Three routes to 24x7 cyber defence

All three models use the same platform, the same use cases and the same analysts. They differ in who carries operational responsibility and how much of your own staff you deploy.

The models side by side

Managed SOC
Co-Managed Cyber Defence
MDR & Managed Capacity
24x7 responsibility
Fully with CyStrat — monitoring, triage and escalation around the clock.
Shared: CyStrat covers nights and weekends, your team the core hours.
With you — CyStrat supplies analyst capacity on demand.
Platform & tooling
CyStrat SOC Suite including SIEM, threat intelligence and SOAR.
CyStrat SOC Suite or your existing SIEM, operated jointly.
Your existing stack stays in the lead; we work inside it.
Own staff required
One point of contact is enough.
A small security team covering core hours.
An existing team lacking capacity or specialist knowledge.
Use-case development
By CyStrat, aligned to your risks.
Jointly — your team knows the applications, we know detection.
On demand, for example as a use-case sprint or review.
Response depth
Triage, containment and agreed countermeasures — a human decides.
Containment after agreed approval, hand-over to your team documented.
Analysis and recommendation; implementation stays with you.
Time to go live
Weeks — onboarding of log sources sets the pace.
Weeks, depending on your existing SIEM.
Days, once access and scope are clear.
Typical fit
Organisations without their own SOC team and with clear compliance requirements.
Organisations with a security team that cannot carry 24x7 alone.
Teams with bottlenecks: leave, vacancies, project peaks or incidents.

Decision guide in three questions

You have no SOC team of your own?

The managed SOC is the direct route: we take over monitoring, triage and escalation around the clock while you keep authority over intrusive measures.

View managed SOC

You have a team but no night coverage?

Co-managed cyber defence splits the shifts: your team works core hours, we cover nights, weekends and public holidays — on a shared platform.

View co-managed

You are short of capacity or specialist knowledge?

The MDR & managed capacity service provides analyst capacity inside your existing stack — no platform change and no long lead time.

View managed capacity

Unsure which model fits?

In a short call we clarify coverage, responsibility and effort — with no sales pressure.

Request a call

Want to check your maturity first? Start the security check

Frequently asked questions

Answers on choosing an operating model.

Can we switch models later?
Yes. Platform, use cases and documentation stay the same, so moving between co-managed, managed SOC and the capacity service works without rebuilding.
What is the difference between co-managed and managed capacity?
Co-managed is a permanent split of shifts with committed coverage. The managed capacity service supplies analyst capacity on demand without taking over operational responsibility.
Do we have to replace our SIEM?
No. Co-managed and managed capacity work inside your existing SIEM. The CyStrat SOC Suite is an option, not a prerequisite.
How quickly can a model start?
The managed capacity service starts within days. Managed SOC and co-managed take a few weeks because onboarding log sources sets the pace.
Does an AI decide on countermeasures?
No. AI components enrich, pre-assess and prepare measures. The decision on intrusive steps is always made by an analyst.

Your question is not listed? Ask us