Your infrastructure delivers the picture
Falcon sensors and connected log sources produce the picture: one platform, one dataset.
- Endpoints, servers and workloads
- Cloud and identity
- Network and OT
- Log sources (Next-Gen SIEM)
A classic Managed SOC detects and alerts. Fixing it usually stays with you. Our Managed CSIRT closes that gap: CrowdStrike Falcon Complete as the foundation, and above it a response team that actually resolves incidents.
Falcon sensors and connected log sources produce the picture: one platform, one dataset.
Every alert is analysed, judged and contained by the vendor's own team.
We take on everything that follows: platform operations, communication and the extended countermeasures.
You have one named contact, one picture of the situation and full transparency.
Up to the line, many providers look alike. Below the line, we are on our own.
| Capability | MDR | Managed SOC | ByteRay Managed CSIRTincl. MDR: Falcon Complete |
|---|---|---|---|
| 24/7 detection and alerting | ✓ | ✓ | ✓ |
| Triage and containment at the endpoint | ✓ | partly | ✓ |
| Management reporting and regular reviews | partly | ✓ | ✓ |
| Platform operations, tuning and product support | — | partly | ✓ |
| Incident management in your language, around the clock | — | partly | ✓ |
| Response tailored to a runbook we write with you | — | partly | ✓ |
| Learning loop: findings from live cases feed back into tuning | — | partly | ✓ |
| A named incident lead from the DFIR team, not account management | — | — | ✓ |
| When it stops being an alertBelow this line the incident is being managed, not monitored. | |||
| Managing a declared major incident¹ | — | — | ✓ |
| Incident command with a mandate, until operations are running again | — | — | ✓ |
| Incident response beyond the sensor: Active Directory, firewalls, SaaS, hypervisor, OT | — | — | ✓ |
| Regulatory notification and crisis communication: NIS2, GDPR, insurer, counsel | — | — | ✓ |
| BSI-listed APT response from the team already running your environment | — | — | ✓ |
✓ included · partly means vendor-dependent or limited in scope · — usually not included. MDR refers to vendor-operated detection and response such as CrowdStrike Falcon Complete.
¹Our three response tiersDay to day:Analysis and response at the sensor: included, unlimited.First response to a serious incident:Incident command, containment, notification deadlines: included, unlimited.Declared major incident:Weeks of forensics and recovery as a DFIR project, on terms you already know today.First response and containment are part of every incident. Managing a declared major incident runs as a DFIR project on terms agreed in advance, with guaranteed priority and no activation fee.
Managed CSIRT is our answer to a gap in the market: MDR plus a response team, delivered as one service.
A Managed SOC monitors, detects and alerts. Fixing the problem usually stays with you. Our Managed CSIRT contains that full SOC scope and goes further: a standing incident response team steps in, including beyond the sensor in Active Directory, firewalls, SaaS, hypervisor and OT. Detection and remediation come from one organisation.
MDR is the foundation: CrowdStrike Falcon Complete analyses, judges and contains every alert around the clock. The ByteRay CSIRT sits on top of it, with platform operations, incident management in English and German, and response tailored to a runbook we write with you. MDR plus a response team, as one service.
Falcon Complete is the vendor's own detection and response layer: every alert is reviewed by CrowdStrike analysts, judged and contained within pre-approved actions. Everything that reaches beyond the sensor is handled by the ByteRay CSIRT.
The runbook defines in advance how we act when something happens: approved measures, escalation paths, named contacts and communication. During an incident nothing is negotiated, it is executed the way your environment requires.
No, it takes the load off. Your team keeps full access to the Falcon console and authority over decisions; a named incident lead, a current picture of the situation and management reporting keep you informed. The operational weight of detection, triage and response sits with us.
Detection, response, notification and rehearsed processes pay directly into the core NIS2 obligations. Alongside that we offer NIS2 readiness, security workshops and tabletop exercises.