A SOC detects.Our CSIRT steps in.

More than a Managed SOC: CrowdStrike Falcon Complete answers every alert, and our response team takes the incident on from there. Around the clock, under a runbook we write with you.

This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
Our service model

Four layers. One service.

A classic Managed SOC detects and alerts. Fixing it usually stays with you. Our Managed CSIRT closes that gap: CrowdStrike Falcon Complete as the foundation, and above it a response team that actually resolves incidents.

Layer 1: Telemetry

Your infrastructure delivers the picture

Falcon sensors and connected log sources produce the picture: one platform, one dataset.

  • Endpoints, servers and workloads
  • Cloud and identity
  • Network and OT
  • Log sources (Next-Gen SIEM)
Layer 2: Detection and Response

Falcon Complete answers every alert

Every alert is analysed, judged and contained by the vendor's own team.

  • Analysis of all alerts
  • Triage and containment within pre-approved actions
  • Around the clock, by the vendor's analysts
Layer 3: CSIRT

ByteRay is your response team

We take on everything that follows: platform operations, communication and the extended countermeasures.

  • Extended incident response beyond the sensor: Active Directory, firewalls, SaaS, hypervisor, OT
  • 24/7 incident management in English and German
  • Response tailored to a runbook we write with you
  • Platform operations, tuning and CrowdStrike product support
  • Service reviews and reporting
  • Optional: security workshops · tabletop exercises · NIS2 readiness
Layer 4: Relief

You get your hours back

You have one named contact, one picture of the situation and full transparency.

  • A named incident lead as your contact
  • Regular management reporting
  • Full access to the Falcon console
The difference

A SOC alerts. A CSIRT steps in.

Up to the line, many providers look alike. Below the line, we are on our own.

CapabilityMDRManaged SOCByteRay Managed CSIRTincl. MDR: Falcon Complete
24/7 detection and alerting
Triage and containment at the endpointpartly
Management reporting and regular reviewspartly
Platform operations, tuning and product supportpartly
Incident management in your language, around the clockpartly
Response tailored to a runbook we write with youpartly
Learning loop: findings from live cases feed back into tuningpartly
A named incident lead from the DFIR team, not account management
When it stops being an alertBelow this line the incident is being managed, not monitored.
Managing a declared major incident¹
Incident command with a mandate, until operations are running again
Incident response beyond the sensor: Active Directory, firewalls, SaaS, hypervisor, OT
Regulatory notification and crisis communication: NIS2, GDPR, insurer, counsel
BSI-listed APT response from the team already running your environment

✓ included · partly means vendor-dependent or limited in scope · — usually not included. MDR refers to vendor-operated detection and response such as CrowdStrike Falcon Complete.

Our three response tiersDay to day:Analysis and response at the sensor: included, unlimited.First response to a serious incident:Incident command, containment, notification deadlines: included, unlimited.Declared major incident:Weeks of forensics and recovery as a DFIR project, on terms you already know today.First response and containment are part of every incident. Managing a declared major incident runs as a DFIR project on terms agreed in advance, with guaranteed priority and no activation fee.

You have a SOC. Do you have a response team?

Book a call
Book a call
FAQ

SOC, MDR, CSIRT: what is what?

Managed CSIRT is our answer to a gap in the market: MDR plus a response team, delivered as one service.

What is the difference between a Managed CSIRT and a Managed SOC?+

A Managed SOC monitors, detects and alerts. Fixing the problem usually stays with you. Our Managed CSIRT contains that full SOC scope and goes further: a standing incident response team steps in, including beyond the sensor in Active Directory, firewalls, SaaS, hypervisor and OT. Detection and remediation come from one organisation.

Is this an MDR service?+

MDR is the foundation: CrowdStrike Falcon Complete analyses, judges and contains every alert around the clock. The ByteRay CSIRT sits on top of it, with platform operations, incident management in English and German, and response tailored to a runbook we write with you. MDR plus a response team, as one service.

What role does CrowdStrike Falcon Complete play?+

Falcon Complete is the vendor's own detection and response layer: every alert is reviewed by CrowdStrike analysts, judged and contained within pre-approved actions. Everything that reaches beyond the sensor is handled by the ByteRay CSIRT.

What does the shared runbook define?+

The runbook defines in advance how we act when something happens: approved measures, escalation paths, named contacts and communication. During an incident nothing is negotiated, it is executed the way your environment requires.

Does this replace our internal IT or security team?+

No, it takes the load off. Your team keeps full access to the Falcon console and authority over decisions; a named incident lead, a current picture of the situation and management reporting keep you informed. The operational weight of detection, triage and response sits with us.

Does this help us with NIS2?+

Detection, response, notification and rehearsed processes pay directly into the core NIS2 obligations. Alongside that we offer NIS2 readiness, security workshops and tabletop exercises.

z
z
z
z
i
i
z
z
Hand over
the night shift.
We will walk you through how the handover works and what would end up in your runbook.
Prefer to book a slot right away?
Book an intro call