Skip to content

FLAGSHIP SERVICE

CROC · Cyber Risk and Operations Center

The CROC doesn't rename the SOC: it changes the unit of work. Instead of managing alerts, it manages risk, 24/7/365 watch from Santo Domingo, run by expert analysts and six AI agents with defined roles. No agent closes a confirmed incident or executes containment without human authorization. If your system generates logs, it enters monitoring, whether it's from this year or a decade ago.

MTTA < 15 min24/7/365ISO 27001 + FIRSTPer-severity SLA
Audited certification and membership of the global incident response forum.
AT A GLANCE
Onboarding 2–3 weeks
Integrates with Your sensors, EDR and cloud
Model Fixed monthly price by scope
Satisfies ISO 27001 · PCI DSS 10 · Law 172-13
HOW WE WORK

One operation, nine capabilities

SOC AI · six agents with roles

Classification, enrichment, reasoned dismissal, hunting, proposed containment and write-ups. 94% of the noise is dismissed at the door with auditable justification; the analyst decides what only a person can.

Monthly quality control

Blind sampling of dismissals by an analyst: "zero real cases lost" is audited every month, not promised.

Correlation & SIEM

Ingest and correlation of network, endpoint, identity and cloud logs in a central platform operated by CBRT.

Threat hunting

Hypothesis-driven hunting over the full telemetry to find what no tool has modeled, every finding becomes new detection.

Incident response

Triage, containment and escalation per runbooks agreed with your team, with documented evidence and optional managed EDR for remote containment.

UEBA · behavioral detection

Complements traditional rules with behavior analytics: sophisticated threats, fewer false positives, business-risk prioritization.

Exposure management

External-surface watch: ports, certificates, leaks and domains that look like yours.

Risk & vulnerabilities

Continuous identification and assessment of cyber risk, with validation and follow-through on remediation.

Compliance reporting

Weekly technical and monthly executive reports, with Power BI dashboards and KPIs aligned to applicable regulation.

METHODOLOGY

From signed contract to full operation in weeks

A continuous watch flow: when the last step closes, the cycle starts again with what the shift learned.

STEP 01

Scope & connectors

Source inventory, agent deployment, and connection of your cloud and sensors to the CROC.

→ Signed coverage matrix
STEP 02

Baseline & tuning

Two weeks of calibration: what is normal in your network, noise suppression, per-asset thresholds.

→ Baseline + tuned rules
STEP 03

24/7 operation

Continuous shifts with < 15 min triage, weekly hunting and runbook-driven containment.

→ Documented cases + panel
STEP 04

Continuous improvement

Monthly review: false positives, tuning applied, visibility gaps and next month's plan.

→ Monthly executive report
⟳ THE CYCLE RETURNS TO STEP 03 · CONTINUOUS OPERATION 24/7/365
SERVICE TIERS

Three tiers, one CROC

The price is fixed in writing after a 30-minute scoping and does not change during the contract. Scope ambiguity is what makes things expensive.

8×5 Monitoring

COVERAGE
Business hours
COMMITTED MTTA
< 60 min
PROACTIVE HUNTING
MAJOR INCIDENT
Ad-hoc rate
ANNUAL TABLETOP
RECOMMENDED

CROC 24/7

COVERAGE
24/7/365
COMMITTED MTTA
< 15 min
PROACTIVE HUNTING
Weekly
MAJOR INCIDENT
Ad-hoc rate
ANNUAL TABLETOP

CROC + Retainer DFIR

COVERAGE
24/7/365
COMMITTED MTTA
< 15 min
PROACTIVE HUNTING
Weekly
MAJOR INCIDENT
Pre-contracted · < 4 h
ANNUAL TABLETOP
Included
REFERENCE FRAMEWORKS

The operation has doctrine

CD/CR FRAMEWORK

Continuous Detection / Continuous Response: detect → contextualize → correlate → decide → act → learn. Every closed case leaves a better rule; every exception has an expiry date and reverts on its own.

OODA LOOP

Whoever completes the loop faster wins, not whoever has better information. Triage SLAs and runbook order are born here.

DIAMOND MODEL

Adversary, capability, infrastructure and victim: pivoting between vertices turns a loose indicator into an understood campaign.

MaGMa

Detections managed as a portfolio: every rule anchored to a business objective, a technique and a data source, and measured.

DYNAMIC RESPONSE

Containment, analysis and communication in parallel, re-scoping with every new fact. The incident does not wait.

MITRE ATT&CK

The common language of red, blue and the committee: coverage measured on the same map, in the heatmap and the monthly report.

DELIVERABLES

What you receive every month

Live shift panel with open cases
Weekly technical report
Monthly executive report
Cases with analysis and recommendations
Applied tuning log
Monthly service meeting
MITRE ATT&CK coverage matrix
Alerting through the channels your team uses
FAQ

Frequently asked questions

Does the CROC replace my IT team?

No: it complements it. Your team keeps platform administration; the CROC brings the continuous watch, expert triage and response that an internal team of 2–3 people cannot sustain 24/7.

What do I have to install?

Usually just connectors: an EDR agent where none exists, and read credentials for your cloud and email. It does not require replacing your current firewall or antivirus.

Where does my data live?

Telemetry is processed on CBRT-controlled infrastructure with encryption in transit and at rest, under NDA and in compliance with Law 172-13. You keep ownership and can export on exit.

How long is onboarding?

Between 2 and 3 weeks: one for connector deployment and two for baseline and tuning. Billing starts when the agreed coverage is active, not at signature.

How is the service measured?

With the monthly report indicators: MTTA and MTTR by severity, false-positive rate, cases by category and SLA compliance. The same numbers the risk committee sees.

Can I exit the contract?

Yes: the contract defines an orderly exit: data export, transfer of documented detection rules and 60 days of transition support. No hidden exit fees.

See the room before you sign.

Meet the analysts who will handle your alerts. No sales script.