Skip to content

Managed operations

Remote SOC

Security event correlation, threat detection, incident response and reporting.

Architecture

Architecture

  1. 01CollectEndpoint, network, application
    • Wazuh agent
    • syslog
    • NetFlow
  2. 02Normalise
    • Vector
    • Graylog pipeline
  3. 03CorrelateDetection rules
    • SIEM rules
    • MITRE ATT&CK
  4. 04TriageFalse-positive filtering
  5. 05RespondContain and recover
    • Playbook
    • Forensics
Security event handling chain

Operator consoles

Operator consoles

These exact systems run on the group's own infrastructure — the screenshots are processed before publication.

Blurred FortiGate dashboard: session, memory and throughput graphs with security-fabric status.

The firewall — policy, sessions and load

A FortiGate in production: thousands of concurrent sessions, SPU load, security-fabric state and per-interface throughput on one screen. A firewall is not a separate box to us — it is designed and operated together with routing, segmentation and logging, by certified engineers.

FortiGateHAsegmentationIPsec
screenshot not supplied yetpublic/media/proof/paloalto-firewall.webpnpm run proof:blur
Palo Alto · PAN-OSblurred

Palo Alto — policy at the application layer

The PAN-OS platform: App-ID and User-ID level policy, logging and threat prevention. We have engineers certified on it; a deployment screen goes up here once a specific production environment is cleared for publication.

PAN-OSApp-IDUser-IDthreat prevention

Capabilities

Capabilities

Every item is marked: verified production experience, or engineering capability.

24/7 network monitoring

Proven

The group's own ISP and datacenter run continuously — same processes, same tooling.

  • Zabbix
  • Prometheus
  • Grafana

Severity-based incident response

Proven
  • Runbooks
  • On-call rota

SOC — event correlation

Capability

SIEM rules, detection content and incident response playbooks.

  • Wazuh
  • Graylog
  • OpenSearch

Co-managed mode

Capability

Your team keeps control; we cover the shifts and the escalation path.

ITSM integration

Capability

Two-way sync with your ticketing system.

  • Webhooks
  • REST API

Telegram / PagerDuty escalation

Proven
  • Telegram Bot API
  • Alertmanager

Path monitoring and loss detection

Proven

Latency and packet loss to every critical destination — including cache servers hosted inside individual operators. That is how you tell whether the fault is in our network, in transit, or at the content provider.

  • OpenPath
  • ICMP / TCP probes
  • per-ASN

Technology stack

Technology stack

Monitoring
ZabbixLibreNMSPrometheusGrafanaBlackbox
In-house tooling
OpenPathnoc.com.ge
Logging
GraylogOpenSearchLokiVector
Security
WazuhFortiGateSuricata
Alerting
AlertmanagerTelegramPagerDuty

Engagement model

Engagement model

Co-managed

NetWizard and your in-house team together, with split responsibility.

Fully managed

We own the agreed operational scope end to end.

Critical operations

24/7 monitoring, response and severity-based escalation.

Retainer

Monthly engineering hours — specialist access on demand.

FAQ

FAQ

How do you access our infrastructure?

Named accounts only, with MFA, logged sessions and agreed change windows. Details are in the Trust Center.

What SLA do you offer?

The SLA is defined per service plan: severity-based acknowledgement, response and escalation targets are fixed in the contract.

Can you work with our existing tools?

Yes. If you already run Zabbix, Prometheus, Grafana or a SIEM we operate on it, correcting the configuration where needed.

Tell us about your infrastructure