CrowdStrike Falcon for business, deployed and operated from our SOC

We are an official CrowdStrike partner. We license, deploy and tune Falcon, and add the layer the console cannot provide on its own: technical analysis of every detection, SIEM correlation and automated 24x7 response.

CrowdStrike Falcon is a cloud-native endpoint protection platform that brings together next-generation antivirus (NGAV), EDR and XDR in a single lightweight agent. It detects indicators of attack by analysing process behaviour, not just known malware signatures, and lets you isolate a host and run remote remediation in seconds. IBERSYA is an official CrowdStrike partner: we handle licensing, sensor deployment on Windows, macOS and Linux, prevention policy tuning and day-to-day operation from our managed SOC in Spain —technical analysis of every detection on 8x5 hours, correlation in our SIEM with the rest of the telemetry, and automated 24x7 response to ransomware, intrusions or exfiltration. Falcon is the premium alternative to the Bitdefender GravityZone EDR included in the SOC price, and is licensed separately.

Official CrowdStrike partner

Falcon supplies the telemetry; the SOC supplies the judgement and the response

A top-tier EDR platform with nobody interpreting its detections is still just a tool that raises alerts. The value is in the operation.

Single lightweight agent

One sensor for prevention, EDR and XDR, without the accumulated layers of traditional suites.

Behavioural detection

Indicators of attack rather than signatures: it detects techniques, not just files already known.

Operated from Spain

The analyst who answers works at IBERSYA, with direct contact to the technical team.

24x7 response

Host isolation and automated blocking on serious indicators, at 3 a.m. as well.

CrowdStrike Falcon capabilities we put into production

We configure the modules the organisation needs and wire them into the SOC’s alert, analysis and response circuit.

Next-generation prevention

Machine learning and indicators of attack to stop malware, ransomware and malicious code execution before it completes.

EDR with deep telemetry

Continuous recording of processes, network connections and system changes. It lets us reconstruct in detail what happened, when, and how it got in.

Remote containment

Isolating the host from the network without powering it off or losing evidence, plus remote remediation on the affected device.

Threat intelligence

Adversary and active-campaign context attached to each detection, which we add to the SOC’s own enrichment with MISP and public sources.

Vulnerability management

Visibility of outdated software and exposed vulnerabilities on each machine, prioritised by real exploitability.

Multi-platform coverage

Windows and Windows Server, macOS, Linux distributions, virtualised environments and cloud workloads from a single console.

Falcon plus SOC

What our SOC adds on top of the CrowdStrike console

Falcon produces high-quality detections. The operational question is who looks at them, who decides what they are and who acts at 3 a.m.

1

8x5 technical analysis

An analyst reviews every detection, rules out false positives and determines the real scope of the event.

2

SIEM correlation

Falcon telemetry is cross-referenced with the firewall, Microsoft 365 and the rest of the estate, across different periods of time.

3

External enrichment

Every IP, domain or file is checked against intelligence sources before analysis, to see whether it already appears in known campaigns.

4

Automated 24x7 response

On serious indicators the platform isolates the host and blocks the IP or mailbox without waiting for human validation.

5

Case management

Every incident is documented in our platform, with your own access so you can see status and the actions taken.

6

Monthly reports

A technical report for the IT team and an executive report for management, usable as compliance evidence.

How to choose

CrowdStrike Falcon or Bitdefender GravityZone

Both are solid EDR platforms and both are operated from our SOC through the same alert, analysis and response circuit. The difference lies in the licensing model and the depth of the telemetry.

CriterionBitdefender GravityZoneCrowdStrike Falcon
LicensingIncluded in the SOC price, from €6 per device/monthLicensed separately from the SOC service
Position in the serviceStandard EDR across all three tiersPremium option on request or requirement
ArchitectureCloud console with its own agentCloud-native, single agent for prevention, EDR and XDR
Typical fitSMEs and mid-sized businesses looking for the best cost-to-protection ratioOrganisations with a vendor requirement, an international parent company or a need for threat hunting
Operated from the SOC8x5 analysis and automated 24x7 response8x5 analysis and automated 24x7 response
Correlation in our SIEMYesYes

If you already run Falcon in production, nothing needs replacing: we connect its telemetry to our SIEM and the SOC starts operating on the investment you have already made.

