113SEC  —  MANAGED SECURITY
X000Y000
[113SEC]TR
SUPPORT
+
+
[ 06 ] — MANAGED SECURITY

MANAGEDSECURITY

A 24/7 security operations centre for companies that can't staff one. We collect the logs, let AI filter the noise, and put a human analyst on what's real — so your team can stay on the business.

COVER24/7 SOC
COREWAZUH SIEM
MODELFIXED MONTHLY

A managed security service (MSSP) means handing log collection, threat detection, alert review and incident response to an external 24/7 security operations centre instead of hiring and running that team in-house.

In practice: an agent is installed on your servers and endpoints, their records stream into a central SIEM, rules and AI read those records continuously, and only the events that matter reach our team — who then pick up the phone.

WHAT THE
SERVICE · COVERS

  • 01
    24/7 SOC Monitoring

    Servers, endpoints, firewalls and cloud accounts are watched without interruption. There are no office hours here — attacks don't keep them either.

    SOC
  • 02
    SIEM & Log Collection

    Wazuh 4.x at the core: log analysis, file integrity monitoring and correlation. Open-source, so we can read the rules, audit them and tune them to you.

    SIEM
  • 03
    AI-Triaged Alerts

    Every alert is read first by an AI model that scores severity, joins context and silences noise. Only what's real reaches a human — within minutes.

    AI
  • 04
    Vulnerability & Patch

    Continuous CVE detection and CIS configuration assessment across every endpoint. Missing patches are an attacker's favourite door; we schedule and report the closing.

    XDR
  • 05
    Active Response

    Obvious attacks are contained automatically: SSH brute force and web attacks are firewall-dropped on sight. Destructive actions always pass a human checkpoint.

    SOAR
  • 06
    Monthly Reporting

    What happened, what we did, what's next — in plain language. Including the evidence trail you need for KVKK and Turkey's Cyber Security Law No. 7545.

    REPORT
+FIG.01 — MONITORING LAYERS

REAL
THREAT & SCENARIOS

01

Pre-Ransomware Signals

Ransomware never arrives alone. Unauthorised sessions, suspicious PowerShell and backup deletion attempts come first — the goal is to stop it before encryption starts.

02

Compromised Accounts

Logins from unusual countries, impossible travel, rogue mail forwarding rules — the first signs of a Microsoft 365 breach.

03

Brute Force on Servers

Password spraying against internet-facing RDP and SSH. Detected, blocked, and the source reported.

04

Web Application Attacks

SQL injection, upload abuse and admin panel scanning, correlated across firewall and SIEM at the same time.

05

Insider Data Leakage

Bulk file copying, USB transfers and out-of-policy sharing, flagged by DLP rules.

06

Blind Spots & Silence

When a server stops sending logs, that is an alert too. Silence is often the most dangerous signal.

WAZUH SIEM · 24/7 SOC · AI TRIAGE · VULNERABILITY MGMT · ACTIVE RESPONSE · KVKK · LAW 7545 · MITRE ATT&CK · 
28+Detection rules mapped to MITRE ATT&CK
8Integrated tools in one operator console
<5minMedian AI triage time per alert
24/7Continuous monitoring and response

ANTIVIRUS
ISN'T · ENOUGH

++FIG.02 — OPERATOR CONSOLE

Antivirus stops known malware. Most of today's intrusions walk in through the front door with a stolen password, looking like a normal user.

So the answer isn't buying another product — it's having someone watching. Collecting the records, making sense of them, and picking up the phone when something is wrong, whatever the hour.

113SEC builds that at SMB scale: enterprise SOC discipline made affordable through open-source cores and AI. Our own MSP platform binds every tool into one screen — and you see the same screen we do.

Every customer is fully isolated with their own data. We show you exactly what we monitor, which rule fired and why an alert was raised. No black boxes.

More detail: what a SOC is and how 24/7 monitoring works · Turkey's Cyber Security Law 7545 · the stack we run.

REQUEST A FREE ASSESSMENT ↗

FREQUENTLY
ASKED · QUESTIONS

  • 01
    What exactly does a managed security service include?

    24/7 SOC monitoring, SIEM log collection, AI-assisted alert triage, vulnerability and patch management, automated active response and monthly reporting. Incident response is included when something does happen.

  • 02
    We already have antivirus — do we still need this?

    Yes. Antivirus stops known malicious files; it does not see an attacker who signs in with a stolen password and uses legitimate tools. SOC monitoring watches behaviour, not just files.

  • 03
    Does an SMB really need 24/7 monitoring?

    Most attacks find small companies through untargeted automated scanning, and a large share of ransomware cases start at night or over the weekend. Continuous monitoring exists precisely for those hours.

  • 04
    Does Turkey's Cyber Security Law No. 7545 apply to us?

    Scope depends on your sector and whether you fall under critical infrastructure. Either way, monitoring records, an incident response plan and reporting serve you under KVKK. We assess your specific position during the free consultation.

  • 05
    How long does onboarding take, and will it disrupt us?

    A typical SMB onboarding takes 5-10 working days. Agent installs are scheduled outside working hours, and any server restart is agreed with you in advance.

  • 06
    Does it work with our existing firewall and systems?

    Yes. We collect logs from Sophos, FortiGate, Cisco Meraki and OPNsense devices, plus cloud services such as Microsoft 365 and AWS. You don't need to replace hardware.

"YOU CAN BUY A SECURITY PRODUCT. YOU CANNOT BUY ATTENTION — IT IS RENTED."

HAND OVER
SECURITY

FREE ASSESSMENT ⟶