Services de sécurité managés
Offrez à votre entreprise des services de sécurité gérés complets pour une protection continue.
Building an effective in-house security operations capability is expensive, complex, and increasingly difficult as the threat landscape evolves daily. Managed Security Services allow organisations to access certified expertise, proven processes, and continuous protection without the overhead of building it all internally.
At e-Xpert Solutions, managed security is not a product we resell — it is a capability our engineers have built and operated since 2001. From our 100% Swiss managed SOC to our proprietary certificate lifecycle management platform, every service in our MSS portfolio is designed, operated, and continuously improved by our own certified specialists in Geneva and Lausanne.
Our MSS portfolio covers both defensive and offensive capabilities: continuous threat monitoring and response, managed application protection, proactive vulnerability management, breach and attack simulation, certificate automation, and penetration testing — all delivered under defined SLAs by engineers who hold advanced industry certifications.
Our Managed Security Services :
At-Defense — Managed SOC 24/7 (100% Swiss)
At-Defense is e-Xpert Solutions’ next-generation managed Security Operations Center — purpose-built for Swiss organisations, operated entirely from Switzerland, and certified ISO 27001 since 2021. Covered by an ISAE 3000 assurance report issued by a Big4 firm, At-Defense provides 24/7 threat monitoring, proactive threat hunting, darknet monitoring, honeypots and honeytokens, and incident response — all included at a flat-rate, predictable cost.
Key confirmed performance indicators: 100% of attacks detected since 2018, zero breaches recorded among SOC clients, less than 3% of alerts escalated to client teams. Analysts hold certifications including GCFA, GCIH, GCFR, GEIR, OSCP, and OSCE. Deploys in as little as two days. Integrates seamlessly with CrowdStrike, Microsoft Defender, and Palo Alto Cortex.
Fully compliant with nLPD, FINMA, and NIS2.
MSS WAF — Managed Web Application & API Protection (F5 MSP)
As an F5 Managed Service Provider, e-Xpert Solutions delivers a fully managed Web Application and API Protection (WAAP) service — covering WAF, Bot Defense, API Security, and DDoS mitigation, powered by the F5 SaaS platform. The service is backed by our 24/7 Security Operations Center and requires no hardware changes or code modifications on the client side. Rapid deployment, centralised protection across data centres, clouds, and edge environments, and continuous policy management by our certified F5 engineers.
PurpleScan — Managed Vulnerability Management
PurpleScan is e-Xpert Solutions’ expert-guided vulnerability management service — combining automated scanning (Nessus, Qualys, Greenbone) with SOC analyst review and prioritisation to reduce the exploitation window from the industry average of over 30 days to under 8 days.
The service includes automated weekly scans, SOC real-time alerts on new vulnerabilities using the “diffing” technique, SOC-led patch prioritisation within one day of detection, immediate analysis of new vulnerabilities with a client report delivered in under two hours, and a dedicated SIEM environment in Splunk with RBAC, 2FA, customisable dashboards, and CSV export for FINMA and ISO auditors. The service can be upgraded to At-Defense with EDR+ for more comprehensive coverage.
Security Control Audit (SCA) — Breach & Attack Simulation
The Security Control Audit is e-Xpert Solutions’ managed Breach and Attack Simulation service — powered by Picus Security — that continuously validates the effectiveness of your security controls against real-world attack scenarios.
Unlike penetration tests or vulnerability assessments, SCA runs continuously in production without disrupting business operations. It simulates adversarial TTPs (Tactics, Techniques, and Procedures) mapped to MITRE ATT&CK across network, endpoint, email, web application, and cloud vectors — validating the detection and prevention effectiveness of your NGFW, IPS, WAF, email gateway, endpoint security, and SIEM simultaneously.
The platform uses over 9,371 real-world payloads updated daily and provides over 34,000 mitigation signatures across more than 10 security vendors — including Check Point, Palo Alto Networks, F5, and Forcepoint — giving your security teams actionable, vendor-specific remediation guidance rather than generic findings.
Available as a one-time assessment or as a monthly managed service with executive summary, adversary simulation action report, mitigation plan, and delta reports.
SSLCert — Certificate Lifecycle Management
SSLCert is an enterprise-grade Digital Certificate Management System developed by e-Xpert Solutions — a Swiss-designed platform that handles the full lifecycle of public and internal digital certificates across on-premises, cloud, and hybrid environments.
Key capabilities: automatic certificate discovery across your network, expiry monitoring and alerting, full ACME protocol support for automated issuance and renewal without human interaction, security analysis integrated with Qualys SSL Labs, and a modular scripting engine for integration with PKI systems, F5, Apache, IIS, and ServiceNow. The platform provides a unified security dashboard — including certificate grades, trusted vs. untrusted status, and vulnerability reporting — and supports the management of thousands of certificates from a single interface.
Penetration Testing
e-Xpert Solutions’ penetration testing service provides expert-led assessment of your environment’s resilience against real-world attack scenarios. Our certified engineers — holding OSCP, OSCE, and other advanced offensive security qualifications — conduct structured penetration tests across network infrastructure, web applications, APIs, cloud environments, and social engineering vectors. Each engagement delivers a comprehensive report covering findings, risk ratings, proof-of-concept evidence, and a prioritised remediation roadmap — tailored to the compliance requirements applicable to your organisation (FINMA, nLPD, ISO 27001, PCI-DSS).
