Managed security services

24/7 Microsoft security operations, without building a SOC.

Monitoring, detection, and incident response for Microsoft 365 and Azure, run by senior analysts in the EU. Four services that build on each other, from platform engineering to a fully outsourced security function.

Runs on Microsoft licenses you already own EU and Nordic operations Senior analyst on every incident For organisations from 50 users
15min
Analyst reaction time
To take ownership of a high-severity alert
30-40%
Sentinel cost reduction
Typical ingestion savings after tuning
70%
Fewer false positives
Typical drop after our detection tuning
3-4wks
To live monitoring
From first call to active protection
Services

Four services, one accountable partner

Each tier maps to how much security capability you keep in-house. Start where the need is greatest; every service builds on the one below it.

Most popular

Managed Detection & Response

Your security operations centre, fully outsourced: monitoring, investigation, containment, and threat hunting. Tiers run from business-hours analyst support (Essential) to full human response with a DFIR retainer (Elite).

15-min reaction on high-severity alerts Essential · Professional · Elite tiers
Start here if

You have no security team, or no coverage outside office hours.

What’s included
  • Everything in Managed Sentinel
  • Continuous analyst monitoring and triage
  • Incident response and containment
  • Proactive threat hunting
  • Forensics and executive reporting

Managed Sentinel

SIEM platform, expertly run

We architect, tune, and run Microsoft Sentinel: detection engineering, automation, and cost control. Your team keeps triage, investigation, and response.

  • Workspace architecture and deployment
  • Custom KQL detection rules
  • Alert tuning and false-positive reduction
  • Ingestion cost optimisation
  • Automation playbooks
30-40% typical ingestion cost cut Start here if

You have analysts, and the platform is eating their time.

Service details

M365 Security Management

Continuous tenant hardening

Your Microsoft 365 tenant is the business foundation. We keep it hardened, catch configuration drift, and improve posture quarter over quarter.

  • Secure Score monitoring and optimisation
  • Configuration drift detection and remediation
  • Conditional Access policy management
  • DLP and sensitivity label maintenance
  • Quarterly posture reviews
Secure Score held above 80 Start here if

An assessment found gaps and you want the fixes to stick.

Service details

CISO as a Service

Security leadership, fractional cost

Strategy, risk, compliance, and board reporting from an experienced security leader, at a fraction of a full-time hire.

  • Security roadmap and policy development
  • Risk assessment and register management
  • GDPR, ISO 27001, and NIS2 programme guidance
  • Board and executive reporting
  • Vendor risk oversight
Pairs with MDR for a full security function Start here if

Auditors, customers, or the board are asking questions nobody owns.

Service details
How they fit

Integrated protection across your Microsoft environment

Each layer builds on the one below. Start where you need to; we help you pick the right entry point.

vCISO
CISO as a Service
Roadmap · Risk · Policy · Board reporting
Leadership
MDR
Managed Detection & Response
Monitoring · Investigation · Response · Hunting
Operations
SIEM
Managed Sentinel
Log collection · Detection rules · Automation · Cost control
Platform
M365
M365 Security Management
Email · Identity · Data protection · Compliance
Foundation
Yours
Your Microsoft environment
Infrastructure

Layered protection

M365 Management hardens the foundation. Sentinel provides the detection platform. MDR adds analysts for response. vCISO sets direction.

Flexible starting points

Some start with tenant hardening, add Sentinel, then move to MDR. Others need full coverage immediately. Start where the need is greatest.

Combinations that work

vCISO with MDR outsources the whole security function. Sentinel with M365 Management pairs platform expertise with a hardened tenant.

Not sure where to start? The free review tells you.

Book a free security review
When we find something

What happens when we detect a threat

No black box and no alert dumps. Every detection follows the same lifecycle, and you decide how much of the response we execute.

01
Detect

Custom detections across Sentinel and Defender fire on real attacker behaviour.

02
Engage

An analyst takes ownership of every high-severity alert.

≤ 15 min reaction
03
Investigate

True positive or false positive decided; scope, timeline, and blast radius established.

04
Contain

Sessions revoked, devices isolated, accounts disabled, per your MDR tier.

05
Report

Plain-language incident report with remediation guidance.

A senior analyst signs off on every incident, at every authority level.
Level 1

Notify

We investigate, you contain.

