Managed SOC 24/7: detection, analysis and response across your entire infrastructure

An in-house security operations centre in Spain that watches your endpoints, servers and cloud services, correlates every event in our SIEM and contains serious threats automatically, including at 3 a.m.

The IBERSYA SOC is a managed security operations centre that continuously monitors and correlates the security events of your endpoints, servers and cloud services. An analyst reviews every alert 8x5 and the platform responds automatically 24x7 —isolating the host, blocking the IP or blocking the mailbox— whenever there are serious signs of ransomware, intrusion or data exfiltration. It includes the Bitdefender GravityZone EDR licence at no extra cost, correlation in our own SIEM, external threat-intelligence enrichment of every alert, client access to our incident management platform and a technical and an executive report at the end of each month. Three service tiers from €6 per device/month, with an in-house SOC in Spain, direct contact with the technical team and all data held inside the European Union.

70% of cyberattacks happen between 8 p.m. and 6 a.m.
60% of SMEs close within 6 months of a serious attack
€50,000 average recovery cost for a Spanish SME
+43% increase in cyberattacks on Spanish businesses since 2024

What the IBERSYA SOC includes in all three tiers

All three tiers share the same core —SOC, EDR and SIEM— and each higher tier adds another layer of visibility over the organisation.

Continuous monitoring

Permanent monitoring of endpoints and servers, extendable to network and email through telemetry add-ons.

EDR licence included

Bitdefender GravityZone deployed and licensed within the per-device price, in any of the three tiers.

SIEM and correlation

Every alert lands in our SIEM, which cross-references events across different machines and across different periods of time.

Threat intelligence

Before an analyst looks at it, each alert is enriched with external sources: we know whether that IP, domain or file already appears in known campaigns.

Active 24/7 response

Automated containment of serious threats in real time: host isolation and IP or email blocking with no prior validation.

Configurable notifications

We handle the incident, but you can receive an alert every time something happens in your organisation.

Incident platform

You access our platform with your own role and see only what is yours: your cases, their status and what we did about each one.

Monthly reports

A technical report and an executive report at the end of every month, one written for the IT team and one for management.

Baseline assessment

At kick-off we deliver an honest picture of the organisation’s security posture and of the vulnerabilities we found.

Service architecture

How the IBERSYA SOC works

All telemetry is centralised in a single SIEM. That is where a stray event becomes an alert with context, and where we decide what to do about it.

1 · Data sources
  • Endpoints and laptops
  • On-premise servers
  • External attack surface
  • Network traffic · add-on
  • Email and identities · add-on
2 · IBERSYA SOC
  • Log and event collection
  • Correlation in the SIEM
  • Behavioural analysis
  • Threat-intelligence enrichment
  • Triage and prioritisation
3 · Response
  • Real-time alerts
  • Automated 24x7 containment
  • Isolation and blocking
  • 8x5 technical analysis
  • Report and case closure
From attack to containment

The path a threat follows, step by step

This is the real circuit of an incident, from the moment it reaches a client machine until it is neutralised and documented.

  1. The threat arrives

    An email with a malicious attachment, an infected download, a fraudulent website or an unauthorised connection attempt against a desktop, laptop or server running the EDR agent.

  2. The EDR acts and sends telemetry

    The agent blocks the threat if it can do so on its own and, whatever happens, sends all telemetry to our SIEM. That record is what later allows us to reconstruct exactly what occurred.

  3. The SIEM correlates

    The event is cross-referenced with what is happening on other machines and on previous days, and enriched with external threat intelligence before the alert is raised. An isolated attempt and a coordinated campaign stop looking alike.

  4. Response

    An analyst on 8x5 hours reviews the alert and rules out false positives. If it is real, we connect to the machine and neutralise the threat. If it is serious, the automated response acts 24x7 without waiting for anyone: it isolates the host, blocks the IP or blocks the mailbox.

  5. Investigation

    We determine the scope of the incident, its origin and the affected assets, and propose the measures needed to stop it recurring through the same route.

  6. Closure and evidence

    You get the notification if you have one configured, and the case is logged in the platform with every action taken, ready for the technical and executive report at month end.

Operating model

Two response modes, one single defence

The platform responds automatically 24x7 to serious threats; analysis and case follow-up are carried out by an analyst on 8x5 hours. Machine speed with human judgement.

Manual handling · 8x5

When the alert needs expert judgement

  • Technical analysis: an analyst reviews every alert and determines the real scope of the event.
  • Manual containment: remote connection to the machine to contain and neutralise the threat.
  • Case management: every incident is documented in the platform and visible to the client.
Active response · 24x7

On serious indicators, it acts on its own

  • Automated detection: ransomware, unauthorised connections and exfiltration, in real time.
  • Immediate containment: host isolation and IP or email blocking with no prior validation.
  • All year round: cover at night, at weekends and on public holidays.

Three tiers of managed protection

Priced per device per month, whether server or endpoint. Common core across all three tiers: SOC, EDR and SIEM.

