Skip to content
LuxGapSOC
Monitoring active
EN
Console sign-in Request onboarding

Monitoring active · Sovereign managed SOC · Operated in Luxembourg

Your whole perimeter, watched 24/7. By a team, not just a tool.

LuxGap SOC collects and correlates logs from your servers, endpoints, network and applications and from your Microsoft 365 and Google Workspace tenants, continuously audits your configurations, monitors the dark web, detects incidents from the first hour and handles regulatory notifications. Cloud, connected devices, industrial equipment, buildings: if it's in your perimeter, it's monitored.

Request onboarding See what the SOC monitors, sector by sector
  • 100% of your perimeter, guaranteed
  • Least-privilege access to your tenants, never Global Administrator
  • Detection from the first hour
  • CNPD, ILR and CSSF notifications within the deadlines
LuxGap SOC — Monitoring console Monitoring active
Dashboard Alerts Assets Cloud configuration Dark web Vulnerabilities IT tasks Incidents Reports
1,284assets monitored
91%coverage score
2 critical · 9 majoropen alerts
Closed 3 days agolast incident
Real-time alerts
CRITICAL Microsoft 365 sign-in from an unusual country, MFA bypassed — account finance-024 min ago
CRITICAL Employee credentials found on a criminal marketplace — primary domain26 min ago
MAJOR External sharing enabled on a SharePoint site — primary tenant1 h ago
MAJOR Unpatched critical vulnerability — srv-erp-012 h ago
INFO Server room opened out of hours — sensor porte-B23 h ago
COMPLIANT Administrator MFA check: 100%5 h ago
IT task board: 14 controls to harden · 3 in progress · 112 closed

Fictitious demo data

Connected sources
  • Microsoft 365
  • Google Workspace
  • Windows and Linux servers
  • Firewalls and network
  • EDR (ESET, Microsoft Defender, others)
  • Business applications
  • Databases
  • Connected devices and buildings
  • Industrial equipment
  • LuxGap DevOps
Frameworks covered
  • NIS2
  • DORA
  • GDPR
  • ISO 27001
  • CSSF circulars
  • ILR
  • CNPD

The reality

Attacks don't wait for office hours. Neither do your obligations.

An SME, a municipality, a hospital or a fiduciary firm has no security team keeping watch at night. Yet credentials circulate on criminal marketplaces, cloud tenants change configuration without anyone noticing, endpoints raise alerts that nobody reads, and nobody monitors the building's connected devices.

Meanwhile, NIS2, DORA and the GDPR require incidents to be detected, triaged and notified within tight deadlines: an early warning within 24 hours under NIS2, an initial notification within 4 hours of classification under DORA, and notification to the CNPD within 72 hours under the GDPR. Without monitoring, these deadlines are impossible to meet.

LuxGap SOC brings your entire perimeter under monitoring, detects from the first hour, contains incidents with your teams, notifies the authorities within the deadlines and documents everything, in a console that you, your auditor and your CISO can consult at any time.

24 hNIS2 early warning to the competent authority
4 hDORA initial notification after a major incident is classified
72 hnotification to the CNPD under the GDPR

Our commitments

Four commitments few SOCs make

100% of your perimeter, guaranteed

We never remove an asset from monitoring for budget reasons. A forgotten server, a printer, a sensor, a PLC: if it's in your perimeter, it's monitored. A SOC that monitors 80% of a perimeter leaves 20% of the doors open.

Least privilege

We never ask for the Global Administrator or Global Reader role on your tenants: these roles would open up read access to your emails and conversations. Before onboarding, you receive the exact list of permissions to grant, and nothing more.

Complex infrastructure

Our greatest strength is adapting monitoring to your reality: multiple sites, industrial networks, connected devices, buildings, in-house applications. We connect what standard SOCs turn down, right down to the sensors and equipment on your premises, with control functions available from the console.

A team, not just a tool

The SOC is made up of analysts based in Luxembourg, processes, escalation procedures and legal experts who handle notifications. The sovereign SIEM/XDR we operate is merely the instrument.