Automated detection with business-hours analyst support. We triage, investigate, and escalate confirmed incidents to your team with remediation guidance.

  • Alert triage and deep-dive investigation
  • Escalation with remediation guidance
  • Your team executes containment
TierMDR Essential
CoverageBusiness hours
ChannelEmail and ticket
Level 2

Approve

We contain on your go-ahead.

Extended coverage with hands-on containment. We detect, investigate, and stage the response, then execute the moment you approve on the dedicated channel.

  • Active containment by our analysts
  • Weekly proactive threat hunting
  • Response playbooks: isolation, revocation, containment
TierMDR Professional
Coverage15 hours/day
ChannelDedicated Teams or Slack
Level 3

Act

We contain immediately.

Full human response with a named analyst and a DFIR retainer. For high-severity incidents we act first, under an authority matrix agreed at onboarding, then walk you through what happened.

  • Pre-authorised full containment
  • DFIR: 10 hours per month included
  • Regulator-ready incident reporting (GDPR, NIS2)
TierMDR Elite
Coverage24/7 human response
ChannelNamed analyst, priority escalation

Response authority follows your MDR tier and is agreed per action type at onboarding. Managed Sentinel is platform engineering only: triage and response stay with your team.

Data sovereignty

EU operations. Your data stays in your tenant.

Most managed detection providers route your telemetry through their own cloud, often outside the EU. We work inside your Microsoft tenant instead, from operations based in Sweden.

OperationsEU / Nordic
Data residencyYour Sentinel workspace
AccessScoped · Revocable · Logged
FrameworksGDPR · NIS2

EU and Nordic operations

Operated from Sweden with EU-based senior analysts. Timezone-aligned, jurisdiction-clear.

Data never leaves your tenant

Logs, alerts, and incident records stay in your Sentinel workspace and Microsoft 365 estate. Nothing is copied to a third-party platform.

Scoped, auditable access

We work through delegated access you grant and can revoke. Every action we take is logged in your tenant.

GDPR and NIS2 aligned

Monitoring, reporting, and incident handling mapped to the obligations your auditors ask about.

Compare

Find your tier

MDR is where most organisations land. Keep analysts in-house? Start with the platform. Worried about posture? Start with the tenant.

Capability
Managed Sentinel You respond
Recommended MDR We respond
M365 Management Posture upkeep
CISO as a Service Leadership
SIEM & detection
Sentinel deployment & architecture · ·
Custom KQL detection rules · ·
Alert tuning & optimisation · ·
Ingestion cost optimisation · ·
Security operations
Continuous SOC monitoring · · ·
Alert triage & investigation · · ·
Incident response & containment · · ·
Proactive threat hunting · · ·
Microsoft 365 security
Secure Score monitoring & optimisation · ·
Configuration drift detection · ·
Conditional Access management · ·
DLP & sensitivity labels · ·
Strategy & governance
Security roadmap development · · ·
Risk assessment & management · · ·
Policy development · · ·
Board & executive reporting · · ·
Compliance guidance (GDPR, ISO 27001, NIS2) · ·
Response authority Your team Notify to act, by tier · Advisory
Best for Teams with analysts who need platform expertise Teams without internal security or out-of-hours coverage Keeping a hardened tenant hardened after an assessment Strategic leadership, compliance, and board reporting
Managed SentinelYou respond
Best for

Teams with analysts who need platform expertise

SIEM & detection
  • Sentinel deployment & architecture
  • Custom KQL detection rules
  • Alert tuning & optimisation
  • Ingestion cost optimisation
Response authorityYour team
MDRWe respond
Recommended
Best for

Teams without internal security or out-of-hours coverage

SIEM & detection
  • Sentinel deployment & architecture
  • Custom KQL detection rules
  • Alert tuning & optimisation
  • Ingestion cost optimisation
Security operations
  • Continuous SOC monitoring
  • Alert triage & investigation
  • Incident response & containment
  • Proactive threat hunting
Microsoft 365 security
  • Secure Score monitoring & optimisation
  • Configuration drift detection
  • Conditional Access management
  • DLP & sensitivity labels
Response authorityNotify to act, by tier
M365 ManagementPosture upkeep
Best for

Keeping a hardened tenant hardened after an assessment

Microsoft 365 security
  • Secure Score monitoring & optimisation
  • Configuration drift detection
  • Conditional Access management
  • DLP & sensitivity labels
Strategy & governance
  • Compliance guidance (GDPR, ISO 27001, NIS2)
CISO as a ServiceLeadership
Best for

Strategic leadership, compliance, and board reporting

Strategy & governance
  • Security roadmap development
  • Risk assessment & management
  • Policy development
  • Board & executive reporting
  • Compliance guidance (GDPR, ISO 27001, NIS2)
Response authorityAdvisory

Monthly after a 90-day initial term. No multi-year lock-in.

