridBuildRun

    Detections written, reviewed, tested and versioned like software.

    • Detection-as-code repository with peer review and CI validation
    • Coverage mapping against adversary technique matrices
    • False-positive budgeting, tuning cadence and detection retirement
  7. 07

    Cyber Threat Intelligence & Threat Hunting

    On-PremCloudHybridAdviseRun

    Structured search for the intrusion that has not alerted yet, driven by what actually targets your sector.

    • Intelligence requirements, source curation and structured feed integration
    • Hypothesis-driven hunts on a fixed cadence with documented outcomes
    • New detections and telemetry gaps produced from every hunt
  8. 08

    Incident Response Retainer & Readiness

    On-PremCloudHybridAdviseRun

    A named team, contracted response times, and a plan that has already been rehearsed.

    • Pre-agreed service levels, escalation paths and authority matrix
    • Playbooks, communication templates and executive tabletop exercises
    • Drawdown hours usable for proactive readiness work
  9. 09

    Digital Forensics & Breach Investigation

    On-PremCloudHybridAdvise

    Establish what happened, what left, and what must be reported - to an evidentiary standard.

    • Forensically sound acquisition with chain of custody
    • Root cause, scope, persistence and data-impact determination
    • Reporting suitable for regulators, insurers and litigation
  10. 10

    Vulnerability Remediation & Patch Operations

    On-PremCloudHybridRun

    The control that prevents most incidents, run as a service with a measured SLA.

    • Patch rings, maintenance windows, testing and rollback procedure
    • Third-party application, firmware and appliance coverage
    • Compliance reporting against the agreed remediation SLA
  11. 11

    Insider Risk & User Behaviour Analytics

    On-PremCloudHybridBuildRun

    Detect the misuse that looks like ordinary work until it is baselined.

    • Behavioural baselining with peer-group and role-based scoring
    • Departing-employee, data-staging and mass-access monitoring
    • Investigation process governed jointly with HR and legal
  12. 12

    Deception Engineering & Honeytokens

    On-PremCloudHybridBuild

    Near-zero-false-positive signals from assets and credentials no legitimate user should ever touch.

    • Decoy host, service, credential and document placement
    • Honeytoken seeding across directories, code, cloud and databases
    • Alert integration and periodic refresh to preserve credibility

Technical deep dive

Rebuilding detection around a pipeline you own

Applies to any security operation whose platform bill grows faster than its detection coverage - the near-universal outcome of routing all telemetry into one licensed tier.

What this is

A telemetry pipeline in front of the analytics platform. Events are collected once, normalised to a common schema at the edge, then routed by value: high-signal data into the real-time detection tier, bulk data into cheap searchable storage, everything into archive with replay. Detections are written, reviewed and tested as code against that schema.

The problem being solved

Ingest has tripled in two years, driven by verbose cloud audit logs and endpoint telemetry. The licence is now the second-largest line in the security budget, and the response has been to stop onboarding sources - so coverage is shrinking while cost grows. Detection content is a few hundred rules edited directly in the console, with no version history, no test coverage and no owner; nobody can say which adversary techniques are covered, and roughly a third of the alert volume comes from a handful of rules everybody has learned to close without reading.

Why it is hard

  • Cost is coupled to coverage. As long as every event must enter the licensed tier to be searchable, every new source is a budget conversation rather than an engineering one.
  • Console-edited rules cannot be reviewed, tested or rolled back, so nobody dares delete a noisy one in case something depends on it.
  • Alert volume is not the same as coverage. High volume from a few rules coexists comfortably with entire technique families having no detection at all.

Reference architecture - step through it

all
SOURCESPIPELINESTORAGE TIERSDETECT & RESPONDEndpoint telemetryprocess, network, fileCloud audit logscontrol plane, data planeIdentity logssign-in, token, directoryNetwork & app logsflow, DNS, proxy, WAFCollection layeragents, APIs, streamsNormalisationcommon schema, enrichmentRouting & reductionvalue-based, per event classDetection CIlint, unit test, deployReal-time tiercorrelation and alertingSearchable tierinvestigation, 90 daysArchivecheap, replayableDetection repositoryversioned, peer-reviewedTriage queueenriched, deduplicatedThreat huntinghypothesis over warm tierAutomated responsegated containmentCoverage maptechnique-level, measureddeployed rulesnew detectionsreplay on demand
A detection as a reviewed, tested, technique-mapped artefactyaml
id: DET-0421
title: Cloud role assumed from an unusual network after token replay
owner: detection-engineering
status: production
technique: [T1550.001, T1078.004]      # coverage is computable from this
data_sources: [cloud_audit, identity_signin]
schema_version: 3

logic:                                  # written against the common schema,
  window: 30m                           # not against one platform's fields
  sequence:
    - event: identity.token.issued
      where: auth_method != "phishing_resistant"
    - event: cloud.role.assumed
      where: |
        principal == prior.principal
        and asn(source.ip) != asn(prior.source.ip)
        and role.privilege_tier <= 1
  emit:
    severity: high
    entities: [principal, role, source.ip]

tests:                                  # CI refuses to deploy without these
  - name: replay_from_hosting_provider
    fixture: fixtures/aitm_replay.jsonl
    expect: alert
  - name: legitimate_travel_same_asn
    fixture: fixtures/roaming_user.jsonl
    expect: no_alert
  - name: service_principal_normal
    fixture: fixtures/ci_pipeline_assume.jsonl
    expect: no_alert

false_positive_budget:
  expected_per_week: 3
  breach_action: ticket_to_owner        # not "analysts absorb it"

response:
  playbook: PB-IDENT-CONTAIN
  auto_actions: [revoke_session, revoke_refresh_token]
  gated_actions: [disable_principal]    # human approves anything destructive

Measured change

MeasureBeforeAfter
Sources onboardedfrozen - cost-constrainedall in scope, tiered by value
Real-time tier volume100% of telemetry18% - the detection-relevant fraction
Detections with automated tests0 of ~300100% - CI blocks untested rules
Technique coverage, measuredunknownpublished and tracked per release
Alert volume from the top 5 noisy rules34% of queueunder 4% after budgeting

Coverage and cost stopped being the same conversation. Detection became a codebase with owners, tests and a changelog - which is what makes it possible to delete a rule, not just add one.

Talk to a security operations, detection & response specialist.

Schedule a free consultation and our team will connect within 12 hours to understand your environment and map out the right approach.

We respond within 12 hours