Almost nobody detects an incident themselves: they find out when a customer tells them, when the ransom note appears, or when someone outside gets in touch. The difference between a scare and a crisis is how long it takes you to find out, and that only shortens with telemetry that someone actually watches.
A SIEM is not a licence purchase
It is the most common installation we come across: the tool is bought, it collects logs from half the estate, nobody has written a rule that did not ship with it, and the alerts are ignored because 95% are noise. That is not detection: it is a monthly invoice.
Phase 1
What to log
Not everything, and not just anything. You pick the sources that cover the attack techniques that actually affect you, starting with identity, endpoint and perimeter.
Phase 2
What to detect
Rules written for your environment and mapped to MITRE ATT&CK, with the coverage documented: what you see and what you do not.
Phase 3
What to do
Every alert with its response playbook. An alert with no attached procedure ends up closed without investigation.
Scope of work
Design of the collection architecture and realistic volume sizing, which is what drives the cost.
Source integration: directory, endpoint, network, cloud, mail, critical applications and security devices.
Detection engineering: custom rules, tuning of existing ones and noise reduction until alerts can genuinely be worked.
Response playbooks per alert type, with concrete steps and escalation criteria.
Documented MITRE ATT&CK coverage, so the gaps are known.
Validation: we run the real techniques and check whether they fire. A detection that has never been tested does not exist.
How we work
1
Diagnosis
What you have, what it collects and what it actually sees today. If you already have a SIEM, the project is often to tune it, not replace it.
2
Threat model
Which attacks are plausible against your organisation. Sources and rules come from that, not from a generic catalogue.
3
Phased integration
Highest value-per-cost sources first. Detection starts within the first weeks, not at the end of the project.
4
Detection engineering
Writing and tuning rules, with active false positive reduction.
5
Offensive validation
Our offensive team runs the techniques and we check what fires and what does not. This is the part almost nobody does.
6
Handover
Training for your team and documentation so you can maintain it without depending on us.
What you get
Documented collection and retention architecture, with sizing and cost.
Rule catalogue, custom-written, with rationale and ATT&CK mapping.
Response playbooks per alert type.
Coverage report: which techniques you detect, which you do not and which gap to close next.
Validation results with the offensive tests executed.
Training for the team that will operate it.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.
Starting from nothing: Master SOC on BOX
A conventional SOC needs several servers, licences billed by data volume and people to keep it running. For a mid-sized organisation that rarely adds up, and it is the reason so many go years with no detection capability at all. Master SOC on BOX is our answer to that specific case: a complete security operations centre condensed into a reduced infrastructure, with the critical functions of a conventional one at a fraction of its installation and running cost.
It is built on open components, so there is no licence for us to sell you. We still have no incentive to push you towards a particular platform: if what suits you is tuning the commercial SIEM you already own, we will tell you so.
Collection
Elastic stack
Elasticsearch, Logstash and Kibana to ingest, normalise, correlate and query. This is the activity log you will later have to show an auditor.
Host
Wazuh
Host intrusion detection, file integrity monitoring and active response. This is where you see what an attacker does once inside.
Network
Suricata
Traffic monitoring and network detection. It covers what the endpoint cannot see: lateral movement, command and control, exfiltration.
Alerting
ElastAlert
Custom rules on already correlated data, each with its response playbook attached. Without this, a SIEM is a log warehouse.
It also integrates with the advanced endpoint protection you already run, whichever vendor it is, so those alerts enter the same flow and are investigated alongside the rest of the telemetry, not in a separate console.
What compliance it covers
Spain’s National Security Framework (ENS) does not ask for “a SIEM”: it asks for specific capabilities, and without a collection and correlation platform there is no way to evidence them. Master SOC on BOX is sized to cover those measures up to Medium level.
op.exp.8
Activity logging. Who, when, what type of event and with what outcome, with auditable retention and protected against tampering.
op.exp.9
Incident management logging. The trail behind the initial report, the interim ones and the final one, and the actions each of them triggered.
op.mon.1
Intrusion detection. Detection tooling on host and on network. At Medium level the reinforcement requires rule-based detection, which is precisely the engineering work that comes with the installation.
op.mon.2
Metrics system. The dashboards come from the same data, with no parallel spreadsheets that nobody updates.
op.mon.3
Monitoring. The automated security event collection system the measure asks for in so many words.