Onboarding

Live monitoring in weeks, not months

Most organisations go from first conversation to active protection in 3 to 4 weeks.

1 Week 1

Security consultation

A free 30-minute call about your environment, posture, and requirements. We recommend a tier. No pressure, no obligation.

2 Weeks 1-2

Environment assessment

Technical review of your Microsoft estate. For MDR this sets the baseline we monitor. For Managed Sentinel it scopes the optimisation work.

3 Weeks 2-4

Service deployment

We deploy monitoring, configure detections, and establish escalation channels, with a dedicated onboarding contact throughout.

4 Ongoing

Continuous improvement

Detections tuned, costs optimised, coverage expanded. Monthly reports and quarterly reviews keep the service improving.

30min
First consultation
3-4wks
To active protection
90days
Then month to month
The alternative

Compare it with building your own SOC

Continuous coverage in-house means a team, tooling, and a year of standing up. The managed route costs a fraction of one hire.

Build in-house
  • Four to six analysts to staff continuous coverage
  • Roughly €90-120k per senior security hire, per year
  • Six to twelve months to recruit, tool, and reach steady state
  • Training, turnover, and tooling costs on top
Falconer managed services
  • A fraction of the cost of one security hire
  • Senior analysts from day one
  • Runs on Microsoft licenses you already own
  • Live in weeks, month to month after 90 days
From a cost review One customer’s Sentinel ingestion bill dropped 58% after our first optimisation pass.
Read the cost breakdowns on the blog

Professional, spot-on, and personal. Their consultants give the concise answers we need and proactively bring in valid points to strengthen our monitoring and setup on Managed Sentinel and Microsoft MDR.

Coen Smiers Project Manager, Rods & Cones
Verified on GoodFirms
FAQ

Common questions

What is the difference between Managed Sentinel and MDR?

Managed Sentinel means we run and optimise your SIEM platform: architecture, detection rules, tuning, and cost control. Your analysts handle triage, investigation, and response. MDR means we handle the whole lifecycle: monitoring, investigation, containment, and reporting.

Do we need Sentinel to use MDR?

No. Sentinel is our detection platform and we deploy it as part of MDR onboarding. If you already run it, we optimise your existing workspace instead.

How much response authority do you take?

You decide, by MDR tier. Essential customers get investigated, validated incidents and keep containment in-house. Professional adds hands-on containment by our analysts. Elite adds pre-authorised full containment with a DFIR retainer, agreed per action type at onboarding. Managed Sentinel is platform engineering only, so detection outcomes stay with your analysts.

Can we start with one service and upgrade later?

Yes. Many clients start with an M365 security assessment, add Managed Sentinel, then move to MDR as needs evolve. The services are designed to build on each other.

How quickly can we get started?

Most organisations are live within 3 to 4 weeks: consultation in week one, environment assessment across weeks one and two, active monitoring by week four.

Do you require long-term contracts?

No. Managed services run on a 90-day initial term, then month to month. Assessment services are one-time engagements with no ongoing commitment.

Where is our data processed?

Inside your own Microsoft tenant. Logs and incident data stay in your Sentinel workspace; we operate with scoped, auditable access from the EU.

Contact

Tell us what you’re dealing with

A Microsoft security specialist reads every message and replies, usually within one business day. Whether you need monitoring, help with a specific tool, or just have a question, start here.

New to this? Ask about a free Microsoft security review as a starting point.

What we can help with
  • Managed detection and response
  • Microsoft Sentinel engineering
  • Identity and email security
  • A free Microsoft security review
1You send a message
2A specialist replies within a business day
3We set up a call to scope what you need

"*" indicates required fields

This field is for validation purposes and should be left unchanged.