A SOC assessment done as a deep technical review, service by service, not a maturity checklist. Ten SOC services, each measured across four axes, for a precise and defendable picture of how effectively each one delivers and where to invest.
Capability
The full spectrum, at a depth others don’t reach.
Compromise assessment, digital forensics and incident response, threat hunting, SOC assessment and OT security, run from Switzerland for organizations across Europe and the Gulf. Whatever the engagement, the standard is the same: bespoke scope, senior delivery, and the rigor to go deeper than the brief requires.
Read this as a range of capabilities, not a list of products. Most engagements draw on several of them, in full or in part, assembled into one scope that answers the question actually being asked. A compromise assessment that becomes an investigation, a readiness review with a threat hunt inside it, a retainer that carries forensic capacity: that is the normal shape of the work.
HOW ENGAGEMENTS RUN
- Scoped, never templated Every engagement is shaped to the organization’s profile, technology and threat landscape, not fitted to a standard package.
- Senior hands only A principal-level operator leads the work, not a junior analyst learning on the account.
- Capability left behind Knowledge transfer and clear documentation mean the team is stronger after the engagement than before it.
Anticipate and strengthen.
Find and close the weaknesses before an adversary does, and prove the organization is ready for the day one gets through. SOC assessment, incident response planning and tabletop exercises.
What an organization needs to do the right things when an incident hits: contain fast, allocate resources where they matter, and avoid the costly missteps. Built on hundreds of real incidents rather than a template.
Continuous defense.
Senior expertise kept on tap and calibrated to a moving threat, so protection does not decay between point-in-time engagements. Managed threat hunting and a continuous cyber defense program.
A multi-year, threat-informed program that keeps defenses calibrated to the adversaries most likely to target the organization, and proves they work. The client’s team operates; principal-level experts design, engineer and advise at a depth an internal SOC cannot self-supply.
Hunts designed and run by DFIR consultants where a compromise would hurt most, in IT and OT. Every detection is investigated forensically to a verdict, and each monthly cycle states whether the critical systems show signs of compromise.
When it counts.
Fast, expert answers to incidents and the questions they raise, including the cases another team has already closed. Emergency incident response, digital forensics and compromise assessment.
Where the hard cases land. The work reconstructs what happened even when the evidence is cold, degraded or was written off as gone, then contains, eradicates and recovers with the calm of people who have done it before. When another team has already closed the case, this is often the second call, and the one that solves it.
More than a hunt for intruders. The assessment examines the environment for active compromise and, in the same pass, for the gaps between existing controls and best practice that would let an attacker move laterally, escalate privilege or persist. Run over time, one of the most effective ways to drive down high-severity incidents.
Exposure, found first.
Proof of what an attacker could reach, found and closed before anyone uses it. The identity review traces the paths to control of Active Directory and Entra ID, and the credentials already exposed.
Which paths lead from an ordinary account to control of Active Directory and Entra ID, and which of the organization’s credentials are already exposed. Every path comes with its evidence and root cause, and each exposed account is read against the paths it would open.
Controlled attack at the depth the question needs, from an external penetration test to an intelligence-led red team run against live production. Nineteen services in eight categories, each showing what an adversary could reach and whether the defenders would stop them.
Flagship program
CDAP / MULTI-YEAR
Cyber Defense Assurance Program
A multi-year, threat-informed program that keeps defenses calibrated to the adversaries most likely to target the organization, and proves they work. The client’s team operates; principal-level experts design, engineer and advise at a depth an internal SOC cannot self-supply.
It is still scoped bespoke. What changes is continuity: the same senior lead, the same understanding of your estate, and every finding carried through to verified closure rather than handed over as a report.
TYPICAL SHAPE OF ONE CYCLE
- Continuous compromise assessment, estate-wide
- Monthly penetration testing against the live estate
- Detection and threat-hunting engineering
- Hardening and identity or perimeter reduction
- Incident readiness, exercised not assumed
- Embedded Virtual Principal Consultant
Cadence, systems in scope and the mix of engagements are set per client. Every finding is carried to verified closure rather than logged and left.