Under attack?
Support and operations

Operational and security
maintenance

A detection platform degrades quietly: sources that stop reporting, rules that drift, indexes that fill up. Operational maintenance stops that erosion; security maintenance keeps the detection relevant.

  • SIEM
  • SOAR
  • UEBA
  • Capacity planning
  • Use case tuning
The observation

The most dangerous failure is the one that makes no noise

When a server goes down, everyone knows. When a log source stops reporting, nobody notices — until the day someone looks for a trace that was never collected.

Operational maintenance addresses that category of failure: the ones that trigger no user complaint but gradually open blind spots in your coverage.

Silent source

A device stops reporting. Caught by a dedicated rule, tuned to the expected level of verbosity.

Parsing drift

A format change breaks field extraction. The rules no longer match.

Index saturation

Actual retention falls below the contractual or regulatory retention.

Stale rules

Use cases no longer cover the attack techniques actually being observed.

Two complementary strands

Operational and security maintenance

Operational maintenance

The platform runs and collects what it is meant to collect.

  • Day-to-day maintenance of the SIEM, SOAR and UEBA platforms
  • Administration: access, permissions, service accounts and collection interfaces
  • Log source monitoring and detection of missing feeds
  • Change management on event and alert sources
  • Capacity planning, corrective and evolutive maintenance
  • Backup and restore, coordinated with your teams
  • Qualification and tracking of production incidents through to resolution

Security maintenance

The platform detects what it is meant to detect.

  • Building detection use cases: rules, dashboards, reports
  • Continuous improvement and tuning of existing use cases
  • Periodic review of how relevant the current rules remain
  • Aligning coverage with the MITRE ATT&CK matrix
  • Reducing false positives and non-actionable alerts
  • Onboarding new perimeters and new sources
Detecting collection loss

One rule per source profile

Not all sources have the same rhythm. A firewall going quiet for a few minutes is a signal; a peripheral device silent for a day may be perfectly normal.

Continuous sources

Firewalls, proxies, domain controllers. A permanent flow is expected: any interruption is caught quickly.

Regular sources

Application servers, databases. Throughput varies with activity; the threshold accounts for quiet hours.

Episodic sources

Peripheral devices, standby systems. A long silence is normal; only a sustained break is escalated.

Trigger thresholds are derived from the behaviour actually observed across your estate during the observation phase, then adjusted over time.

Delivery models

Remote, on site, or both

Remote support

Our teams work from Côte d’Ivoire and Morocco, with service windows and response times agreed in the contract.

Dedicated resource on site

A resource based in your offices for hands-on work, changes and infrastructure upgrades, working alongside your teams.

Hybrid model

An on-site presence for sensitive operations, backed by remote support for routine maintenance and on-call cover.

Who does what

Every maintenance contract opens with an explicit split of responsibilities: what we administer, what you decide, what requires your approval. That document is what prevents the grey area in which incidents get stuck.

Your platform deserves an audit

We review the real state of your SIEM: active sources, detection coverage, configuration debt. The starting point for any maintenance contract.