Opérations de sécurité et protection contre les menaces
Surveillez, détectez et répondez aux menaces pour protéger vos systèmes et opérations contre les risques évolutifs.
Cyber threats do not wait. Attackers move fast, dwell quietly, and strike when detection gaps are widest. Effective security operations require continuous monitoring, intelligent threat detection, and the ability to respond decisively — 24 hours a day, 7 days a week.
At e-Xpert Solutions, security operations is not just a service we sell: it is what our engineers do every day. Since 2001, we have built and operated security monitoring environments for Swiss organisations across the financial, healthcare, industrial, luxury, and public sectors. Our practice is anchored by At-Defense — our own 100% Swiss managed SOC, certified ISO 27001 and covered by an ISAE 3000 assurance report — and powered by a team of engineers who contribute actively to MITRE ATT&CK, SIGMA, and the broader cybersecurity research community.
Our Security Operations Capabilities :
At-Defense — Managed SOC 24/7 (100% Swiss)
At-Defense is e-Xpert Solutions’ next-generation managed Security Operations Center — purpose-built for Swiss organisations, operated entirely from Switzerland, and designed around your compliance needs and budget.
Certified ISO 27001 since 2021 and covered by an ISAE 3000 assurance report issued by a Big4 firm, At-Defense provides complete perimeter coverage, proactive threat hunting, darknet monitoring, and 24/7 incident response — all included at a flat-rate, predictable cost. The service deploys in as little as two days with no disruption to your environment and no internal staffing required.
Key performance indicators confirmed since 2018:
%
of attacks detected
breaches recorded among SOC clients
breaches recorded among SOC clients
%
of alerts escalated to client teams
Thanks to intelligent filtering and context-aware analysis by our certified analysts (GCFA, GCIH, GCFR, GEIR, OSCP, OSCE).
At-Defense integrates seamlessly with your existing EDR — Microsoft Defender, CrowdStrike Falcon, Palo Alto Cortex — and extends coverage to the Darknet, cloud workloads, and network sensors.
SIEM & Real-Time Log Correlation
A SIEM is only as good as the intelligence that drives it. Our engineers design and operate next-generation SIEM environments using Splunk and Elastic — ingesting data from endpoints, networks, cloud platforms, email, identity systems, and applications for real-time multi-source correlation. We build output-driven SIEM architectures optimised for detection quality and operational efficiency: custom detection rules, context-aware alert enrichment, and automated playbooks that reduce analyst workload without sacrificing visibility. For Splunk environments, we also deliver an IT Service Intelligence (ITSI) Integration Service — extending SIEM capabilities to IT operations and service health monitoring.
Security Data Pipeline
At scale, the volume of security data becomes an operational and financial challenge. Our engineers deploy Cribl Stream to build intelligent security data pipelines that filter, enrich, transform, and route log data before it reaches the SIEM — reducing Splunk and Elastic ingest costs, improving data quality, and enabling flexible routing to cold storage or multiple destinations simultaneously. Cribl is a platform in which e-Xpert Solutions holds deep certified expertise, and it is an integral component of our At-Defense SOC architecture.
Incident Response & Forensics
When an incident occurs, the quality of the response determines the outcome. Our engineers provide expert-led incident response — covering initial triage, threat containment, forensic evidence collection and preservation, root cause analysis, and recovery. Our IR process integrates directly with At-Defense SOC operations: when the SOC detects a critical incident, the response chain is activated immediately — alerting, containment, forensics, and integrated incident reporting — with a defined SLA of under one hour for Severity 1 events. For organisations without a managed SOC, we also provide standalone IR retainer services.
Threat Hunting & Darknet Monitoring
Automated detection finds known threats. Threat hunting finds the ones that hide. Our SOC analysts conduct proactive threat hunting exercises — using knowledge of attacker techniques, MITRE ATT&CK TTPs, and hypothesis-driven investigation to uncover persistent threats that have evaded standard detection. We also continuously monitor darknet sources for leaked credentials, exposed data, and intelligence relevant to our clients — providing early warning of threats that may not yet have manifested in the environment. Both capabilities are built into At-Defense as standard.
Deception Technology — Honeypots & Honeytokens
The most effective way to detect an attacker who has already breached your perimeter is to let them find something that should not exist. We deploy honeypots, honeytokens, and cloud decoys as active deception layers within client environments — generating high-fidelity alerts the moment an attacker interacts with them. These traps are deployed as part of At-Defense’s Complete Perimeter Coverage and provide detection at the earliest possible stage of the kill chain, before attackers reach critical assets.
User Behaviour Analysis (UBA) & Lateral Movement Detection
Insider threats and compromised credentials are among the hardest attacks to detect with traditional tools. Our engineers deploy User Behaviour Analysis capabilities — using Silverfort and Splunk-based analytics — to establish behavioural baselines for users and systems, and to detect anomalous activity indicative of credential compromise, privilege escalation, or lateral movement. UBA findings feed directly into At-Defense SOC operations for analyst review and rapid response.
