SOC and MDR monitoring
Relevant signals are collected, assessed by specialists and made visible for IT and management.
Security as a complete operating model: SOC-adjacent monitoring, technical assessment, clear priorities and a customer portal that connects endpoints and infrastructure.
This comparison shows which capabilities are included, available as an add-on or not included in the current package model.
| Service | ![]() | ![]() | ![]() |
|---|---|---|---|
| Prevention and Security Culture | |||
| Security awareness training | Add-on | Included | Included |
| Phishing simulations | Add-on | Included | Included |
| Technical Assessment and Hardening | |||
| Continuous vulnerability scans | Add-on | Included | Included |
| Vulnerability reports and scorecards | Add-on | Included | Included |
| Patch management | Not included | Included | Included |
| System hardening guidance | Not included | Add-on | Included |
| Manual pentesting | Not included | Add-on | Included |
| Operations and Resilience | |||
| Security monitoring and reporting | Add-on | Included | Included |
| Endpoint detection and response | Included | Included | Included |
| Incident triage and escalation | Add-on | Included | Included |
| Managed backups and restore checks | Add-on | Included | Included |
| Ransomware prevention basics | Add-on | Included | Included |
| Five-year documentation and retention | Included | Included | Included |
| Governance and Evidence | |||
| Risk management | Add-on | Included | Included |
| Security posture assessment | Add-on | Included | Included |
| Cyber insurance readiness | Not included | Add-on | Included |
| Regular security review meetings | Not included | Add-on | Included |
| Executive trend report and readout | Not included | Not included | Included |
These capabilities are not separate sales paths. They are parts of one operating model, with depth depending on risk, environment and package.
Relevant signals are collected, assessed by specialists and made visible for IT and management.
Endpoints are treated as part of the operating model so suspicious activity is not handled too late or in isolation.
External and internal attack surfaces are checked regularly and prioritized by real risk.
Critical actions become manageable work items instead of unfiltered tool output.
Recoverability is verified, documented and connected with resilience planning.
Employees train with realistic scenarios so technical controls are supported by safer behavior.
Clear escalation paths, structured assessment and calm coordination support suspected or confirmed incidents.
Findings, decisions, action status and next steps remain traceable in one place.
Managed security only works when assessment, implementation and operations run together. The workflow therefore stays repeatable and traceable.
We capture systems, risks, existing controls and the required operating depth.
Endpoints, infrastructure, processes and people are connected in one security model.
Signals, vulnerabilities and events are made visible and assessed continuously.
Findings become concrete actions with urgency, ownership and clear rationale.
Status, decisions and progress are documented in the customer portal.
Recurring sessions keep goals, risks and next steps current.
We do not sell disconnected measures. Packages connect people, technology, operations and decisions into one manageable model.
Experts test, assess and prioritize. Automation supports the work but does not replace accountable judgement.
Your team receives clear priorities, understandable reports and traceable next steps instead of scattered tool output.
Answers about pricing, package selection and getting started with endline.
Pricing is calculated individually. The main factors include the number and type of hosts or endpoints, the number of employees, existing IT and security systems, the required level of support and any add-ons. After a short needs assessment, you receive a transparent proposal with a clearly defined scope of services.
Basic is designed for organizations with about 5 to 10 employees and no formal compliance obligations. Plus covers broader ongoing security operations, while Premium supports higher evidence, resilience and compliance requirements. The final choice is based on your actual environment and risks.
Yes. Services marked with a plus can be added after technical coordination. Scope and pricing depend on the selected base package, your system landscape and the required operating effort.
During the first meeting, we review systems, hosts, responsibilities, risks, existing tools and priorities. This produces an agreed scope of services and concrete setup and onboarding steps.
Not automatically. Existing solutions are assessed for suitability and integration options. Replacement is recommended only when there are relevant protection gaps, technical limitations or unnecessary operating overhead.
Relevant security reports, findings, decisions and action status are retained traceably for five years within the agreed documentation model. Content, access rights, privacy requirements and deletion requirements are defined during onboarding.
We clarify which package fits your environment, which capabilities should create impact first and how collaboration can start without unnecessary complexity.