Mira Albers
SOC Lead, L3
GCIH · GCFA · 9 yrs
KEEL MDR
24/7 detection and response by analysts in Kiel, on your existing tools. Live in 14 days.*
01 / HOW TRIAGE WORKS
01 · Events · 24 h
2.18 bn
Illustrative · 24 h sample, 2026-09-23
01 · Events
Endpoint, identity, cloud, email and network telemetry flows into our platform in Frankfurt. Billions of events a day, normalized and enriched with threat intelligence.
02 · Alerts
Detection rules mapped to ATT&CK and tuned to your environment. We suppress known-good behavior with you during onboarding, so alerts mean something.
03 · Incidents
L1 and L2 analysts investigate each alert with full context. Fewer than 2% of what reaches you turns out to be a false positive (illustrative).
04 · Contained
Pre-authorized actions like host isolation and account lockout start within minutes. You get a call, a T+ timeline and clear next steps.
02 / SLA ON T+ TIME
| SEVERITY | TRIAGE | YOU'RE NOTIFIED | CONTAINMENT STARTED | CHANNEL |
|---|---|---|---|---|
| Critical | ≤ 00:10 | ≤ 00:15 | ≤ 00:20 | Phone + console |
| High | ≤ 00:20 | ≤ 00:30 | ≤ 00:45 | Phone + console |
| Medium | ≤ 01:00 | ≤ 04:00 | next business day | Console + email |
| Low | ≤ 08:00 | weekly digest | as agreed | Monthly report |
03 / DETECTION COVERAGE
Initial Access
Execution
Persistence
Privilege Esc.
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact
Illustrative · simplified tactic set · coverage validated by purple-team exercises, 2026-08
04 / INTEGRATIONS
We connect to the EDR, identity, cloud and email security you already own. No rip-and-replace, and your logs stay in Germany.
05 / ANALYSTS & SHIFT MODEL
SOC Lead, L3
GCIH · GCFA · 9 yrs
Threat Hunter
GREM · OSCP · 7 yrs
SOC Analyst, L2
BTL1 · GCIA · 4 yrs
See it yourself: a 45-minute guided tour of our SOC in Kiel, in person or remote.
Book a SOC tour06 / SAMPLE REPORT
A redacted real report: executive summary, incidents on T+ timelines, coverage changes and recommended actions. 14 pages.
Download redacted sample (PDF, 2.1 MB)07 / PRICING
Excl. VAT · min. 100 endpoints · 12-month term · illustrative
€6 / endpoint / month
Detection and triage on your EDR, 24/7.
€9 / endpoint / month
Adds active response and identity coverage.
€13 / endpoint / month
Full coverage including cloud and IR hours.
08 / IN-HOUSE VS. MANAGED
| Criterion | IN-HOUSE 24/7 SOC | KEEL MDR |
|---|---|---|
| Annual cost | ≈ €780,000 (8 FTE + tooling) | ≈ €108,000 (Standard) |
| Time to operational | 9–18 months | 14 days |
| Night & weekend coverage | Hard to staff, high turnover | Included |
| Detection engineering | Your team | Shared across 180+ clients |
| Incident response | Separate contract | Included from Standard |
| Data location | Your choice | Germany |
Illustrative estimate for 1,000 endpoints, Germany, 2026. Staffing: 8 FTE for 24/7 coverage incl. leave.
09 / FAQ
No. We integrate with the EDR, identity and cloud security you already use. If you have no EDR, we can provide one as part of the service.
In ISO/IEC 27001-certified data centers in Frankfurt and Nuremberg. Analysts work from our SOC in Kiel. No data leaves the EU.
Every alert is investigated by an analyst before it reaches you. During onboarding we tune detections to your environment. Fewer than 2% of escalations are false positives (illustrative).
A kickoff, connector setup with your IT team (typically 6–10 hours of your time), a 7-day tuning phase and go-live. Live in 14 days on average (illustrative).
12 months, then monthly cancellation. A free 30-day pilot on up to 250 endpoints.
Most insurers ask for EDR, 24/7 monitoring, MFA and tested backups. Keel MDR covers the monitoring and response part; we document it for your insurer.