Network Traffic Analysis (NTA) & Firewall Intelligence
Network-level visibility is essential for detecting threats that bypass endpoint controls. Our engineers deploy network sensors and integrate traffic analysis with Tufin, Check Point, and Palo Alto Networks to provide complete network visibility — detecting anomalous traffic patterns, command-and-control communications, and lateral movement that would be invisible from endpoint data alone. Network telemetry feeds into the At-Defense SIEM for unified threat correlation.
Why e-Xpert Solutions for Security Operations?
Security operations at e-Xpert Solutions is built on two decades of field experience and genuine engineering depth — not resold managed services or outsourced analyst capacity.
Our engineers hold advanced certifications including GCFA, GCIH, GCFR, GEIR, OSCP, and OSCE. They contribute actively to MITRE ATT&CK and SIGMA, and have published CVEs for vendors including Microsoft, F5, and Abacus — bringing offensive security expertise that directly informs how we build detection rules, tune SIEM logic, and respond to incidents.
At-Defense — our own Swiss-built, Swiss-operated managed SOC — is the operational proof of this expertise. ISO 27001 certified, ISAE 3000 assured, 100% attacks detected since 2018. It is not a white-labelled service: it is the SOC our own engineers built, operate, and continuously improve.
If you are under attack right now, call our Emergency Response Line: +41 22 727 05 45.
We operate from our offices in Geneva (Plan-les-Ouates) and Lausanne, serving organisations across French-speaking Switzerland and internationally.
Technologies We Work With
We build and operate security operations environments using the following platforms — all deployed and managed by our certified engineers:

At the centre of our security operations stack is At-Defense — our own Swiss-designed, Swiss-operated managed SOC. Every technology we deploy can feed into At-Defense for 24/7 monitoring, threat hunting, and incident response.
Ready to Strengthen Your Security Operations?
Whether you need a fully managed SOC, want to improve your threat detection and response capabilities, or need expert incident response support, e-Xpert Solutions brings the engineering depth and the operational track record to help. Contact us — or call our Emergency Response Line directly at +41 22 727 05 45.
Frequently Asked Questions – Security Operations & Threat Protection in Switzerland
Q : What is a Security Operations Center (SOC) and do I need one?
A Security Operations Center (SOC) is a dedicated team and set of processes responsible for continuously monitoring, detecting, investigating, and responding to cybersecurity threats around the clock. Any organisation handling sensitive data, subject to regulatory requirements (FINMA, nLPD, NIS2), or operating critical infrastructure should have SOC-level monitoring in place. The choice is between building an in-house SOC — expensive, complex, and difficult to staff — or using a managed SOC such as At-Defense, which provides the same capability at a predictable flat-rate cost with no internal staffing required.
Q : What makes At-Defense different from other managed SOC services?
At-Defense is a 100% Swiss managed SOC operated entirely by e-Xpert Solutions — not a white-labelled service or outsourced capacity. It is certified ISO 27001 (since 2021) and covered by an ISAE 3000 assurance report issued by a Big4 firm, making it suited to regulated environments subject to FINMA, nLPD, and NIS2. Its analysts hold advanced certifications (GCFA, GCIH, GCFR, GEIR, OSCP, OSCE) and the team contributes to MITRE ATT&CK and SIGMA. Since 2018: 100% of attacks detected, zero breaches among SOC clients. Deploys in two days. Flat-rate pricing. Less than 3% of alerts reach client teams.
Q : What is the difference between SIEM and MDR?
A SIEM (Security Information and Event Management) platform aggregates and correlates log and event data from across an organisation’s environment to detect threats and generate alerts. MDR (Managed Detection and Response) is a fully managed service that wraps SIEM capabilities with 24/7 human analyst coverage, threat hunting, and incident response. At-Defense combines both: e-Xpert Solutions operates a next-generation SIEM using Splunk and Elastic, and provides full MDR capabilities — threat detection, investigation, response, and forensics — as an integrated managed service.
Q : What is Cribl and why is it part of your SOC architecture?
Cribl Stream is a security data pipeline platform that sits between log sources and the SIEM — filtering low-value data, enriching events, and routing telemetry to the right destinations at the right cost. In At-Defense, Cribl is used to optimise data ingestion into Splunk: reducing licensing costs by filtering noise before it reaches the SIEM, improving detection quality by enriching events with contextual data, and enabling flexible routing to cold storage for compliance purposes. It is a critical component of a scalable, cost-effective SOC architecture.
Q : What happens when At-Defense detects a critical incident?
When At-Defense detects a Severity 1 incident — such as active ransomware, a confirmed breach, or a critical infrastructure compromise — the response chain activates immediately. Within the defined SLA of under one hour, our analysts initiate alerting, containment, forensic evidence collection, and integrated incident reporting. The client is contacted directly, the affected systems are isolated, and a response playbook is executed. If you are under active attack and not yet an At-Defense client, you can call our Emergency Response Line directly: +41 22 727 05 45.
Q : Where is e-Xpert Solutions based?
e-Xpert Solutions is headquartered in Plan-les-Ouates (Geneva) — telephone +41 22 727 05 55 — and operates a second office in Lausanne — telephone +41 21 802 26 78. Founded in 2001, we serve organisations across French-speaking Switzerland and internationally. As part of Swiss Expert Group, we also collaborate with teams in Gland, Givisiez, Fribourg, and Kloten (Zurich).