24/7 monitoring
We monitor your infrastructure — day and night.
NIS-2 · MANAGED SOC
The NIS-2 reporting period begins as soon as you become aware of a significant security incident. Cypurge Managed SOC detects threats 24/7, while our consultants support you in implementing the remaining NIS-2 obligations.
SECURITY MONITORING
24/7/365
SCOPE
NIS-2 applies to medium-sized and large entities in one of the sectors covered by the Directive. National requirements vary by country.
Certain covered entities are subject to NIS-2 regardless of their size.
Not sure if you are in scope? Ask our experts50 or more employees
or over €10M in both turnover and balance sheet total
In force in Germany since 6 December 2025 — with no transition period
REPORTING OBLIGATION
Under § 32 BSIG, significant security incidents must be reported in three stages. Early detection limits the damage — and gives your team the information it needs for timely reporting.
Incident notification
Status report
after the status report: final report
Late detection
Monday, 08:15 — the attacker has had the whole weekend.
Early detection
Friday, 17:45 — your team contains the incident before it spreads.
02:00:00
SUNDAY · ACTIVE MONITORING
Anyone building 24/7 detection in-house needs at least five to six analysts, clear processes, infrastructure and seamless shift schedules.
Internal team
Managed SOC
We monitor your infrastructure — day and night.
We detect threats early — giving your team time.
Following an agreed escalation plan, we notify the right contacts — even at night.
Every incident raises your security level.
HOLISTIC IMPLEMENTATION
NIS-2 also requires risk analysis, policies, business continuity, supply-chain security, training and more. Cypurge closes the remaining gaps with security consulting.
Start your NIS-2 assessment
We identify your NIS-2 gaps.
You receive a prioritised action plan with effort and timeframe.
Continuous monitoring, detection and escalation.
Regular evaluations keep your security level up to date.
Management must approve the risk-management measures, oversee their implementation and participate in training. Liability is governed by the applicable corporate-law provisions.
No. A SOC covers detection and part of incident handling. Risk management, business continuity, supply chains and training remain your responsibility — and we support you with them.
As soon as your entity becomes aware of a significant security incident.
No, the law does not require an in-house SOC. A Managed SOC provides 24/7 monitoring without requiring you to recruit and retain a team.
Request your quote for the Cypurge Managed SOC, or start with a NIS-2 assessment to see where you stand.
Managed SOC and security consulting from one provider
Thank you. A Cypurge expert will contact you shortly.