Tier I · Entry level

6 €

per device, per month

  • Bitdefender GravityZone EDR licence included
  • Technical analysis of every alert on 8x5 hours
  • Automated 24x7 response to serious threats
  • In-house SIEM with event correlation
  • Threat-intelligence enrichment
  • Access to the incident management platform
  • Monthly technical and executive report
Request a quote
Tier II · Cyber intelligence

8 €

per device, per month

  • Everything in Tier I
  • Continuous monitoring of domains and IP addresses
  • Leaked credential detection
  • Sensitive data published or up for sale
  • Your real attack surface exposed to the internet
  • Actionable alerts: what to change and what to shut down
Request a quote
Tier III · Full visibility

12 €

per device, per month

  • Everything in Tier II
  • Wazuh agent deployed on every device
  • Detection of outdated and vulnerable software
  • Review of machine configuration and security policies
  • Continuous inventory and sign-in history
  • Direct evidence for NIS2, ENS and GDPR
Request a quote

Optional add-ons on any tier: Microsoft 365 telemetry (€60/month) and Fortinet telemetry (€60/month). The final figure depends on how many devices are monitored.

Optional add-ons

Two more sources for the same SIEM

Both sources join the rest of the telemetry and follow exactly the same alert, analysis and response path. They can be added to any tier.

€60/month

Microsoft 365 telemetry

We collect your tenant telemetry to detect and stop attacks against user accounts and corporate email.

  • Impossible travel: a user signing in from the Dominican Republic and five minutes later from Spain. The account is blocked immediately.
  • Email security: phishing, impersonation and mailbox rules created behind your back.
  • Critical changes: creation of Azure applications and sensitive configuration changes.
  • Data leakage: alerts on mass downloads or data exfiltration.
€60/month

Fortinet telemetry

We integrate your FortiGate firewall telemetry to watch everything happening at the network perimeter.

  • Configuration changes: immediate notice of any firewall modification.
  • Brute-force attacks: detection of repeated access attempts against the network.
  • Suspicious sign-ins: monitoring of VPN and administrative access.
  • C2 connections: traffic towards command-and-control infrastructure.

Is your business protected while you sleep?

Request a proposal

Certified technology and official partners

Bitdefender GravityZone is the standard EDR included in the price. As official partners of CrowdStrike and Palo Alto Networks, the SOC can also operate on their platforms when the organisation has already made that investment or needs a specific stack because of a group or customer requirement.

Our SIEM is Wazuh, case management runs on IRIS, and indicator enrichment on MISP plus public threat-intelligence sources such as AbuseIPDB and AlienVault OTX. Where a deployment calls for it we work with products listed in the CPSTIC catalogue of the Spanish National Cryptologic Centre and aligned with the Spanish National Security Framework (ENS).

Regulatory compliance: NIS2, ENS, DORA and GDPR

A SOC provides the active controls and incident traceability that the main regulatory frameworks require. Non-compliance can carry fines of up to 2% of annual turnover.

Client platform and monthly reports

We handle the incident, but the visibility is yours. You access our incident management platform with your own role and see only your own information: your cases, their status and the actions taken on each one. At the end of the month you receive two reports: a technical one for the IT team and an executive one written for management.

  • Access with your own role: you only see your cases, their status and the actions taken
  • Technical report and executive report at the end of every month
  • Follow-up and log of the work carried out proactively
  • Notification of the vulnerabilities found in your organisation
  • Client folder in SharePoint with proposals, contracts and documentation
IBERSYA SOC SIEM dashboard showing security event correlation
Onboarding

A guided, friction-free rollout

Response capability is live from the first phase. Initial deployment takes around two weeks.

1

Kick-off

We align objectives and collect the inventory of machines and servers to monitor.

2

Deployment

EDR agent installation and configuration of security policies tailored to you.

3

Baseline

We deliver the assessment document and the list of vulnerabilities found.

4

Operation

Continuous monitoring, contingency plan and monthly technical and executive reports.

Phases 1 and 2 · around 2 weeks

Why choose the IBERSYA SOC

What sets us apart from off-the-shelf antivirus, from a generalist IT provider and from a high-volume MSSP.

In-house SOC in Spain

The analyst who answers works at IBERSYA, with direct contact to the technical team. No ticket queues, and all data inside the European Union.

Genuine automated response

Immediate containment at night, at weekends and on public holidays too. Actions fire according to defined rules and are logged case by case.

Automated plus human

Machine speed to contain, analyst judgement to investigate. Filtering false positives is a large part of the job.

EDR licence included

Bitdefender GravityZone sits inside the per-device price at any tier. When comparing quotes, add up what the other provider bills separately.

SIEM correlation

We cross-reference events across machines and across time to catch attacks that, looked at in isolation, draw no attention.

Tiered model

You start at Tier I and move up when it makes sense. There is no need to buy the full package on day one.

SOC glossary

The terms that appear in any SOC proposal, explained without jargon.

