Security Operations Centre

Cyber Security tailored to your business

TL_Defensive_Managed Detection and Response_Image

Managed Detection & Response

Trust our team of experts to defend your systems and data around the clock, 24x7, every day of the year.

Schedule a chat with our specialist and solution architect to determine the best services for your current level of security and your cyber set-up.

SOC Services tailored to your business

DefenceShield 543 x 571 - 4

Monitor

This service provides the core to the Managed Detection and Response service portfolio, 24x7x365 monitoring.

Our team deploys a Security Information and Event Management (SIEM) solution, which provides endless telemetry from various devices and brings together information from across your systems and paints a picture of what ‘normal’ looks like and lets us know if there is something out of the ordinary happening.  

Includes:   

  • Service Delivery   
  • All in one pricing including SIEM licensing 
  • 24x7x365 Monitoring   
  • Optional Response capabilities 
  • Threat Intelligence   
  • Log Storage to meet compliance requirements 
  • Deception Technology 
DefenceShield 543 x 571 - 2

Assess

Our assess service regularly scans your whole network to look for vulnerabilities in your technologies.

Our experienced team review the outcomes with you and build remediation plans.

Without a Vulnerability Management service such as this, you’re not going to be aware of issues such as missing patches or misconfigurations an attacker could be targeting. 

Includes: 

  • Service Delivery
  • Schedule Vulnerability Assessments
  • Configuration of the vulnerability scanning solution, goals and remediation process
  • In depth analysis of all results to provide remediation plans
  • All in one licencing
  • Deployment support and guidance 
DefenceShield 543 x 571 - 8

Protect

Where security threats are identified and triaged, the Triskele Labs SOC will act where agreed and possible to remediate the threat.

This will occur through the tools Triskele Labs will have access to including EDR, Mail Gateway and SIEM. 

Includes: 

  • Service Delivery  
  • 24x7x365 Monitoring and Remediation  
  • Response Change Approval 
DefenceShield 543 x 571 - 11

Advanced

We build a suite of playbooks based on your organisation’s unique situation, and our technology takes an automated action based on the threat.

Our Advanced service involves our Security Orchestration Automation & Response (SOAR) platform, integrated tightly into our Security Information and Event Management (SIEM) and your existing infrastructure. 

 Includes: 

  • Targeted and subsequent Playbook Development
  • Ongoing Management of the SOAR Solution 
  • Monthly Reporting based on Playbook Executions
  • Response Change Approval  
DefenceShield 543 x 571 - 7

Hunt

Sometimes Threat Actors can dodge even the best monitoring systems, so our expert team of Threat Hunters use Endpoint Detection & Response (EDR) tools to find the needle in the haystack. 

Our Cyber Threat Intelligence (CTI) team are continually scouring for new threats and provide the Tactics, Techniques and Procedures (TTPs) to our team to conduct ongoing hunting.

Based on this, we build new customised detections to ensure we stay ahead of the game.  

Includes: 

  • Service Delivery 
  • Ongoing Threat hunting  
  • Detailed Reporting 

 

DefenceShield 543 x 571 - 3

Infiltrate

Led by the Red Team and defended by the Blue Team, our teams conduct ongoing, Adversary Simulation Activity aligned with the MITRE ATT&CK framework to ensure the relevant controls are in place.

Following the activities, our teams report if threats were identified or not.

Where threats were not identified, detection rules will be implemented, technology and logging permitting.  

Includes: 

  • Reporting of findings  
  • Ongoing Attack Simulation  
  • Purple Team 
DefenceShield 543 x 571 - 6

Intelligence

Our dedicated Cyber Threat Intelligence (CTI) team is continually identifying new indicators of compromise, clues that point to a data breach, and TTPs to find out what is being used in the wild. 

Includes: 

  • DefenceShield Service Delivery
  • DarkWeb Monitoring
  • Phishing Domain Monitoring
  • Shodan checks
  • Monthly Intelligence Report  
DefenceShield 543 x 571 - 12

WhiteGlove 

Our WhiteGlove service provides Incident Response and Containment services, for an event where a Threat Actor has managed to compromise a host(s) and gain persistence, move laterally or otherwise further compromise the network.

The WhiteGlove team will be initiated to commence investigation into the origins of the attack, it’s root cause if possible and any potential or actual impact, along with recommendations regarding next steps. 

  • Service Delivery 
  • Major Incident Response Team Formation Time 
  • Major Incident Response Team Composition  
DefenceShield IR 543x571

Incident Response

Unfortunately, cyber security attacks happen all the time, which is why we’re always watching.

If a Threat Actor does manage to get through your security, we’re ready to respond instantly

Our teams will be immediately deployed to contain the incident, mitigate any potential damage and identify exactly what happened, all while keeping you informed every step of the way.

Get in touch

If you’d like to discuss Security Operations Centre services, and how it might work for your organisation, drop us a line.

 

Certifications

Certification_Deffensive_Network+logo

 

Certification_Deffensive_Security+logo

 

Certification_Deffensive CySA+logo

 

Certification_Deffensive_GASFlogo

 

Certification_Deffensive_GREMlogo

 

Certification_Deffensive_GCIHlogo

 

 

 

Certification_Deffensive_GPENlogo

 

Certification_Deffensive_GCTIlogo

 

Certification_Deffensive_GSEClogo

 

Certification_Deffensive_GCFElogo

 

Certification_Deffensive_GCFAlogo

 

Certification_Deffensive_BlueTeamlogo

 

 

 

Knowing the Triskele Labs team are monitoring other customers in our industry, along with several others, gives us the confidence they are up to date with the latest tactics and deploying detections to protect us from emerging threats.
Kamran Channa
Chief Information Officer – Latrobe Health Services

Trusted by organisations Australia-wide