MSS PAM — Managed Privileged Access Management
As part of Swiss Expert Group, e-Xpert Solutions offers managed CyberArk PAM services — covering ongoing maintenance, patching, account onboarding, and operational support for your CyberArk environment under defined SLAs. This service ensures your privileged access management solution remains secure, operational, and aligned with evolving security requirements — without placing a maintenance burden on your internal team.
Why e-Xpert Solutions for Managed Security?
Managed security at e-Xpert Solutions is built on genuine engineering depth — not resold capacity or white-labelled platforms.
Our engineers hold advanced certifications including GCFA, GCIH, GCFR, GEIR, OSCP, and OSCE, and contribute actively to MITRE ATT&CK and SIGMA. They have published CVEs for vendors including Microsoft, F5, and Abacus — bringing offensive security knowledge that directly informs how we configure detection rules, tune SIEM logic, and validate security controls.
At-Defense is our own Swiss-built SOC. SSLCert is our own CLM platform. PurpleScan is our own vulnerability management methodology. SCA is our own Breach and Attack Simulation programme. These are not third-party services we resell: they are capabilities we have built, operate, and continuously improve based on real client environments and real threat intelligence.
Our Security Operations Center is certified ISO 27001 and covered by an ISAE 3000 assurance report — giving regulated clients the independent assurance they require. All data and operations remain in Switzerland.
If you are under attack right now, call our Emergency Response Line: +41 22 727 05 45.
We operate from our offices in Geneva (Plan-les-Ouates) and Lausanne, serving Swiss and international organisations across the financial, healthcare, industrial, luxury, and public sectors.
Technologies We Work With
We deliver our managed security services using the following platforms — all operated by our certified engineers:

At the centre of our managed security stack is At-Defense — our own Swiss-designed, Swiss-operated managed SOC. Every technology we deploy can feed into At-Defense for unified 24/7 monitoring, threat hunting, and incident response.
Ready to Explore Our Managed Security Services?
Whether you need a fully managed SOC, continuous application protection, proactive vulnerability management, or security control validation, e-Xpert Solutions brings the engineering expertise and the operational track record to help. Contact us — or call our Emergency Response Line at +41 22 727 05 45 if you need immediate assistance.
Frequently Asked Questions – Managed Security Services in Switzerland
Q : What is a Managed Security Service (MSS)?
A Managed Security Service (MSS) is a security function delivered by an external provider on an ongoing basis — covering areas such as threat monitoring, incident response, vulnerability management, application protection, or management of specific security technologies. MSS allows organisations to access certified expertise and continuous protection without building and staffing the full capability internally. e-Xpert Solutions delivers MSS across six complementary domains: SOC monitoring, WAF, vulnerability management, breach and attack simulation, certificate lifecycle management, and penetration testing.
Q : What is Breach and Attack Simulation (BAS) and how is it different from a penetration test?
Breach and Attack Simulation (BAS) continuously and automatically simulates real-world cyberattack scenarios — including malware, APT group techniques, lateral movement, data exfiltration, and web application attacks — against your production environment, without disrupting operations. Unlike a penetration test, which is a point-in-time manual assessment, BAS runs continuously, validates multiple security controls simultaneously, and provides immediate, vendor-specific mitigation guidance. e-Xpert Solutions’ Security Control Audit uses Picus Security to deliver BAS with over 9,371 real-world payloads and 34,000+ mitigation signatures.
Q : What is PurpleScan and how does it reduce the vulnerability exploitation window?
PurpleScan is e-Xpert Solutions’ expert-guided vulnerability management service. In a standard vulnerability management process, the average time between a new vulnerability being discovered and a patch being applied exceeds 30 days — leaving a significant exploitation window. PurpleScan reduces this to under 8 days by having SOC analysts review and prioritise new vulnerabilities within one day of detection, implement mitigations where possible, and deliver a client report in under two hours. The process is continuous and automated, using Nessus, Qualys, and Greenbone scanners integrated with a dedicated Splunk SIEM environment.
Q : What is SSLCert and who should use it?
SSLCert is a Certificate Lifecycle Management platform developed by e-Xpert Solutions. It is designed for any organisation managing a significant number of SSL/TLS certificates — typically those with more than 50 certificates across on-premises, cloud, or hybrid environments. It automates certificate discovery, monitoring, renewal, and security analysis — eliminating the operational risk of certificate expiry and the compliance risk of unmanaged or vulnerable certificates. It integrates with PKI systems, F5, Apache, IIS, and ServiceNow, and is proven in the financial, industrial, healthcare, luxury, and public sectors.
Q : How does e-Xpert Solutions ensure its managed services comply with Swiss regulations?
e-Xpert Solutions’ At-Defense SOC is certified ISO 27001 and covered by an ISAE 3000 assurance report issued by a Big4 firm — providing the independent assurance required by FINMA-regulated institutions. All data and operations remain in Switzerland, ensuring compliance with nLPD data residency requirements. PurpleScan and SCA reporting includes CSV exports specifically formatted for FINMA and ISO 27001 audit submissions. Our penetration testing reports are structured to support compliance with FINMA circulars, nLPD, and PCI-DSS requirements.
Q : Where is e-Xpert Solutions based?
e-Xpert Solutions is headquartered in Plan-les-Ouates (Geneva) — telephone +41 22 727 05 55 — and operates a second office in Lausanne — telephone +41 21 802 26 78. Founded in 2001, we serve organisations across French-speaking Switzerland and internationally. As part of Swiss Expert Group, we collaborate with teams in Gland, Givisiez, Fribourg, and Kloten (Zurich). Emergency response line: +41 22 727 05 45.