Sovereignty

Your logs stay in Luxembourg. Your emails stay yours.

Logs, alerts and evidence are processed and stored on LuxGap group infrastructure in Luxembourg, by a sovereign SIEM/XDR operated by our own team, with no dependency on a monitoring service hosted outside the European Union. Contracts are governed by Luxembourg law. Our legal experts, cybersecurity engineers and developers work under one roof.

  • Data in Luxembourg
  • Contracts under Luxembourg law
  • Team based in Luxembourg

What we ask for / what we never ask for

We ask for

  • Roles limited to reading security logs and configuration settings
  • A read-only account on EDR consoles
  • An agent on servers
  • A collection point for the network

We never ask for

  • The Global Administrator role
  • The Global Reader role
  • Access to the content of your emails or conversations
  • Write access to your applications

You receive the exact list of permissions before granting anything, and you can have it checked by your DPO.

Sectors

What the SOC monitors in your organisation, sector by sector

Anything that produces a log, an event or a signal can be connected. A few examples below; the Sectors page details the sources, threats and obligations for each one.

Finance and insurance

Tenants, business applications, administration bastion hosts, ICT third-party providers: the monitoring expected by DORA and the CSSF.

See details →

Healthcare

Patient records, imaging, connected medical devices, access to premises: protecting health data under NIS2 and the GDPR.

See details →

Industry and energy

PLCs, industrial networks, sensors, remote maintenance access: monitoring production without disrupting it.

See details →

Public sector and municipalities

Citizen portals, email, buildings and schools: NIS2 compliance for public administrations.

See details →

Professional firms and practices

Email, business software, credentials: protecting professional secrecy.

See details →

Software vendors and IT services firms

Hosting, pipelines, client access, code: the monitoring your regulated clients demand, with LuxGap DevOps.

See details →
See all sectors and what can be connected
LuxGap SOC — IT tasksMonitoring active
To harden 14
Enable MFA on 3 service accountshigh priorityassigned to IT provider
In progress 3
Closed 112
Coverage score 91% · continuously updated

Fictitious demo data

The console

A monitoring console, in French and English, that you can open whenever you like

The LuxGap SOC console shows monitored assets, triaged alerts, configuration deviations, dark web exposures, vulnerabilities, incidents and the IT task board in real time. It is protected by mandatory multi-factor authentication and TLS 1.3 encryption, and you sign in with your Microsoft account or through local client access.

  • Dashboard with the coverage score and open alerts
  • Connected assets, with the status of each source
  • IT tasks shared with your IT provider
  • Incidents and regulatory notifications, with evidence
  • Exportable reports for management and auditors
  • Dedicated access for your auditor, DPO or external CISO

The SOC monitors the infrastructure. The LuxGap group takes care of the rest.

LuxGap DevOps

Continuous monitoring of your applications' code: vibe coding oversight, code security, application penetration testing, automated testing, compliance evidence. Critical findings feed into the SOC. From €0.01 excl. VAT per line of code per month.

devops.luxgap.com →

Hosting, backup, secrets, compliance

Sovereign hosting in Luxembourg, daily backups, a secrets vault, legal compliance for your website, and multi-site distribution for ultra-high availability.

devops.luxgap.com/groupe/ →

Go further

The details, page by page

All features

Collection and correlation, cloud audit, dark web, EDR, vulnerabilities, IoT and industrial systems, incident response, IT tasks, console.

See all nine features →

Detection and response

The six phases, from first alert to closure, and the NIS2, DORA and GDPR regulatory clock.

See the deadlines →

Pricing

What drives the price, what every subscription includes, and a firm quote within 24 hours.

Understand the pricing →

FAQ

Twelve answers: tenant access rights, existing EDR, incidents, logs, subscribing.

Read the answers →

You describe your perimeter, and LuxGap replies within 24 hours with a firm quote and the contract. Dealing with an incident right now? Call +352 621 583 116.

Request onboarding