24/7 hotline

KEEL SECURITY · MDR · INCIDENT RESPONSE · MANAGED IT

Calm when
it matters.

A 24/7 SOC in Kiel that turns billions of events into the few signals that matter, and acts on them. Median triage T+00:07, Q2 2026. *

  • SOC staffed 24/7 in Germany
  • ISO/IEC 27001 [placeholder]
  • BSI-qualified APT response [placeholder]
  • NDA on request
Signal filter · 24 h Live
  1. 01 Events 2,184,331,902
  2. 02 Alerts 1,284
  3. 03 Incidents 3
  4. 04 Contained 3 of 3
* Illustrative data

02 / THE SOC FUNNEL

Two billion events. Three decisions.

01 · Events

2.18 bn

Ingested from endpoints, identity, cloud and network.

02 · Alerts

1,284

Left after correlation, enrichment and tuning.

03 · Incidents

3

Confirmed by an analyst as true positives.

04 · Contained

3

Median T+00:19 from first signal to containment.

Illustrative · Keel SOC, 24 h sample, 2026-09-23 00:00–24:00 UTC · bar length on log scale See how triage works →

03 / RESPONSE, ON T+ TIME

From alert to contained in eleven minutes.

One incident from last quarter, every step timestamped. The clock starts when the first signal arrives, not when someone notices.

  1. T+00:00

    Detected

    EDR flags credential dumping on host-17.example.com.

  2. T+00:04

    Triaged

    An L2 analyst confirms a true positive, severity High.

  3. T+00:11

    Contained

    Host isolated, account disabled, your IT lead on the phone.

  4. T+00:47

    Eradicated

    Persistence removed, lateral movement ruled out.

  5. T+06:00

    Reported

    Timeline, root cause and fixes in your console.

Illustrative · median T+00:07 to triage and T+00:19 to containment, all High/Critical incidents, Q2 2026 · host-17.example.com, 192.0.2.17

TLP:AMBER CASE STUDY · 04 / 2026

Ransomware at a mid-sized manufacturer, contained in 47 minutes.

“At 3 a.m. the phone rang, and the voice on the other end already knew which host, which account and what to do next.”

Head of IT, XXXXXXXX Manufacturing
Read the case
Detected
T+00:00
Mass file rename on a file server
Contained
T+00:47
14 hosts isolated, spread stopped
Data exfiltrated
None
Verified by forensic analysis
Back in production
2 days
From tested offline backups
Illustrative · client anonymized with permission

04 / NIS2

NIS2, without the panic.

Two questions give you a first indication. The full check takes three minutes and ends with your obligations in plain language. No email required.

Indicative only. Not legal advice.

Quick scope check0 of 2 answered
1. Your sector
2. Employees

Pick a sector and a size to see a first indication.

05 / ADVISORIES

What matters this week.

Critical 9.3 TLP:CLEAR

CVSS 4.0 · CVE-2026-XXXXX

Unauthenticated remote code execution in a widely used SSL VPN gateway

Affected: Gateway firmware 7.2.0 to 7.2.8 (placeholder)

Do now: Patch to 7.2.9 today and check for admin accounts created since 2026-09-20.

High 8.1 TLP:GREEN

CVSS 4.0 · CVE-2026-XXXXX

Privilege escalation in a backup agent for Windows servers

Affected: Agent 12.x (placeholder)

Do now: Update the agent and restrict the service account to backup rights only.

Medium 5.4 TLP:CLEAR

CVSS 4.0 · CVE-2026-XXXXX

Stored cross-site scripting in a self-hosted ticketing platform

Affected: Versions before 5.1 (placeholder)

Do now: Update within your regular patch window.

Placeholder IDs and products for demonstration.

PHOTO · duotone · two analysts at a quiet SOC desk, early morning light

06 / CAREERS

Join the watch.

Fair shifts, a certification budget and salary ranges on every posting. Prefer puzzles to cover letters? Apply through our CTF.

  • SOC Analyst L2Kiel · 4-on/4-off shifts, night bonus €58k–72k
  • Penetration TesterRemote in Germany · OSCP/OSEP budget €65k–85k
  • Incident ResponderKiel or Munich · paid on-call €72k–95k
All 14 open roles →

Talk to someone who does this at 3 a.m.

A free 30-minute consultation with a senior engineer. No sales script, NDA on request.

Book a consultation
  • ✓ Response within 15 minutes, 24/7
  • ✓ Fixed-price assessments, no long lock-in
  • ✓ ISO/IEC 27001 · TISAX [placeholders]

UNDER ATTACK RIGHT NOW

Call us. An incident responder answers, day or night.

+49 431 555 0000 Or request a callback, phone number only →
WARD Kit · D01