Cybersecurity › Detection & Response
Detection & Response

An attack is already underway.
The question is, who will notice it first?

We monitor your systems around the clock, personally assess every anomaly, and take action in an emergency rather than simply sending a notification.

In-house SOC in Austria · EU Technology

The Problem

Attackers are already there—
—before anyone even notices.

Virus scanners detect what they recognize. Professional attackers know this and deliberately operate below this threshold, often for weeks at a time.

1.14 million USD

Additional costs if a data breach goes undetected for more than 200 days.

IBM Cost of a Data Breach 2025

241 days

Average time it takes to detect and contain a data breach.

IBM Cost of a Data Breach 2025

88 %

In these ransomware cases: The encryption began outside of business hours.

Sophos Active Adversary Report 2026

Attackers have time

As long as no one is actively looking for them, they go about their business undisturbed: gathering data, securing access points, and waiting for the right moment.

There's a shortage of analysts everywhere

Qualified security analysts are hard to come by. For most companies, maintaining their own team around the clock is not an option.

Improvising comes at a cost

Those who don't have a defined response process make decisions under pressure. And in the meantime, the attack continues to spread.

Managed Detection & Response

Round-the-clock protection—
—without needing your own security team.

We handle all monitoring, assessment, and response. You'll hear from us when it matters—not every time an alarm goes off.

Recognition
  • Real-time monitoring of all endpoints
  • Anomaly detection instead of relying solely on signatures
  • Targeted Follow-Up for Anomalies
Reaction
  • Remotely isolate affected systems
  • Investigate incidents to determine the root cause
  • Integrate Existing Security Tools
Transparency
  • Monthly Report with Recommendations
  • Key Metrics for Detection and Response
  • Quarterly Trend Analysis
Technology Partner

HarfangLab EDR

Detects attackers on your endpoints in real time. Developed in France, it has consistently ranked at the top in independent telemetry tests.

Technology Partner

IKARUS EPP

Blocks known threats before they become active. An Austrian solution that is automated and continuously updated.

Our Services

SOC in Austria

Alerts are not automatically forwarded. Our analysts evaluate each alert themselves and make a decision immediately, even at night and on holidays.

Contractually Guaranteed Response Times

MDR 24/7 · as soon as the report is received
Severity 1
up to 4 hours
Active attacker, ransomware, or large-scale data breach.
Severity 2
up to 6 hours
Malware on a system or a successful phishing attack.
Severity 3
up to 8 hours
Unusual logins or suspicious script activity.
Severity 4
2 business days
Non-critical warnings and automatically blocked attacks.

Measured from the time the report is received until the security analyst begins the analysis. For MDR 8/5, the applicable times are during business hours, Monday through Friday, 8:00 a.m. to 4:00 p.m.

An alert doesn't mean a response.
Someone has to read it.

That's why we guarantee a response time for every incident, rather than just generating a report.

Two models

24/7 at
or during business hours.

Detection runs continuously in both cases.
The difference lies in when an analyst responds.

MDR 24/7 · Recommended

Full coverage, 365 days a year

For companies that don't want to risk an attack outside of business hours—such as at night, on weekends, and during holidays.

  • Round-the-clock monitoring, all year round
  • Guaranteed response times at any hour
  • For Severity 1, immediate containment
MDR 8/5

Protection During Normal Operation

For companies that do not require support outside of business hours. Detection still runs continuously.

  • Hours: Monday through Friday, 8:00 a.m. to 4:00 p.m.
  • Guaranteed response times during service hours
  • 24/7 detection, response during business hours
Supplementary Services

When things get serious,
—or if no one sounds the alarm.

Both services can be booked individually or as a supplement to MDR.
As an MDR customer, you benefit from the fact that we are already familiar with your environment.

Incident Response

In the event of an attack, every minute counts.

You call, and we spring into action. We'll figure out what happened, stop the spread, and get your business back up and running.

Initial Examination
Assess the situation, stop the spread, implement immediate measures
In-Depth Analysis
Identify the cause, clean up systems, secure access points
Additional Support
Recovery and Follow-Up; IT forensics provides evidence admissible in court
Final Report
What happened, how we responded, and what measures will prevent it from happening again
Call in case of an emergency
Threat Hunting

Detect attackers before they are noticed.

Some attackers don't trigger any alerts because they behave like authorized users. We actively look for them.

Search for genuine patterns
We are looking for the modus operandi of known groups, not generic alerts
Sideways Movement Online
Identify behavior that automated systems classify as normal
Full Report
What was found, how critical it is, and what to do next
Request Hunting
Frequently Asked Questions

What customers want to know beforehand.

What distinguishes MDR from a firewall or a virus scanner?

Firewalls and antivirus scanners block what they recognize. MDR monitors what’s actually happening in your environment and looks for attackers who are already inside. The difference is between a reactive filter and active monitoring by humans.

Do we need to purchase or license our own security software?

No, we provide the technology. You'll need internet access and the ability to install our agents. We'll handle the setup together with your IT department.

What is ITanic allowed to do without our approval if an attack is detected?

We’ll determine this together during onboarding. You decide what we’re allowed to do on our own—such as isolating systems—and what requires your approval. In the event of critical attacks, we recommend granting us as much leeway as possible, because every minute counts.

Where is our data processed?

Exclusively in Austria, in a certified data center. No U.S. providers and no processing outside the European Economic Area.

Is incident response included in MDR?

MDR includes the following guided response steps: isolating systems, severing connections, and taking immediate action. In-depth forensic analysis, on-site operations, and system recovery are separate services.

Can we use Incident Response without an MDR contract?

Yes, Incident Response can be booked even without an active contract. However, without prior knowledge of your environment, the engagement will begin with an assessment—which is not required for MDR customers.

How does threat hunting differ from monitoring in MDR?

Monitoring responds to alerts. Threat hunting actively and manually searches for attackers, even when there are no alerts. It involves a separate, more in-depth investigation with a comprehensive report.

Do you know where your systems are vulnerable?

Before we start monitoring, it’s worth taking a look at what options are actually available.

View security tests

How well is your IT
protected against attacks?

In thirty minutes, we'll show you how we would protect your environment and which model is right for you.

Free and with no obligationDirectly with management30 minutes, concrete results