Almost nobody detects an incident themselves: they find out when a customer tells them, when the ransom note appears, or when someone outside gets in touch. The difference between a scare and a crisis is how long it takes you to find out, and that only shortens with telemetry that someone actually watches.
A SIEM is not a licence purchase
It is the most common installation we come across: the tool is bought, it collects logs from half the estate, nobody has written a rule that did not ship with it, and the alerts are ignored because 95% are noise. That is not detection: it is a monthly invoice.
Phase 1
What to log
Not everything, and not just anything. You pick the sources that cover the attack techniques that actually affect you, starting with identity, endpoint and perimeter.
Phase 2
What to detect
Rules written for your environment and mapped to MITRE ATT&CK, with the coverage documented: what you see and what you do not.
Phase 3
What to do
Every alert with its response playbook. An alert with no attached procedure ends up closed without investigation.
Scope of work
Design of the collection architecture and realistic volume sizing, which is what drives the cost.
Source integration: directory, endpoint, network, cloud, mail, critical applications and security devices.
Detection engineering: custom rules, tuning of existing ones and noise reduction until alerts can genuinely be worked.
Response playbooks per alert type, with concrete steps and escalation criteria.
Documented MITRE ATT&CK coverage, so the gaps are known.
Validation: we run the real techniques and check whether they fire. A detection that has never been tested does not exist.
How we work
1
Diagnosis
What you have, what it collects and what it actually sees today. If you already have a SIEM, the project is often to tune it, not replace it.
2
Threat model
Which attacks are plausible against your organisation. Sources and rules come from that, not from a generic catalogue.
3
Phased integration
Highest value-per-cost sources first. Detection starts within the first weeks, not at the end of the project.
4
Detection engineering
Writing and tuning rules, with active false positive reduction.
5
Offensive validation
Our offensive team runs the techniques and we check what fires and what does not. This is the part almost nobody does.
6
Handover
Training for your team and documentation so you can maintain it without depending on us.
What you get
Documented collection and retention architecture, with sizing and cost.
Rule catalogue, custom-written, with rationale and ATT&CK mapping.
Response playbooks per alert type.
Coverage report: which techniques you detect, which you do not and which gap to close next.
Validation results with the offensive tests executed.
Training for the team that will operate it.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.
Questions we get asked
Which tool do you work with?
Whichever you have, or whichever suits you. We do not resell licences, so we have no incentive to push you towards a particular platform. If your budget does not stretch to a commercial solution, open alternatives work well with the right engineering.
Do you operate the SOC?
We can support operations and on-call under a service agreement, but our natural work is to build the capability and hand it over. If what you want is to outsource monitoring entirely, we will say so before starting.
We have a SIEM we do not use. Start again?
Almost never necessary. Usually the problem is incomplete sources and out-of-the-box rules, not the product. We start by measuring real coverage and decide with data.
Does it help with NIS2 or the ENS?
Yes. Both require detection, logging and timely notification. You cannot notify within 24 hours something you never detected.
Measure what you see today before buying anything
Half an hour with an auditor to review your current detection capability and decide whether you need more tooling or better engineering.
Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET) · Email: info@jaymonsecurity.com
We reply within 2 working hours.

