Cyber Detector

Cyber DetectorBook a meeting
Menu
Partner-only SOC as a Service

24/7 SOC as a Service for MSPs and their customers.

Cyber Detector supports partners with a 25-person Security Operations Center in Germany, operating across three shifts to monitor, validate, prioritise and support response across customer environments.

25 SOC specialists in GermanyThree operational shiftsPartner-owned customer relationship
Illustrative SOC Operations ViewContinuous monitoring
TelemetrySources connected
Analyst queueCases prioritised
EscalationPartner workflow active
Security activity and reviewed casesAnalyst validated
Identity anomaly reviewedUser, device and location context combined
Exposure requires follow-upAsset relevance and vulnerability context added
Partner notifiedRecommended next step documented
DetectCorrelateValidateEscalate
One clearer operational caseSignals, context, analyst review and next actions brought together before escalation.
25 specialistsGerman SOC team
3 shiftsContinuous operational coverage
Partner-onlyNo direct end-customer sales
Connected deliverySIEM, VMaaS, NDR and Open XDR
From signal to coordinated action

A repeatable SOC workflow for partner-delivered security.

The SOC team supports partners by turning technical security signals into reviewed, prioritised and documented operational cases.

01

Monitor

Connected SIEM, network, identity and vulnerability data create a continuous operational picture.

02

Correlate

Related events are grouped so analysts can work with broader context instead of isolated alerts.

03

Validate

A SOC analyst reviews the available evidence, relevance and severity before escalation.

04

Prioritise

The partner receives a clearer indication of what requires attention first and why.

05

Coordinate response

Containment, remediation and communication are coordinated according to the agreed responsibility model.

06

Document

Actions, decisions and follow-up are captured for operations, management and governance work.

Human expertise around the clock

A 25-person SOC team working across three shifts.

The team in Germany supports partners with continuous monitoring, analyst review and coordinated follow-up across customer environments.

25

Security professionals

Three operational shifts create continuous coverage and ensure that relevant cases can be reviewed by human specialists throughout the day and night.

Shift 1Continuous coverage
Shift 2Continuous coverage
Shift 3Continuous coverage
Technology layerSIEM, VMaaS, NDR and Open XDR

Security data and exposure information are collected and connected across the agreed customer scope.

Analyst layerHuman validation before escalation

The SOC team reviews context and evidence instead of forwarding every raw alert.

Partner layerThe partner owns the customer dialogue

Cyber Detector supports the partner without creating channel conflict or selling directly to the customer.

Operational layerFollow-up through an agreed process

Responsibilities, escalation routes and response activities are defined for each setup.

Clear responsibility model

Technology, SOC, partner and customer each have a defined role.

The exact responsibility split is agreed during onboarding so alerts and incidents do not become unclear handovers.

Cyber Detector SOC

Monitors, correlates, validates, prioritises and supports response within the agreed technical and operational scope.

The partner

Owns the customer relationship, coordinates communication and manages the wider service delivery.

The customer

Provides access, business context and internal action according to its agreed responsibilities and procedures.

Partner-led onboarding

A structured process for each new customer environment.

We onboard the partner first. Additional customer environments can then be added through the same repeatable process as needs arise.

01

Partner onboarding

Review the service model, operational contacts, responsibilities and customer onboarding process.

02

Customer intake sheet

Document the environment, systems, contacts, escalation routes and agreed requirements.

03

Joint setup meeting

Review the customer’s IT landscape with the SOC team and connect the agreed data sources.

04

One week of data

Allow the connected environment to produce operational data for validation and tuning.

05

SOC review

Review the data after approximately one week and confirm that the environment is connected correctly.

Operational and management visibility

Reporting that supports action, customer dialogue and governance.

The reporting layer should translate technical operations into information the partner and customer stakeholders can use.

Prioritised cases

Reviewed findings with relevant context and a clearer indication of urgency.

Incident documentation

Recorded decisions, actions and follow-up across the agreed response process.

Management summaries

Operational insight translated for customer management and partner conversations.

Governance support

Documentation that can support structured NIS2 and ISO 27001 security work without guaranteeing compliance.

Partner confidence

Built to strengthen the partner’s own managed security offering.

“Cyber Detector gives us exactly the security and control we need – without complex setup for us and our customers.”
CO
Christian Bundgaard OtteHead of IT Operations · myCloud
“At OneOffice, we’ve been looking for a cybersecurity solution that’s both easy to implement and will truly add value for our customers. With Cyber Detector, we’ve found exactly that.”
MK
Martin KumminiCEO & Founder · OneOffice

Security & Trust

Review Cyber Detector’s current security and trust information. Product-specific data handling, retention and service commitments must be confirmed in the final agreement.

