Skip to content
LuxGapSOC
Monitoring active
EN
Console sign-in Request onboarding

Monitoring active · Sector by sector

Anything that produces a log, an event or a signal can be monitored.

Servers, cloud, endpoints, network, applications, databases, connected devices, industrial equipment, buildings: if it's in your perimeter, LuxGap SOC connects it. Here, sector by sector, is what we connect, what we detect and the obligations this covers.

Request onboarding Back to LuxGap SOC
SOC

Methods

Nine ways to connect a source, always with least privilege

Source Method What the SOC receives
Microsoft 365 and Google Workspace API connector with limited roles, exact list of permissions provided before access is granted, never Global Administrator or Global Reader Sign-ins, MFA, sharing, forwarding rules, authorised applications, logging, security alerts
Windows and Linux servers Lightweight agent installed by your teams or by LuxGap System and security logs, file integrity, vulnerabilities, suspicious processes
Firewalls, switches, VPN, Wi-Fi Logs forwarded to an encrypted collection point, network flows Inbound and outbound connections, intrusion attempts, remote access, unknown devices
Endpoints Connector to your existing EDR (ESET, Microsoft Defender, others) Malware, suspicious behaviour, unprotected or out-of-date endpoints
Business applications and databases Application logs and database audit logs, availability probes Abnormal access, bulk queries, errors that point to an attack, outages
Connected devices and buildings Gateways and antennas (for example Zigbee), building protocols Door openings, presence, temperature, smoke, flooding, UPS units, lighting, offline cameras; control functions where the equipment supports them
Industrial equipment Passive monitoring of the industrial network via a mirror port, with no action on PLCs Devices present, protocols in use, abnormal commands and program changes, remote maintenance access
Application code LuxGap DevOps connection Critical code findings: exposed secrets, vulnerabilities, risky dependencies
Multiple sites One collection point per site, encrypted link to the SOC All the sources above, site by site, in a single console

Sectors

What we monitor in your organisation

01

Finance and insurance

Banks, PSFs, funds, insurers, asset managers

Request onboarding

Connected sources

  • Microsoft 365 or Google Workspace tenants and employee accounts
  • Business applications: online banking, portfolio management, KYC platforms, reporting tools
  • Bastion hosts and administrator accounts, ICT third-party provider access
  • Firewalls, VPN, endpoints and EDR, databases
  • Code of in-house applications, via LuxGap DevOps

What the SOC detects

  • Abnormal sign-ins and MFA bypasses on sensitive accounts
  • Business email compromise and payment diversion fraud attempts
  • Provider access outside agreed windows
  • Client data exfiltration, bulk queries
  • Internet-exposed vulnerabilities and configuration deviations

Regulatory framework

DORA (initial notification of major incidents to the CSSF within 4 hours of classification), CSSF circulars, GDPR, anti-money laundering obligations for KYC platforms.

02

Healthcare

Hospitals, clinics, laboratories, care homes, medical practices

Request onboarding

Connected sources

  • Electronic patient records, imaging, laboratory information system
  • Connected medical devices: monitors, pumps, imaging equipment, and their remote maintenance access
  • Wi-Fi network for patients and visitors, separate from the clinical network
  • Badges and access control for sensitive areas, pharmacy, technical rooms
  • Directory, cloud tenants, endpoints and EDR, backups

What the SOC detects

  • Abnormal or bulk access to patient records
  • Ransomware encryption in progress, spread between endpoints
  • Vulnerable, obsolete or exposed medical devices
  • Unscheduled remote maintenance on a piece of equipment
  • Healthcare staff credentials exposed on the dark web

Regulatory framework

NIS2 (health sector), GDPR and health data, notification to the CNPD within 72 hours, continuity-of-care obligations.

03

Industry and energy

Factories, energy production and distribution, water, critical infrastructure

Request onboarding

Connected sources

  • PLCs, supervisory systems, operator interfaces, engineering workstations
  • Industrial networks via passive monitoring, gateways between office IT and production
  • Remote maintenance access for equipment manufacturers
  • Sensors, building management systems, security systems (cameras, access control)
  • Cloud tenants, servers, endpoints and EDR on the office IT side

What the SOC detects

  • Abnormal commands and program changes on PLCs
  • New device or unusual protocol on the industrial network
  • Remote maintenance access outside the agreed window
  • Ransomware on engineering workstations, compromised gateway between office IT and production
  • Physical anomalies: temperature, door opening, power cut

Regulatory framework

NIS2 (energy, water, manufacturing depending on size), ILR as the authority, critical infrastructure requirements, GDPR for staff data.

04

Public sector and municipalities

Public administrations, municipalities, inter-municipal syndicates, public institutions

Request onboarding

Connected sources

  • Citizen portals and online services, civil registry, school management
  • Email and cloud tenants for staff and elected officials
  • Municipal buildings: heating, lighting, access control, CCTV
  • Public Wi-Fi, networks for schools and sports facilities
  • Access for municipal service agencies and providers

What the SOC detects

  • Attack on or defacement of a portal, unavailability of an online service
  • Business email compromise and phishing targeting elected officials and staff
  • External sharing of citizens' data
  • Provider accounts active outside scheduled interventions
  • Building equipment exposed to the internet

Regulatory framework

NIS2 for administrations within the scope of Luxembourg law, GDPR and the CNPD, public service continuity obligations.

