24/7 hotline

KEEL MDR

We watch.
You work.

24/7 detection and response by analysts in Kiel, on your existing tools. Live in 14 days.*

MTTD (median)
00:04
MTTR (median)
00:19
SLA attainment
99.4%
False positives passed on
< 2%
* Illustrative · High/Critical incidents, Q2 2026 · h:mm

01 / HOW TRIAGE WORKS

Noise in. Decisions out.

01 · Events · 24 h

2.18 bn

Illustrative · 24 h sample, 2026-09-23

  1. 01 · Events

    Everything is collected, nothing is ignored.

    Endpoint, identity, cloud, email and network telemetry flows into our platform in Frankfurt. Billions of events a day, normalized and enriched with threat intelligence.

  2. 02 · Alerts

    Correlation turns events into alerts.

    Detection rules mapped to ATT&CK and tuned to your environment. We suppress known-good behavior with you during onboarding, so alerts mean something.

  3. 03 · Incidents

    A human confirms every incident.

    L1 and L2 analysts investigate each alert with full context. Fewer than 2% of what reaches you turns out to be a false positive (illustrative).

  4. 04 · Contained

    We act, then we call.

    Pre-authorized actions like host isolation and account lockout start within minutes. You get a call, a T+ timeline and clear next steps.

02 / SLA ON T+ TIME

Every severity has a clock. It's in the contract.

SEVERITY TRIAGE YOU'RE NOTIFIED CONTAINMENT STARTED CHANNEL
Critical ≤ 00:10 ≤ 00:15 ≤ 00:20 Phone + console
High ≤ 00:20 ≤ 00:30 ≤ 00:45 Phone + console
Medium ≤ 01:00 ≤ 04:00 next business day Console + email
Low ≤ 08:00 weekly digest as agreed Monthly report

03 / DETECTION COVERAGE

Mapped to ATT&CK, tested monthly.

  • Detect + respond
  • Detect
  • Visibility only

Illustrative · simplified tactic set · coverage validated by purple-team exercises, 2026-08

04 / INTEGRATIONS

Your tools. Our eyes.

We connect to the EDR, identity, cloud and email security you already own. No rip-and-replace, and your logs stay in Germany.

  • EDRLogo placeholder
  • EDRLogo placeholder
  • XDRLogo placeholder
  • IdentityLogo placeholder
  • IdentityLogo placeholder
  • CloudLogo placeholder
  • CloudLogo placeholder
  • EmailLogo placeholder
  • FirewallLogo placeholder
  • SIEMLogo placeholder
  • TicketingLogo placeholder
  • OT sensorLogo placeholder

05 / ANALYSTS & SHIFT MODEL

People you can name, awake when you're not.

Night · 4 analysts + IR on call Day · 9 analysts + 2 threat hunters Handover · 30 min overlap
PORTRAIT · duotone · analyst at console, calm

Mira Albers

SOC Lead, L3

GCIH · GCFA · 9 yrs

PORTRAIT · duotone · hunter reviewing notes

Jonas Petersen

Threat Hunter

GREM · OSCP · 7 yrs

PORTRAIT · duotone · analyst on headset

Aylin Demir

SOC Analyst, L2

BTL1 · GCIA · 4 yrs

See it yourself: a 45-minute guided tour of our SOC in Kiel, in person or remote.

Book a SOC tour

06 / SAMPLE REPORT

What lands on your desk every month.

A redacted real report: executive summary, incidents on T+ timelines, coverage changes and recommended actions. 14 pages.

Download redacted sample (PDF, 2.1 MB)

07 / PRICING

Per endpoint. Per month. No surprises.

Excl. VAT · min. 100 endpoints · 12-month term · illustrative

Essentials

€6 / endpoint / month

Detection and triage on your EDR, 24/7.

  • 24/7 monitoring & triage
  • Phone escalation
  • Monthly report
  • Console access
Get a quote

Complete

€13 / endpoint / month

Full coverage including cloud and IR hours.

  • Everything in Standard
  • Cloud & network sources
  • 40 IR hours / year included
  • Named security advisor
Get a quote

08 / IN-HOUSE VS. MANAGED

A 24/7 SOC needs at least eight people.

Criterion IN-HOUSE 24/7 SOC KEEL MDR
Annual cost≈ €780,000 (8 FTE + tooling)≈ €108,000 (Standard)
Time to operational9–18 months14 days
Night & weekend coverageHard to staff, high turnoverIncluded
Detection engineeringYour teamShared across 180+ clients
Incident responseSeparate contractIncluded from Standard
Data locationYour choiceGermany

Illustrative estimate for 1,000 endpoints, Germany, 2026. Staffing: 8 FTE for 24/7 coverage incl. leave.

09 / FAQ

Questions we get in every first call.

Do we have to replace our existing tools?

No. We integrate with the EDR, identity and cloud security you already use. If you have no EDR, we can provide one as part of the service.

Where is our data stored and processed?

In ISO/IEC 27001-certified data centers in Frankfurt and Nuremberg. Analysts work from our SOC in Kiel. No data leaves the EU.

How do you avoid flooding us with false positives?

Every alert is investigated by an analyst before it reaches you. During onboarding we tune detections to your environment. Fewer than 2% of escalations are false positives (illustrative).

What does onboarding involve?

A kickoff, connector setup with your IT team (typically 6–10 hours of your time), a 7-day tuning phase and go-live. Live in 14 days on average (illustrative).

What are the contract terms?

12 months, then monthly cancellation. A free 30-day pilot on up to 250 endpoints.

Does this meet cyber-insurance requirements?

Most insurers ask for EDR, 24/7 monitoring, MFA and tested backups. Keel MDR covers the monitoring and response part; we document it for your insurer.

Live in 14 days. Watched from day one.

Free 30-day pilot on up to 250 endpoints · no lock-in after 12 months

WARD Kit · D02