24/7 SOC as a Service for MSPs and their customers.
Cyber Detector supports partners with a 25-person Security Operations Center in Germany, operating across three shifts to monitor, validate, prioritise and support response across customer environments.
A repeatable SOC workflow for partner-delivered security.
The SOC team supports partners by turning technical security signals into reviewed, prioritised and documented operational cases.
Monitor
Connected SIEM, network, identity and vulnerability data create a continuous operational picture.
Correlate
Related events are grouped so analysts can work with broader context instead of isolated alerts.
Validate
A SOC analyst reviews the available evidence, relevance and severity before escalation.
Prioritise
The partner receives a clearer indication of what requires attention first and why.
Coordinate response
Containment, remediation and communication are coordinated according to the agreed responsibility model.
Document
Actions, decisions and follow-up are captured for operations, management and governance work.
A 25-person SOC team working across three shifts.
The team in Germany supports partners with continuous monitoring, analyst review and coordinated follow-up across customer environments.
Security professionals
Three operational shifts create continuous coverage and ensure that relevant cases can be reviewed by human specialists throughout the day and night.
Security data and exposure information are collected and connected across the agreed customer scope.
The SOC team reviews context and evidence instead of forwarding every raw alert.
Cyber Detector supports the partner without creating channel conflict or selling directly to the customer.
Responsibilities, escalation routes and response activities are defined for each setup.
Technology, SOC, partner and customer each have a defined role.
The exact responsibility split is agreed during onboarding so alerts and incidents do not become unclear handovers.
Cyber Detector SOC
Monitors, correlates, validates, prioritises and supports response within the agreed technical and operational scope.
The partner
Owns the customer relationship, coordinates communication and manages the wider service delivery.
The customer
Provides access, business context and internal action according to its agreed responsibilities and procedures.
A structured process for each new customer environment.
We onboard the partner first. Additional customer environments can then be added through the same repeatable process as needs arise.
Partner onboarding
Review the service model, operational contacts, responsibilities and customer onboarding process.
Customer intake sheet
Document the environment, systems, contacts, escalation routes and agreed requirements.
Joint setup meeting
Review the customer’s IT landscape with the SOC team and connect the agreed data sources.
One week of data
Allow the connected environment to produce operational data for validation and tuning.
SOC review
Review the data after approximately one week and confirm that the environment is connected correctly.
Reporting that supports action, customer dialogue and governance.
The reporting layer should translate technical operations into information the partner and customer stakeholders can use.
Prioritised cases
Reviewed findings with relevant context and a clearer indication of urgency.
Incident documentation
Recorded decisions, actions and follow-up across the agreed response process.
Management summaries
Operational insight translated for customer management and partner conversations.
Governance support
Documentation that can support structured NIS2 and ISO 27001 security work without guaranteeing compliance.
Built to strengthen the partner’s own managed security offering.
“Cyber Detector gives us exactly the security and control we need – without complex setup for us and our customers.”
“At OneOffice, we’ve been looking for a cybersecurity solution that’s both easy to implement and will truly add value for our customers. With Cyber Detector, we’ve found exactly that.”
Security & Trust
Review Cyber Detector’s current security and trust information. Product-specific data handling, retention and service commitments must be confirmed in the final agreement.
Review Security & Trust →Part of CyberInspector
SOC as a Service works together with the wider CyberInspector platform, including Next-Generation SIEM, VMaaS, NDR and Open XDR.
Explore CyberInspector →Clear answers before partner and customer onboarding.
Does Cyber Detector sell SOC services directly to end customers?
No. Cyber Detector works through partners. The partner owns the customer relationship, commercial dialogue and broader service delivery.
Where is the SOC team located?
The SOC team is based in Germany and consists of 25 employees working across three shifts.
What does the SOC team do?
The team monitors connected security data, correlates related signals, validates relevant cases, prioritises findings and supports escalation and response according to the agreed scope.
How is a new customer onboarded?
The partner and customer complete an intake sheet, review the IT environment with the SOC team, connect the agreed data sources and review the collected data after approximately one week.
Who communicates with the customer?
The partner owns the customer dialogue. The communication and escalation model is agreed during onboarding.
Does SOC as a Service guarantee NIS2 or ISO 27001 compliance?
No service guarantees compliance by itself. The service can support monitoring, documentation and operational follow-up, while the organisation remains responsible for governance and legal compliance.
Build a partner-delivered 24/7 security operation.
Map customer environments, escalation routes, responsibilities and the required CyberInspector service layers in one focused partner session.
What is SOC as a Service?
SOC as a Service combines security technology, operational processes and human analysts in a managed service that helps partners monitor and protect customer environments continuously.
A Security Operations Center receives and reviews security data from connected systems. Rather than forwarding every raw alert, analysts correlate related signals, add context, assess relevance and help determine what requires attention first.
For an MSP or IT partner, SOC as a Service provides access to specialist capability without building and staffing an internal 24/7 operation. The partner remains responsible for the customer relationship, while Cyber Detector supports the agreed monitoring, validation, escalation and reporting workflow.
The final service depends on the connected data sources, responsibilities, escalation routes and response permissions agreed for each customer environment.
Collects, normalises, enriches and correlates security events from connected sources.
Analysts review cases, validate context, prioritise findings and support coordinated follow-up.
Combines technology and analyst expertise according to an agreed operational and response scope.
From suspicious activity to a documented partner response.
A realistic SOC workflow connects technology, analyst judgment and the partner’s customer process.
Signal detected
An unusual sign-in, endpoint event or network connection creates a security signal.
Context correlated
Identity, device, network and vulnerability information is connected.
Analyst validates
The SOC team reviews evidence, relevance and likely impact.
Priority assigned
The case is prioritised according to the available technical and business context.
Partner notified
The partner receives a clearer case and recommended next step through the agreed route.
Action documented
Response, remediation and follow-up are recorded for operations and reporting.
The exact notification route, response action and responsibility split depend on the agreed customer setup.
What can be included—and what is agreed per customer.
A transparent scope protects the partner, the customer and the SOC team from unclear handovers during a security event.
Can be included in the SOC delivery
Agreed for each customer environment
Designed for partners supporting different security needs.
The service model can be adapted to the customer’s IT landscape, internal resources and operational risk.
Production companies
Support environments where uptime, operational continuity and network visibility are essential.
NIS2-relevant organisations
Strengthen monitoring, documentation and structured operational follow-up.
Professional services
Protect identity, cloud services, customer information and distributed work environments.
Hybrid IT environments
Connect cloud, on-premises, endpoint, identity and network security data.
Customers without an internal SOC
Add 24/7 analyst capability without building a complete in-house operation.
Build the SOC delivery around the customer’s actual environment.
SOC as a Service can connect with the wider CyberInspector security stack according to the agreed partner and customer scope.
Build a partner-delivered 24/7 security operation.
Map the customer environment, escalation routes, responsibilities and required CyberInspector service layers in one focused partner session.
