Service · Cybersecurity

SOC monitoring

Each security tool sees one piece: EDR sees the devices, the firewall sees the network, Entra ID sees the sign-ins. A real attack leaves traces in all of them at once, but small ones: a sign-in from an unusual IP on Monday, a new forwarding rule in a mailbox on Tuesday, a laptop querying the directory far more than normal on Wednesday. On their own none looks serious; together they tell a story. A security operations centre pulls those logs into a SIEM, applies rules that look for such combinations and, above all, puts a person in charge of deciding whether an alert is real and what to do. We run that service remotely, during business hours or around the clock depending on the contract, with a response procedure agreed in advance and shaped around whatever reporting obligations your organisation has.

SIEM
Microsoft Sentinel, Wazuh or similar
Mon-Fri 9-18 or 24/7
depending on the contract
Use cases
written for your environment, not generic
Procedure
for response agreed before any incident

What falls within the scope of this service

We start with the sources that say the most for the least volume: identity, email, EDR and firewall. Collecting everything from day one only drives up storage costs and buries the signals.

Pin down the details with one of our engineers

Log sources

Entra ID and Microsoft 365, Google Workspace, firewalls, VPN, Windows and Linux servers, EDR and, where relevant, critical applications such as the ERP or the e-government portal.

Detection rules

Concrete use cases: impossible travel between two sign-ins, forwarding rules to outside mailboxes, admin accounts created out of hours, antivirus being disabled, mass access to shared folders.

Triage

Every alert is reviewed by an analyst, who rules out false positives, gathers context and decides whether to escalate. You receive incidents, not noise.

Response

Actions agreed in advance: lock an account, isolate a device, revoke sessions or block an IP. What can be done without asking and what needs your approval is written down.

Help with notification

If an incident involves personal data, we provide the technical detail for the 72-hour notification to the AEPD. If your organisation falls under NIS2 or the ENS, we prepare the information for reporting to INCIBE-CERT or CCN-CERT within the deadlines that apply to you.

Reports and review

A monthly report on incidents, trends and rule changes, and a quarterly meeting to revisit the use cases with your team.

How the engagement unfolds, one stage at a time

Getting started takes a few weeks. The first month is a learning period: rules are tuned to your company's normal behaviour so that alerts are few and meaningful.

01

Design

Sources, use cases, retention, service hours and response procedure, with your contacts for each type of incident.

02

Connection

Sources wired into the SIEM without installing anything at your premises: cloud connectors and collectors on your servers.

03

Calibration

A month of daily false-positive review and rule changes.

04

Service

Monitoring and response as contracted, monthly reports and a yearly incident exercise with your team.

The response procedure is written before the incident, not during it. At three in the morning, with a server being encrypted, nobody should be deciding whether the analyst may isolate the invoicing server or which director needs to be woken. Those decisions, together with contacts and permissions, are signed off at the design stage.

Common questions

EDR watches devices and acts on them. A SOC looks at the whole picture (identities, email, network and devices) and joins the dots. Many attacks start in email or with a stolen account and do not touch a device until the very end; at that stage EDR on its own sees nothing.

Clients on a 24/7 service receive an on-call line in their contract; it is not published on the website. During business hours any incident can be reported to helpme@apply.es, where every email becomes a prioritised ticket.

It depends on volume and retention, and it is the item that varies most. That is why we start with high-value sources and filter out irrelevant events before storing them. Before you sign, we give you an estimate based on a week of your real volumes.

In your own Azure subscription, your tenant or a server under your control, in an EU region and, if you prefer, in Spain. The logs are yours, and if you stop working with Apply they stay where they are.

On the technical side, yes: NIS2 requires significant incidents to be detected and reported within very short deadlines, with an early warning followed by a fuller report, and without monitoring it is hard to meet them. Whether your organisation is in scope and which authority to notify is for you to settle with your legal adviser.

See the attack coming instead of finding it afterwards

Tell us which tools you have, how many users and servers, and whether you need 24/7 cover. We will reply with an outline design and the sources we would start with.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.