Sources
Firewalls, EDR, Entra ID sign-ins, Microsoft 365, domain controllers, servers and key applications.
Security tools write events all day long, yet rarely does anyone read them: logs get opened after an incident, not before. Monitoring reverses that logic, so suspicious activity is spotted while there is still time to step in.
Monitoring makes sense once there is something to monitor: security tools and logging first, then the watch on top.
Firewalls, EDR, Entra ID sign-ins, Microsoft 365, domain controllers, servers and key applications.
Single events look harmless on their own, but together they sketch an attack: a sign-in from abroad, a new forwarding rule and a mass download from SharePoint.
Rules tuned to your environment plus a library of known attack techniques, for example from MITRE ATT&CK.
Who is contacted, what is shut down, in which order and with whose approval.
How they got in, what they reached and what must change so it does not happen again.
Help with early warnings and notifications under NIS2, and to Datatilsynet if personal data is affected.
Onboarding takes from two weeks to a month, and nearly all of that time goes on fitting the rules to your environment.
Which systems produce useful logs, and what can be extracted from them.
Logs are sent to a central platform such as Microsoft Sentinel and brought into a common format.
In the first weeks false alarms are removed, otherwise the real ones drown in noise.
Continuous monitoring, alerts according to the runbook and monthly reports.
Monitoring without the authority to act is pointless. At three in the morning the analyst sees an attack, may not shut the server down and has no one to call. The list of contacts with phone numbers and decision rights is drawn up during onboarding, not after the first incident.
The basics: logging switched on, antivirus centrally managed, the perimeter closed and backups protected. Watching an unprotected environment merely records how you are being attacked.
Work it out from the cost of downtime and data leaks. Where IT mainly supports office work, solid basics and good backups are often enough. Where production would halt or customer data could leak, monitoring pays for itself with the first incident it prevents.
A named person on your side with the right to stop systems. That is a management question rather than a technical one, and it must be settled before onboarding.
Significant incidents require an early warning within 24 hours and a notification within 72 hours, followed by a final report. Monitoring supplies the timeline and technical details, but the report is filed in your name.
Describe your critical systems and roughly how much a lost working hour costs. You get a straight answer on whether monitoring pays off now or the groundwork comes first.
Thank you for getting in touch
One of our consultants already has it. Expect a reply within the working day; anything urgent goes straight to an engineer.
That city is not on our list. Check the spelling or pick the nearest larger town.