Frequently asked questions about LuxGap SOC
Frequently asked questions
Everything you want to know before connecting your perimeter
What exactly is a managed SOC?
A team of analysts, processes and escalation procedures that monitor your perimeter 24/7 with a SIEM/XDR, triage alerts, contain incidents with you, notify the authorities within the deadlines and document everything. LuxGap SOC is operated from Luxembourg by the LuxGap team.
What can be connected to the SOC?
Anything that produces a log, an event or a signal: Microsoft 365 and Google Workspace tenants, Windows and Linux servers, firewalls and network equipment, endpoints and EDR, business applications, databases, connected devices, industrial equipment, buildings (badges, sensors, cameras, air conditioning, UPS units) and LuxGap DevOps. The Sectors page gives examples by industry.
What access rights do you need to my Microsoft 365 tenant?
Roles limited to reading security logs and configuration settings. Never the Global Administrator or Global Reader role, which would open up read access to your emails and conversations. You receive the exact list of permissions before onboarding.
Do I have to change my antivirus, hosting provider or IT provider?
No. LuxGap SOC integrates your existing EDR (ESET, Microsoft Defender and others), works with any hosting provider and shares the IT task board with your IT provider, without giving them access to anything else.
What happens if there is an incident?
An analyst triages the alert and contains the incident with your teams; our legal experts draft and submit the regulatory notifications to the CNPD, the ILR or the CSSF within the NIS2, DORA or GDPR deadlines; the incident is then documented and the task board updated. Dealing with an incident right now? Call +352 621 583 116.
Does the SOC cover my NIS2 and DORA obligations?
It covers incident detection, management and notification, continuous configuration hardening and the production of evidence. The SOC can be included in a LuxGap outsourced CISO engagement that takes care of all your NIS2 and DORA obligations.
Where are my logs stored?
On LuxGap group infrastructure in Luxembourg, processed by a sovereign SIEM/XDR operated by our team. Nothing is sent to a monitoring service hosted outside the European Union.
Do you really monitor connected devices and industrial equipment?
Yes. The building's connected devices are integrated through building protocols (for example a Zigbee antenna), and industrial equipment through passive network monitoring, without disrupting production. Physical and digital alerts arrive in the same console, and some control functions are available from the console.
How much does it cost?
The price depends on the perimeter: tenants, servers, endpoints, network equipment, sites, connected devices, options. You describe your perimeter in the onboarding request and receive a firm quote within 24 hours. The SOC can also be included in an outsourced CISO engagement.
What does the ‘100% perimeter’ guarantee mean?
That the entire perimeter set out in writing during scoping is monitored, without exception, and that no asset is ever removed from it for budget reasons. If a new asset appears, it is added to the perimeter, not ignored.
Can my auditor or external CISO access the console?
Yes, with dedicated read-only access to alerts, incidents, tasks, reports and evidence.
How does subscribing work?
You fill in the onboarding request. LuxGap replies within 24 hours with a firm quote and the annual contract. On signature, we scope the perimeter, give you the list of permissions and connect your sources gradually.