Review Security & Trust →

Part of CyberInspector

SOC as a Service works together with the wider CyberInspector platform, including Next-Generation SIEM, VMaaS, NDR and Open XDR.

Explore CyberInspector →
SOC as a Service FAQ

Clear answers before partner and customer onboarding.

Does Cyber Detector sell SOC services directly to end customers?

No. Cyber Detector works through partners. The partner owns the customer relationship, commercial dialogue and broader service delivery.

Where is the SOC team located?

The SOC team is based in Germany and consists of 25 employees working across three shifts.

What does the SOC team do?

The team monitors connected security data, correlates related signals, validates relevant cases, prioritises findings and supports escalation and response according to the agreed scope.

How is a new customer onboarded?

The partner and customer complete an intake sheet, review the IT environment with the SOC team, connect the agreed data sources and review the collected data after approximately one week.

Who communicates with the customer?

The partner owns the customer dialogue. The communication and escalation model is agreed during onboarding.

Does SOC as a Service guarantee NIS2 or ISO 27001 compliance?

No service guarantees compliance by itself. The service can support monitoring, documentation and operational follow-up, while the organisation remains responsible for governance and legal compliance.

Build a partner-delivered 24/7 security operation.

Map customer environments, escalation routes, responsibilities and the required CyberInspector service layers in one focused partner session.

SOC as a Service explained

What is SOC as a Service?

SOC as a Service combines security technology, operational processes and human analysts in a managed service that helps partners monitor and protect customer environments continuously.

A Security Operations Center receives and reviews security data from connected systems. Rather than forwarding every raw alert, analysts correlate related signals, add context, assess relevance and help determine what requires attention first.

For an MSP or IT partner, SOC as a Service provides access to specialist capability without building and staffing an internal 24/7 operation. The partner remains responsible for the customer relationship, while Cyber Detector supports the agreed monitoring, validation, escalation and reporting workflow.

The final service depends on the connected data sources, responsibilities, escalation routes and response permissions agreed for each customer environment.

SIEMThe data and detection layer

Collects, normalises, enriches and correlates security events from connected sources.

SOCThe people and process layer

Analysts review cases, validate context, prioritise findings and support coordinated follow-up.

MDR service modelManaged detection and response

Combines technology and analyst expertise according to an agreed operational and response scope.

Illustrative incident workflow

From suspicious activity to a documented partner response.

A realistic SOC workflow connects technology, analyst judgment and the partner’s customer process.

01

Signal detected

An unusual sign-in, endpoint event or network connection creates a security signal.

02

Context correlated

Identity, device, network and vulnerability information is connected.

03

Analyst validates

The SOC team reviews evidence, relevance and likely impact.

04

Priority assigned

The case is prioritised according to the available technical and business context.

05

Partner notified

The partner receives a clearer case and recommended next step through the agreed route.

06

Action documented

Response, remediation and follow-up are recorded for operations and reporting.

One operational case instead of multiple isolated alerts.

The exact notification route, response action and responsibility split depend on the agreed customer setup.

Clear service scope

What can be included—and what is agreed per customer.

A transparent scope protects the partner, the customer and the SOC team from unclear handovers during a security event.

Can be included in the SOC delivery

Continuous monitoring of the agreed connected security data.
Analyst validation and prioritisation of relevant cases.
Escalation support and documented recommended actions.
Operational reporting and management-oriented summaries.
Context from SIEM, VMaaS, NDR and Open XDR where included.

Agreed for each customer environment

01Data sources, integrations and technical coverage.
02Contact routes, escalation paths and authorised recipients.
03Permitted response actions and access responsibilities.
04Retention, service commitments and any applicable SLA.
05Responsibility split between SOC, partner and customer.
Customer environments and use cases

Designed for partners supporting different security needs.

The service model can be adapted to the customer’s IT landscape, internal resources and operational risk.

Production companies

Support environments where uptime, operational continuity and network visibility are essential.

NIS2-relevant organisations

Strengthen monitoring, documentation and structured operational follow-up.

Professional services

Protect identity, cloud services, customer information and distributed work environments.

Hybrid IT environments

Connect cloud, on-premises, endpoint, identity and network security data.

Customers without an internal SOC

Add 24/7 analyst capability without building a complete in-house operation.

Suspicious identity activityMalware and endpoint signalsUnusual network trafficCritical vulnerability contextCross-source security incidents

Build a partner-delivered 24/7 security operation.

Map the customer environment, escalation routes, responsibilities and required CyberInspector service layers in one focused partner session.