Detection & response · London

Most breaches
are quiet.

By the time an alert fires, an intruder has usually been inside for weeks. We build the platform that catches them early — and the team that tells you what to do next.

StatusSweeping
Assets in scope0
Pass duration00:00.0
Flagged this pass0
We work across Financial services Legal Advanced manufacturing Local government Healthcare
NOX SIEM

A SIEM small teams
can actually run.

Most security platforms assume you have twelve analysts and a tuning budget. Ours assumes you have two people and a day job.

01

Everything in one timeline

Endpoint, cloud, identity and network events land in a single ordered view. When something looks wrong you see what happened before and after it, on every system, without stitching together four consoles.

Ingest
Any log source
Retention
12 months hot
Deployment
Cloud or on-prem
02

Detections that ship tuned

Rules arrive already fitted to your estate rather than as a library you have to configure. Noise is suppressed before it reaches you, not after you have learned to ignore it.

03

Answers, not alerts

Each detection comes with what triggered it, what it usually means, and the specific next action. Written for a competent engineer, not a specialist.

NOX SIEM · working

Stopped at
the edge.

An illustration of how inbound attempts are blocked before they reach anything that matters.

Defended site Inbound attempt Blocked
Blocked · illustrative
0
Source networks · illustrative
0
Live feed Edge · all estates
Illustrative visualisation, not live customer telemetry. Locations are indicative only.
Consultancy

Three services,
done properly.

A small team of engineers, not a call centre. You get the same people every time, and they know your network.

S01

Incident response

Retained or emergency. We contain the intrusion, work out how it started, and hand you a report your board and your insurer can both read.

ContainmentForensicsRansomware
S02

Offensive testing

We attack the estate the way a real intruder would, then sit down with your engineers and fix it. No 200-page PDF of scanner output.

Penetration testingRed teamCloud & AD
S03

Security advisory

A named engineer who sits in your leadership meetings, owns the roadmap and tells you where the money is worth spending — and where it isn't.

vCISOGovernanceBoard reporting
Onboarding

How the first
fortnight runs.

No discovery phase that bills for three months. Cover starts before the paperwork is finished.

00
Day zero

Briefing

Ninety minutes with your team. We map what you run, what you're worried about, and what has already gone wrong.

03
Day three

Sensors live

Agents deployed, log sources connected, monitoring switched on. You are covered from this point.

14
Day fourteen

Baseline report

What normal looks like on your network, what we found on the way in, and a ranked list of fixes.

Ongoing

Standing watch

Monthly review with the same engineers. Quarterly testing. Callout whenever you need it.

Contact

Talk to an engineer,
not a salesperson.

Tell us what you're running and what's keeping you up. If we're not the right fit we'll say so and point you somewhere better.

Security reports
security@noxdefence.com
Office
London, United Kingdom