Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Managed security

Managed SIEM and log monitoring for the sources that matter.

F Creative Studio 360 helps organisations in any country collect, keep and use security logs. You can keep the platform. We do not publish a universal response time.

A SIEM is only as useful as the logs inside it.

Common platforms include Microsoft Sentinel, Splunk and IBM QRadar. Detection ideas can be mapped to MITRE ATT&CK. None of those products is required.

What the work covers

Sources
Which systems send logs, and which critical systems are still silent.
The pipeline
How logs are collected, parsed and kept, including where they are stored.
Detection content
The rules and correlations that match the organisation, not a default pack left untouched.
The handoff
Who receives an alert. Triage and hunting are a monitoring or detection engagement, not this one, unless written in.

How an engagement runs

  1. 1

    Name the platform

    The SIEM you already run, or the one you have chosen. F Creative Studio 360 does not require Microsoft Sentinel, Splunk or QRadar.

  2. 2

    Name the sources

    Identity, endpoints, cloud and the applications that matter. A plant or a payment system is included only when you put it in scope.

  3. 3

    Set retention and residency

    How long logs are kept, and in which country, is a contract term. It is not a number we publish for every client.

  4. 4

    Hand back the gaps

    Missing sources, noisy rules and a pipeline that would not support an investigation.

What you receive

  • A list of sources in scope, and the ones still missing.
  • A note on parsing, retention and where the logs reside.
  • Detection content you can keep after the engagement.
  • No claim of a universal response time, and no containment unless it is written in.

Common questions

How is this different from SOC monitoring?+

This work is the log platform: sources, parsing, retention and detection content. SOC monitoring is the people who triage what that platform raises. They can be scoped together, and they are not the same service.

How is this different from managed detection and response?+

Managed detection adds hunting and containment that you have agreed in advance. A SIEM engagement does not contain an incident unless that action is written into the contract.

Do we have to move to your platform?+

No. The usual engagement is the platform you already license. A new platform is recommended only when the current one cannot hold the sources you need.

Where do you do this?+

For organisations in any country. Log residency is agreed in the scope. A local rule is added only when that organisation is subject to it.

Start with the logs you already have.

F Creative Studio 360 will look at the platform and the sources, then say what a sensible engagement includes. There is no obligation to proceed.