01
MANAGED SERVICES
As Asia's first Certification Authority, Netrust helps organizations protect, manage, and scale their digital environments with the right security strategy, not just tools.
WHAT WE OPERATE
A centralized team that monitors, detects, and responds to threats in real time. It is the backbone of your cybersecurity program. Scroll to move through all six capabilities.
01
Continuous Monitoring
02
Threat Detection
03
Incident Response
04
Threat Hunting
05
Vulnerability Management
06
Reporting & Compliance
01
A 24/7 watch across systems, endpoints, and network traffic. Nothing in your environment goes unobserved. Activity is collected and correlated around the clock.
02
Advanced tooling and threat intelligence surface malicious behavior as it happens, separating real signals from routine noise.
03
When something is confirmed, the team moves: isolating affected systems, blocking malicious activity, and resolving incidents quickly.
04
Analysts actively search for hidden or unknown threats that evade automated detection, using SIEM, EDR, and network data.
05
Weaknesses are identified, prioritized, and patched fast, which closes the gaps attackers look for before they are used.
06
Clear reporting on threats, affected systems, and actions taken. Evidence that meets your regulatory and internal standards.
01
/ 06
01 / THE PEOPLE
A strong SOC is only as effective as the people behind it. Each role plays a critical part in maintaining continuous protection.
SIX CORE ROLES
01
SOC Manager
Oversees operations, sets priorities, and coordinates the team.
02
Security Analysts (Tier 1–3)
Investigate alerts, respond to incidents, and perform threat analysis.
03
Incident Responders
Handle security breaches and take corrective actions.
04
Threat Hunters
Search for advanced or hidden threats in the environment.
05
SOC Engineers
Maintain and optimize SOC tools, platforms, and infrastructure.
06
Compliance Officers
Ensure SOC operations meet regulatory and internal standards.
LIVE OPERATIONS
Someone is watching your environment right now.
Tier 1 to Tier 3 coverage, every hour of every day.
RUN IT OR OUTSOURCE IT
IN-HOUSE SOC
Full control, more resources
Managed internally by the organization. It offers complete ownership of tooling, data, and process. It does demand headcount, 24/7 shift coverage, and continuous tuning to stay effective.
Own it. Or let us run it.
MANAGED SOC (MSSP)
Expert coverage, day one
Outsourced to Netrust for monitoring and incident response. You inherit trained analysts, mature playbooks, and round-the-clock coverage without building the function yourself.
OUR STACK
01
SIEM
Collects and analyzes logs from multiple systems to detect threats across your entire environment.
→
02
EDR
Protects and monitors endpoints like laptops, servers, and mobile devices in real time.
→
03
SOAR
Automates repetitive tasks and helps coordinate responses across security tools.
→
04
Threat Intelligence Platforms
Provides data about emerging threats and attack patterns to stay ahead of adversaries.
→
05
Firewalls & IDS / IPS
Control traffic and detect malicious activity before it reaches critical systems.
→
06
Monitoring & Dashboards
Centralized interface for tracking security events and alerts at a glance.
→
PLATFORM IN FOCUS
01 / 06
SIEM: Security Information & Event Management
WHAT IT GIVES YOU
Log correlation
Central visibility
Alerting
02 / MANAGED DETECTION & RESPONSE
MDR fuses 24/7 monitoring, intelligent detection, and expert analysts into a single managed service, and it combines advanced tooling with human expertise to stop attacks before they cause damage.
WHAT MDR DELIVERS
01
24/7 Monitoring
→
Endpoints
Network
Logs
02
Threat Engine
→
Behavioral analytics
Anomaly scoring
03
Incident Response
→
Isolate
Contain
Recover
04
Threat Intelligence
→
Updated detection data
Emerging patterns
05
Security Experts
→
Human validation
False-positive triage
A structured, repeatable process from data collection to full remediation that keeps your systems clean and your team informed.
01
Data Collection
Collect logs from endpoints, servers, and network devices.
02
Detection
Analyze data for suspicious behavior or compromise.
03
Investigation
Analysts review alerts to confirm real threats.
04
Response
Isolate affected systems or block malicious activity.
05
Remediation
Fix vulnerabilities and restore normal operations.
03 / DETECTION & RESPONSE LAYERS
From device-level protection to full enterprise visibility, each detection layer watches a different part of your environment, and together they compound.
THREE LAYERS
01
Endpoint Detection & Response
EDR
02
Network Detection & Response
NDR
03
Extended Detection & Response
XDR
DEVICE-LEVEL SIGNAL
"Unsigned process spawned from a user download folder on a finance laptop at 02:14."
Endpoint Detection & Response (EDR)
Focuses on detecting threats on devices like laptops and servers.
LAPTOPS
SERVERS
PROCESS TELEMETRY
Security is never one-and-done. The cycle keeps adapting as new threats emerge, here is what runs continuously behind your service.
✓ ALWAYS ON
Five steps that never stop running.
Every cycle feeds the next detection rule.
01
Continuous Monitoring
Track all activities across systems and networks.
02
Threat Hunting
Actively search for hidden or unknown threats.
03
Behavioral Analysis
Identify unusual patterns that may indicate attacks.
04
Rapid Response
Immediately contain and stop threats.
05
Continuous Improvement
Update detection rules and strategies for new threats.
04 MODELS
01
In-House SOC
Managed internally by the organization. Offers full control but requires more resources.
BEST FOR: LARGE ENTERPRISES
02
Managed SOC (MSSP)
Outsourced to a third-party provider for monitoring and incident response. Cost-effective for smaller teams.
BEST FOR: SMALL & MID-SIZE TEAMS
03
Hybrid SOC
Combination of internal staff and external services for flexibility and scalability.
BEST FOR: GROWING ORGANIZATIONS
04
Virtual / Cloud SOC
Cloud-based SOC that monitors and responds remotely. Offers scalability with less physical infrastructure.
BEST FOR: DISTRIBUTED & REMOTE
HOW WE START
A managed service should be running, not pending. Here is the path from first conversation to live coverage.
01
Scope & Baseline
We map your systems, data sources, and risk priorities, then agree the coverage model.
02
Deploy & Tune
Sensors and log sources are connected, detection rules tuned to your environment.
03
Operate & Report
Monitoring goes live with agreed response paths and regular reporting to your team.
GET IN TOUCH
Whether you are exploring cybersecurity solutions, looking for long-term security support, or interested in working with our team, we'd be happy to connect.
MOBILE
(+63) 917-104-6513VIBER / WHATSAPP
(+63) 917-104-6513
OFFICE HOURS
Monday – Friday, 8:00 – 5:00
Whether you are exploring cybersecurity solutions, looking for long-term security support, or interested in working with our team, we'd be happy to connect.