Onboarding sources
Identity and mail (Entra ID with Microsoft 365, or Google Workspace), the firewall and VPN gateway, domain controllers, critical servers and EDR. Website and e-commerce logs can be added when relevant.
Events that look harmless on their own can tell the story of an attack once they are lined up. Think of an exporter in Gaziantep. On Monday morning the finance manager's account signs in from abroad. The same day a mailbox rule appears that forwards every message containing the word “bank” to an outside address. On Wednesday a European buyer receives an email announcing a new IBAN. Every clue lives in a separate system and log, and none triggers an alert by itself. Had someone seen them side by side, the account could have been locked before any money moved. That is the job of SOC monitoring. We collect identity, email, firewall, server and endpoint logs in one platform, look for suspicious patterns using detection logic adapted to how your company works, and have an analyst review each alert. When a threat is real, we carry out the steps you approved beforehand: locking an account, ending sessions, isolating a device. Few SMEs can justify an in-house security operations team, so we deliver this service fully remotely.
Log sources differ in value. The richest ones come first; more are added gradually.
Identity and mail (Entra ID with Microsoft 365, or Google Workspace), the firewall and VPN gateway, domain controllers, critical servers and EDR. Website and e-commerce logs can be added when relevant.
Logic for familiar attacker behaviour: impossible travel between sign-ins, newly created forwarding rules, accounts added to admin groups, mass deletion or encryption of files, VPN sessions at odd hours.
An analyst checks every alert: false positive, harmless exception or genuine incident. Only what really matters reaches you, in writing, so you are not buried in noise.
Pre-approved actions such as locking an account, ending sessions, resetting a password, isolating a device or blocking an IP address. The actions we can take on our own authority are listed in writing.
When things turn serious: containing the damage, securing evidence, cleaning up and restoring service. If personal data is affected, we assemble the technical facts your legal adviser needs to decide on KVKK notification.
Each month, a plain-language summary of alerts, incidents, patterns and advice, and a short video review each quarter.
Expect a settling-in period of several weeks, after which raw noise has been shaped into dependable early warnings.
We fix the log sources, coverage hours, named contacts and pre-approved actions in a short working document.
Log forwarding is set up, completeness is verified and the first rules go live.
A tuning stretch of two to four weeks that teaches the platform your normal patterns, filters out noisy alerts and adds the exceptions you need.
Continuous monitoring, playbook-driven response, monthly reporting and a quarterly rule review.
Intruders rarely strike the moment they get in. They often wait days or weeks, mapping accounts, hunting for backups and choosing their moment. That dwell time is the defender's best opportunity. A SOC is not there to guard the front door, but to make sure nobody wanders around inside unnoticed.
The standard scope covers Monday to Friday, 09:00-18:00 Turkey time. Automated rules keep running outside those hours, so a device showing signs of ransomware is isolated automatically. Continuous human monitoring is added to the contract through the Premium plan or the 24/7 support service.
On a platform running in EU data centres. Since log entries include personal data, this is a transfer abroad under KVKK: it should appear in your privacy notice and inventory, and your lawyer should assess the legal basis. We agree the retention period with you based on your needs and legal requirements.
The law and sector rules set expectations around detecting, recording and reporting incidents, with more detail for critical infrastructure operators. SOC monitoring covers a technical part of those expectations and produces the information needed for reports to USOM or a sector SOME. It is not a compliance guarantee on its own.
EDR only sees devices. Mailbox rules, cloud sign-ins, VPN sessions and firewall logs are outside its view. An IBAN fraud like the one described above can happen without malware ever running on a device. A SOC brings those separate sources together.
Tell us which platforms, firewall and EDR you use. We will say which sources make sense to start with.
We have your enquiry
A reply will reach you by the next working day at the latest. If your message says work has come to a halt, it goes to the top of the pile.
No such city in our list. Try another spelling, or just pick the closest big city: we work entirely over remote connections, so nothing about the service changes from one province to the next.
The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.