FLAGSHIP SERVICE
CROC · Cyber Risk and Operations Center
The CROC doesn't rename the SOC: it changes the unit of work. Instead of managing alerts, it manages risk, 24/7/365 watch from Santo Domingo, run by expert analysts and six AI agents with defined roles. No agent closes a confirmed incident or executes containment without human authorization. If your system generates logs, it enters monitoring, whether it's from this year or a decade ago.
One operation, nine capabilities
SOC AI · six agents with roles
Classification, enrichment, reasoned dismissal, hunting, proposed containment and write-ups. 94% of the noise is dismissed at the door with auditable justification; the analyst decides what only a person can.
Monthly quality control
Blind sampling of dismissals by an analyst: "zero real cases lost" is audited every month, not promised.
Correlation & SIEM
Ingest and correlation of network, endpoint, identity and cloud logs in a central platform operated by CBRT.
Threat hunting
Hypothesis-driven hunting over the full telemetry to find what no tool has modeled, every finding becomes new detection.
Incident response
Triage, containment and escalation per runbooks agreed with your team, with documented evidence and optional managed EDR for remote containment.
UEBA · behavioral detection
Complements traditional rules with behavior analytics: sophisticated threats, fewer false positives, business-risk prioritization.
Exposure management
External-surface watch: ports, certificates, leaks and domains that look like yours.
Risk & vulnerabilities
Continuous identification and assessment of cyber risk, with validation and follow-through on remediation.
Compliance reporting
Weekly technical and monthly executive reports, with Power BI dashboards and KPIs aligned to applicable regulation.
From signed contract to full operation in weeks
A continuous watch flow: when the last step closes, the cycle starts again with what the shift learned.
Scope & connectors
Source inventory, agent deployment, and connection of your cloud and sensors to the CROC.
→ Signed coverage matrixBaseline & tuning
Two weeks of calibration: what is normal in your network, noise suppression, per-asset thresholds.
→ Baseline + tuned rules24/7 operation
Continuous shifts with < 15 min triage, weekly hunting and runbook-driven containment.
→ Documented cases + panelContinuous improvement
Monthly review: false positives, tuning applied, visibility gaps and next month's plan.
→ Monthly executive reportThree tiers, one CROC
The price is fixed in writing after a 30-minute scoping and does not change during the contract. Scope ambiguity is what makes things expensive.
8×5 Monitoring
CROC 24/7
CROC + Retainer DFIR
The operation has doctrine
Continuous Detection / Continuous Response: detect → contextualize → correlate → decide → act → learn. Every closed case leaves a better rule; every exception has an expiry date and reverts on its own.
Whoever completes the loop faster wins, not whoever has better information. Triage SLAs and runbook order are born here.
Adversary, capability, infrastructure and victim: pivoting between vertices turns a loose indicator into an understood campaign.
Detections managed as a portfolio: every rule anchored to a business objective, a technique and a data source, and measured.
Containment, analysis and communication in parallel, re-scoping with every new fact. The incident does not wait.
The common language of red, blue and the committee: coverage measured on the same map, in the heatmap and the monthly report.
What you receive every month
Frequently asked questions
Does the CROC replace my IT team?
No: it complements it. Your team keeps platform administration; the CROC brings the continuous watch, expert triage and response that an internal team of 2–3 people cannot sustain 24/7.
What do I have to install?
Usually just connectors: an EDR agent where none exists, and read credentials for your cloud and email. It does not require replacing your current firewall or antivirus.
Where does my data live?
Telemetry is processed on CBRT-controlled infrastructure with encryption in transit and at rest, under NDA and in compliance with Law 172-13. You keep ownership and can export on exit.
How long is onboarding?
Between 2 and 3 weeks: one for connector deployment and two for baseline and tuning. Billing starts when the agreed coverage is active, not at signature.
How is the service measured?
With the monthly report indicators: MTTA and MTTR by severity, false-positive rate, cases by category and SLA compliance. The same numbers the risk committee sees.
Can I exit the contract?
Yes: the contract defines an orderly exit: data export, transfer of documented detection rules and 60 days of transition support. No hidden exit fees.
See the room before you sign.
Meet the analysts who will handle your alerts. No sales script.