05

Retail and hospitality

Retail brands, hotels, restaurants, store networks

Request onboarding

Connected sources

  • Point-of-sale systems and payment terminals, booking and hotel management software
  • Customer Wi-Fi, separate from the business network
  • Cameras, smart locks, stockroom access control
  • Multi-site network linking shops or venues
  • Cloud tenants, e-commerce website, via LuxGap DevOps for the code

What the SOC detects

  • Compromised point-of-sale systems or terminals, malware on checkout workstations
  • Customer network not isolated, unknown devices
  • Shared accounts and exposed credentials
  • Vulnerable e-commerce website, customer data leak
  • Locks or cameras offline, out-of-hours openings

Regulatory framework

GDPR and the CNPD, PCI DSS requirements for card payments, NIS2 depending on size and activity.

06

Professional firms and practices

Lawyers, fiduciaries, chartered accountants, notaries, doctors, architects

Request onboarding

Connected sources

  • Email and Microsoft 365 or Google Workspace tenants
  • Online business software: accounting, case management, electronic signature
  • File server or NAS, backups
  • Mobile endpoints and EDR, remote access
  • Document exchange platforms for clients

What the SOC detects

  • Business email compromise and payment diversion fraud targeting clients
  • Auto-forwarding rules set up by an attacker
  • Sign-ins from unusual countries, MFA bypasses
  • Credentials exposed on the dark web, client file exfiltration
  • Unencrypted, out-of-date or unprotected endpoints

Regulatory framework

GDPR and professional secrecy, anti-money laundering obligations for the professions concerned, CSSF requirements for PSFs.

07

Software vendors and IT services firms

Software vendors, integrators, managed service providers

Request onboarding

Connected sources

  • Application hosting: virtual machines, containers, databases
  • Code forges and pipelines, secrets, developer accounts
  • Client access: VPN, bastion hosts, dedicated environments
  • Cloud tenants, team endpoints and EDR
  • Application code, via LuxGap DevOps

What the SOC detects

  • Exposed secrets, vulnerable dependencies, AI-generated code with no review
  • Unauthorised access to production, lateral movement between client environments
  • Compromised developer accounts
  • Internet-exposed vulnerabilities
  • Incidents to be notified to your regulated clients within their deadlines

Regulatory framework

NIS2 for managed service providers, DORA as an ICT third-party service provider to financial clients, GDPR as a processor.

08

Associations, federations and clubs

Professional federations, clubs, non-profit organisations

Request onboarding

Connected sources

  • Member database and management tools, website and ticketing
  • Email and cloud tenants, volunteers' shared accounts
  • Online payments, event platforms
  • Endpoints and EDR for permanent staff

What the SOC detects

  • Member database leak, abnormal access
  • Phishing targeting volunteers and permanent staff, compromised shared accounts
  • Vulnerable website or ticketing platform
  • Credentials exposed on the dark web

Regulatory framework

GDPR and the CNPD, obligations of your public or financial partners, NIS2 for federations that are subject to it.

09

Buildings and sites

Common to all sectors

Request onboarding

Connected sources

  • Access control and badges, gates, smart locks
  • CCTV, cameras and recorders
  • Sensors: door opening, presence, temperature, smoke, flooding
  • Server room air conditioning, UPS units, lighting
  • Wi-Fi network and building equipment, connected through gateways and antennas (for example Zigbee)

What the SOC detects

  • Sensitive room opened out of hours, unexpected presence
  • Abnormal server room temperature, UPS failure, power cut
  • Camera or sensor offline, building equipment exposed to the internet
  • Unknown device on the building network
  • And from the console, for equipment that supports it: control commands, such as lighting

Regulatory framework

Physical and environmental security expected under NIS2 and ISO 27001, GDPR for CCTV and badges.

Don't see your sector listed?

Transport and logistics, education, media, real estate, agriculture, research: the principle is the same. Tell us what you use and what concerns you; we scope the perimeter with you and guarantee it 100%.

Describe your perimeter

Frequently asked questions about onboarding

Can connecting industrial equipment disrupt production?

No. Industrial networks are monitored passively, with no agent on the PLCs and no action on the equipment. The SOC observes; it does not intervene in production.

Do I need an agent on every endpoint?

No. The SOC relies on your existing EDR (ESET, Microsoft Defender or another) and integrates it through a connector. Servers receive a lightweight agent; network equipment sends its logs.

What happens if a site loses its link to the SOC?

The site's collection point keeps the logs and forwards them as soon as the link is restored; the loss of the link itself triggers an alert.

Can you monitor a site abroad?

Yes, with an on-site collection point and an encrypted link to the SOC in Luxembourg. The regulatory framework that applies to the site is confirmed during scoping.

How long does full onboarding take?

It is gradual: monitoring starts from the first connected source, and further sources are added asset by asset, with no disruption to your business. The timeline is set during scoping, according to the size of the perimeter.

Describe your perimeter, and we'll monitor all of it

Cloud, servers, endpoints, network, applications, connected devices, industrial equipment, buildings: a firm quote within 24 hours, an annual contract under Luxembourg law, and 100% of your perimeter guaranteed.

Request onboarding

Dealing with an incident right now? Call +352 621 583 116.