What it involves
We collect the events from servers, workstations, firewall, VPN and email in a single place, correlate them and watch them 24 hours a day. When something matches an attack pattern we act there and then: isolate the machine, kill the session, block the account. Includes a monthly report and a quarterly review of the detection rules.





