Log sources
Entra ID and Microsoft 365, Google Workspace, firewalls, VPN, Windows and Linux servers, EDR and, where relevant, critical applications such as the ERP or the e-government portal.
Each security tool sees one piece: EDR sees the devices, the firewall sees the network, Entra ID sees the sign-ins. A real attack leaves traces in all of them at once, but small ones: a sign-in from an unusual IP on Monday, a new forwarding rule in a mailbox on Tuesday, a laptop querying the directory far more than normal on Wednesday. On their own none looks serious; together they tell a story. A security operations centre pulls those logs into a SIEM, applies rules that look for such combinations and, above all, puts a person in charge of deciding whether an alert is real and what to do. We run that service remotely, during business hours or around the clock depending on the contract, with a response procedure agreed in advance and shaped around whatever reporting obligations your organisation has.
We start with the sources that say the most for the least volume: identity, email, EDR and firewall. Collecting everything from day one only drives up storage costs and buries the signals.
Entra ID and Microsoft 365, Google Workspace, firewalls, VPN, Windows and Linux servers, EDR and, where relevant, critical applications such as the ERP or the e-government portal.
Concrete use cases: impossible travel between two sign-ins, forwarding rules to outside mailboxes, admin accounts created out of hours, antivirus being disabled, mass access to shared folders.
Every alert is reviewed by an analyst, who rules out false positives, gathers context and decides whether to escalate. You receive incidents, not noise.
Actions agreed in advance: lock an account, isolate a device, revoke sessions or block an IP. What can be done without asking and what needs your approval is written down.
If an incident involves personal data, we provide the technical detail for the 72-hour notification to the AEPD. If your organisation falls under NIS2 or the ENS, we prepare the information for reporting to INCIBE-CERT or CCN-CERT within the deadlines that apply to you.
A monthly report on incidents, trends and rule changes, and a quarterly meeting to revisit the use cases with your team.
Getting started takes a few weeks. The first month is a learning period: rules are tuned to your company's normal behaviour so that alerts are few and meaningful.
Sources, use cases, retention, service hours and response procedure, with your contacts for each type of incident.
Sources wired into the SIEM without installing anything at your premises: cloud connectors and collectors on your servers.
A month of daily false-positive review and rule changes.
Monitoring and response as contracted, monthly reports and a yearly incident exercise with your team.
The response procedure is written before the incident, not during it. At three in the morning, with a server being encrypted, nobody should be deciding whether the analyst may isolate the invoicing server or which director needs to be woken. Those decisions, together with contacts and permissions, are signed off at the design stage.
EDR watches devices and acts on them. A SOC looks at the whole picture (identities, email, network and devices) and joins the dots. Many attacks start in email or with a stolen account and do not touch a device until the very end; at that stage EDR on its own sees nothing.
Clients on a 24/7 service receive an on-call line in their contract; it is not published on the website. During business hours any incident can be reported to helpme@apply.es, where every email becomes a prioritised ticket.
It depends on volume and retention, and it is the item that varies most. That is why we start with high-value sources and filter out irrelevant events before storing them. Before you sign, we give you an estimate based on a week of your real volumes.
In your own Azure subscription, your tenant or a server under your control, in an EU region and, if you prefer, in Spain. The logs are yours, and if you stop working with Apply they stay where they are.
On the technical side, yes: NIS2 requires significant incidents to be detected and reported within very short deadlines, with an early warning followed by a fuller report, and without monitoring it is hard to meet them. Whether your organisation is in scope and which authority to notify is for you to settle with your legal adviser.
Tell us which tools you have, how many users and servers, and whether you need 24/7 cover. We will reply with an outline design and the sources we would start with.
Your request is with us
Expect an answer within one working day. A reported fault that has halted your team is handled first.
No match found. Try another spelling, or go with the closest provincial capital: every job is done remotely, so the location makes no difference to what we deliver anywhere in Spain.