Want CrowdStrike Falcon with a SOC that genuinely operates it?

Request a proposal

Deployment, migration and coexistence with your current stack

A badly deployed EDR generates false positives, slows machines down and ends up switched off by the user. Deployment runs in phases: inventory, sensor installation in learning mode, exclusion tuning against your business applications, orderly removal of the previous solution, and the move to active prevention. Detection capability is live from the first phase.

  • Inventory of machines, servers and workloads to protect
  • Sensor installation and policy tuning against your real applications
  • Orderly removal of the previous antivirus to avoid agent conflicts
  • Connection of the telemetry to our SIEM and to the incident platform
  • Delivery of the baseline assessment and the vulnerabilities found
IBERSYA SOC analyst operating CrowdStrike Falcon

Frequently asked questions about CrowdStrike Falcon

What is CrowdStrike Falcon?
CrowdStrike Falcon is a cloud-native endpoint protection platform that combines next-generation antivirus (NGAV), EDR and XDR in a single lightweight agent. Rather than relying only on known malware signatures, it detects indicators of attack by analysing process behaviour, and sends all telemetry to the CrowdStrike cloud, where it is correlated with activity observed across the rest of the protected organisations.
Is IBERSYA a CrowdStrike partner?
Yes. IBERSYA is an official CrowdStrike partner and we deploy, configure and operate Falcon from our SOC in Spain. We handle licensing, sensor deployment, prevention policy tuning and day-to-day operation: analysis of every detection on 8x5 hours and automated 24x7 response to serious threats.
What is the difference between CrowdStrike Falcon and Bitdefender GravityZone?
Bitdefender GravityZone is our SOC’s standard EDR and its licence is included in the per-device price, from €6 per device/month. CrowdStrike Falcon is the premium alternative: a single cloud-native agent, deeper telemetry, threat hunting capabilities and CrowdStrike’s own threat intelligence. Falcon is licensed separately from the SOC service. The choice depends on budget, on the level of visibility the organisation needs, and on whether a parent company or customer requirement imposes a specific vendor.
Can I buy the IBERSYA SOC if I already have CrowdStrike deployed?
Yes, and it is one of the most common scenarios. If you already run Falcon in production, we connect its telemetry to our SIEM and the SOC starts operating on the platform you have already paid for: analysis of every detection, correlation with the other sources, enrichment with external threat intelligence and automated 24x7 response. There is no need to replace the agent or duplicate licences.
Does CrowdStrike Falcon replace traditional antivirus?
Yes. Falcon includes next-generation malware prevention and is designed to work as the sole endpoint protection solution, with no need to keep an additional antivirus. Running two protection agents on the same machine usually causes performance conflicts and false positives, so during deployment we remove the previous solution in an orderly way.
Which operating systems does the Falcon agent support?
The Falcon sensor covers Windows and Windows Server, macOS and the main Linux distributions, as well as virtualised and container environments. That means one console can protect workstations, data-centre servers and cloud workloads, which is particularly useful in hybrid environments.
What does the IBERSYA SOC add on top of the CrowdStrike console?
The Falcon console produces detections, but somebody has to look at them, decide what they are and act. Our SOC provides that function: an analyst reviews every detection on 8x5 hours, we correlate it in our SIEM with firewall, Microsoft 365 and estate-wide telemetry, we enrich each indicator with external threat intelligence and we automatically contain serious threats 24x7. You also receive a technical and an executive report at the end of every month.
How much does CrowdStrike Falcon cost for a business?
The Falcon licence is quoted separately from the SOC service, because the price depends on the modules chosen and the number of devices. The IBERSYA SOC keeps its per-device monthly rate (€6, €8 or €12 depending on the tier) and Falcon licensing is added on top. Tell us how many machines and servers you have and what level of visibility you need and we will prepare the two line items separately.

Request a CrowdStrike Falcon proposal

Tell us how many machines and servers you have, which antivirus you use today and whether you already run Falcon. We will prepare the licensing and the SOC service as separate line items.

Phone 665 87 93 46
Hours Monday to Friday: 8:00 - 20:00
We call you!
Shall we call you?

Leave your phone number and we will contact you within 1 hour.