Finance and insurance
Tenants, business applications, administration bastion hosts, ICT third-party providers: the monitoring expected by DORA and the CSSF.
See details →The reality
An SME, a municipality, a hospital or a fiduciary firm has no security team keeping watch at night. Yet credentials circulate on criminal marketplaces, cloud tenants change configuration without anyone noticing, endpoints raise alerts that nobody reads, and nobody monitors the building's connected devices.
Meanwhile, NIS2, DORA and the GDPR require incidents to be detected, triaged and notified within tight deadlines: an early warning within 24 hours under NIS2, an initial notification within 4 hours of classification under DORA, and notification to the CNPD within 72 hours under the GDPR. Without monitoring, these deadlines are impossible to meet.
LuxGap SOC brings your entire perimeter under monitoring, detects from the first hour, contains incidents with your teams, notifies the authorities within the deadlines and documents everything, in a console that you, your auditor and your CISO can consult at any time.
Our commitments
We never remove an asset from monitoring for budget reasons. A forgotten server, a printer, a sensor, a PLC: if it's in your perimeter, it's monitored. A SOC that monitors 80% of a perimeter leaves 20% of the doors open.
We never ask for the Global Administrator or Global Reader role on your tenants: these roles would open up read access to your emails and conversations. Before onboarding, you receive the exact list of permissions to grant, and nothing more.
Our greatest strength is adapting monitoring to your reality: multiple sites, industrial networks, connected devices, buildings, in-house applications. We connect what standard SOCs turn down, right down to the sensors and equipment on your premises, with control functions available from the console.
The SOC is made up of analysts based in Luxembourg, processes, escalation procedures and legal experts who handle notifications. The sovereign SIEM/XDR we operate is merely the instrument.
Sovereignty
Logs, alerts and evidence are processed and stored on LuxGap group infrastructure in Luxembourg, by a sovereign SIEM/XDR operated by our own team, with no dependency on a monitoring service hosted outside the European Union. Contracts are governed by Luxembourg law. Our legal experts, cybersecurity engineers and developers work under one roof.
We ask for
We never ask for
You receive the exact list of permissions before granting anything, and you can have it checked by your DPO.
Sectors
Anything that produces a log, an event or a signal can be connected. A few examples below; the Sectors page details the sources, threats and obligations for each one.
Tenants, business applications, administration bastion hosts, ICT third-party providers: the monitoring expected by DORA and the CSSF.
See details →Patient records, imaging, connected medical devices, access to premises: protecting health data under NIS2 and the GDPR.
See details →PLCs, industrial networks, sensors, remote maintenance access: monitoring production without disrupting it.
See details →Citizen portals, email, buildings and schools: NIS2 compliance for public administrations.
See details →Email, business software, credentials: protecting professional secrecy.
See details →Hosting, pipelines, client access, code: the monitoring your regulated clients demand, with LuxGap DevOps.
See details →Fictitious demo data
The console
The LuxGap SOC console shows monitored assets, triaged alerts, configuration deviations, dark web exposures, vulnerabilities, incidents and the IT task board in real time. It is protected by mandatory multi-factor authentication and TLS 1.3 encryption, and you sign in with your Microsoft account or through local client access.
Continuous monitoring of your applications' code: vibe coding oversight, code security, application penetration testing, automated testing, compliance evidence. Critical findings feed into the SOC. From €0.01 excl. VAT per line of code per month.
devops.luxgap.com →Sovereign hosting in Luxembourg, daily backups, a secrets vault, legal compliance for your website, and multi-site distribution for ultra-high availability.
devops.luxgap.com/groupe/ →Go further
Collection and correlation, cloud audit, dark web, EDR, vulnerabilities, IoT and industrial systems, incident response, IT tasks, console.
See all nine features →The six phases, from first alert to closure, and the NIS2, DORA and GDPR regulatory clock.
See the deadlines →What drives the price, what every subscription includes, and a firm quote within 24 hours.
Understand the pricing →Twelve answers: tenant access rights, existing EDR, incidents, logs, subscribing.
Read the answers →You describe your perimeter, and LuxGap replies within 24 hours with a firm quote and the contract. Dealing with an incident right now? Call +352 621 583 116.
Request onboarding