The same platform carries what other regimes require, because the underlying problem is the same in all of them: NIS2, which mandates an early warning within 24 hours and does not let you report what you never detected; DORA, with its incident logging and classification; ISO/IEC 27001, controls 8.15 and 8.16 on logging and monitoring; and Article 33 GDPR, whose 72 hours start running the moment you become aware of the breach.
See it running
You do not have to take the description on trust. We publish the full build and a hands-on demonstration, with the real console and the alerts firing.
Part 1 · Video
Implementation and roll-out
How the SIEM/SOC service is built piece by piece on the reduced infrastructure.
The technical detail is on the blog: Master SOC on BOX, part 1 and part 2. The videos open on YouTube: we do not embed them here so as not to bring third-party trackers onto this site.
What’s included and what isn’t
A service that does not say where it ends creates more friction than it removes. This is what the deployment covers, and what is quoted separately.
Included in the deployment
Scoping and sizing
Event volume, log retention and the size of the deployment are settled before anything is installed, against the regulation that applies to you and against your actual estate. We publish no figures here because any number would be wrong for half the cases.
Appliance or virtual machine
Delivered either as a preloaded physical box or as a virtual machine on your own hypervisor. You choose, depending on what you already run and on your isolation requirements.
Build and rule engineering
Installation, source integration, correlation and detection rules tuned against your environment, each with its response playbook. This is precisely the work that separates a SIEM from a log warehouse.
Integration with your endpoint protection
Alerts from the advanced endpoint protection you already run enter the same flow and are investigated alongside the rest of the telemetry, whichever vendor it comes from.
Audit-ready documentation
The trail and the dashboards you have to put in front of an ENS, ISO 27001 or NIS2 auditor, drawn from the same data rather than from a parallel spreadsheet.
Outside the deployment
Continuous monitoring
The platform is handed over working and tuned, but with nobody watching it. The usual arrangement is a separate periodic review with reports delivered monthly, quarterly or at whatever cadence we agree, on a block-of-hours basis.
Incident response and forensics
Detecting is not containing, eradicating or giving expert evidence. DFIR is a separate service with its own scope.
Third-party licences
The platform components are open source and there is no licence to sell you. Your antivirus, your EDR or any commercial product you already use remain yours.
Hardening and remediation
The SOC tells you what is wrong and in what order. Applying the patches and fixing the configurations is a different job.
Certification
The platform evidences specific Annex II measures, but it does not replace the certification body or the compliance consultancy.
None of the above is a refusal: all of it can be done, quoted separately and with its own scope, so you always know what you are paying for. The cost of the deployment depends on what the scoping produces, so there is no published rate and no trial period: there is a technical conversation first, and a quote after.
Questions we get asked
Which tool do you work with?
Whichever you have, or whichever suits you. We do not resell licences, so we have no incentive to push you towards a particular platform. If your budget does not stretch to a commercial solution, open alternatives work well with the right engineering.
Do you operate the SOC?
We can support operations and on-call under a service agreement, but our natural work is to build the capability and hand it over. If what you want is to outsource monitoring entirely, we will say so before starting.
We have a SIEM we do not use. Start again?
Almost never necessary. Usually the problem is incomplete sources and out-of-the-box rules, not the product. We start by measuring real coverage and decide with data.
Does it help with NIS2 or the ENS?
Yes. Both require detection, logging and timely notification. You cannot notify within 24 hours something you never detected.
Measure what you see today before buying anything
Half an hour with an auditor to review your current detection capability and decide whether you need more tooling or better engineering.
Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET) · Email: info@jaymonsecurity.com
We reply within 2 working hours.