SOC
Security operations centre: the team and platform that monitor, investigate and respond to incidents.
SIEM
A system that collects events from every machine and tool and cross-references them to detect attacks that would be invisible on a single device.
EDR
Advanced antivirus. As well as matching files against known threats, it watches machine behaviour and keeps a record of everything that happens.
SOAR
Response automation: rules that execute containment actions on their own, without waiting for an analyst to be at the desk.
MDR
Managed detection and response. It is the IBERSYA SOC service model: we provide both the technology and the analysts.
8x5 / 24x7
Service windows. 8x5 means 8 hours a day, 5 days a week. 24x7 means any hour, every day of the year.
Telemetry
The data that machines and security tools send continuously about what is happening.
False positive
An alert that looked dangerous and turns out to be harmless on review. Filtering them is much of the SOC’s work.
Containment / isolation
Disconnecting a machine from the network so the threat cannot spread, without powering it off or losing the evidence.
Attack surface
Everything the business exposes to the internet that an attacker could try to use: website, email, remote access, IP addresses.
Cyber intelligence
Monitoring what happens outside the network: whether the company’s passwords, domains or data appear published or for sale.
C2 (command and control)
The server an attacker uses to issue orders to an already infected machine. Detecting such a connection means the machine is compromised.
Impossible travel
Two sign-ins to the same account from places so far apart the person could not have travelled between them. Almost certainly a stolen account.
Ransomware
Software that encrypts the company’s files and demands a ransom. It is the incident that most often stops a business outright.

Frequently asked questions about the managed SOC

What is a SOC and what is it for?
A SOC (Security Operations Center) is a security operations centre that collects telemetry from a company’s endpoints, servers and cloud services, correlates it in a SIEM and acts when it detects an attack. It takes you from owning tools that raise alerts to having a service that interprets those alerts and responds: an analyst reviews each one and the platform automatically contains serious threats.
How much does a managed SOC cost for a business?
The IBERSYA SOC costs €6 per device/month at Tier I, €8 per device/month at Tier II and €12 per device/month at Tier III, with the Bitdefender GravityZone EDR licence included in all three tiers. The price is the same for a server and for a workstation. The Microsoft 365 and Fortinet telemetry add-ons cost €60/month each. A business with 40 devices starts at €240/month.
What is the difference between a SOC and just having antivirus?
Antivirus raises alerts but does not decide. It protects one machine and matches files against known threats. The SOC collects telemetry from every machine, cross-references it in a SIEM to detect attacks invisible on a single device, enriches each alert with external threat intelligence, rules out false positives and takes actions antivirus cannot, such as isolating a machine from the network at 3 a.m.
How does 24/7 protection work if technical analysis is 8x5?
They are two complementary layers. Automated response is active 24x7, 365 days a year: on serious signs of ransomware, intrusion or exfiltration the platform isolates the host, blocks the IP or blocks the mailbox without waiting for human validation. Analysis, investigation and case follow-up are carried out by an analyst on 8x5 hours. No serious attack waits until the next morning to be contained.
Does the SOC replace my IT provider or my in-house IT team?
No. The SOC is a monitoring and response layer that sits on top of whoever already manages the systems. Your team or your provider keep running day-to-day operations (desktops, networks, servers) and we supply the function almost nobody has in-house: alert analysis, SIEM correlation and automated response outside working hours. In practice we usually work alongside them.
What data of my company does the SOC see?
Security data only: events, telemetry, processes, network connections, sign-ins and alert metadata. We do not access the contents of your files or business applications. When we have to act on a machine to contain a threat, access is limited to the cybersecurity scope and is logged case by case in the incident management platform.
How long does the service take to go live?
Initial deployment is completed in around two weeks: kick-off and inventory, EDR agent installation and policy configuration, delivery of the baseline assessment with the vulnerabilities found, and handover to continuous operation. Detection and response capability is live from the deployment phase, not at the end of the project.
Does the SOC help with NIS2, ENS, DORA or GDPR compliance?
Yes. NIS2, the Spanish National Security Framework, DORA and the GDPR all require active detection controls, response capability and incident traceability. The SOC provides all three and documents them: a centralised history of access, vulnerabilities and configuration, a record of each incident with the actions taken, and a monthly technical and executive report you can use as evidence with an auditor, a customer or your insurer.
Is there a minimum number of devices to sign up for the SOC?
The service is billed per device per month, so it scales down to small estates. The final figure depends on how many machines and servers are monitored, and Tier I is the natural entry point because it already includes the EDR antivirus licence most businesses currently pay for separately.
Can you integrate CrowdStrike or Palo Alto Networks if I already have them deployed?
Yes. Bitdefender GravityZone is the standard EDR included in the price, but we are partners of CrowdStrike and Palo Alto Networks and the SOC can operate on CrowdStrike Falcon as the EDR or ingest telemetry from Palo Alto firewalls and Cortex XDR. That is the usual route for businesses that have already made the investment or need a specific stack because of a group or customer requirement.

Request a managed SOC proposal

Tell us how many machines and servers you have, whether you use Microsoft 365 and whether you have a firewall. With that we can quote you and show you the platform in a demo.

Phone 665 87 93 46
Hours Monday to Friday: 8:00 - 20:00
We call you!
Shall we call you?

Leave your phone number and we will contact you within 1 hour.