Corban Global / Capabilities / Cybersecurity
02 · Cybersecurity

Zero-trust, operated 24/7 — by people you'll actually call by name.

From architecture review to managed detection & response, we stand up the controls and run them around the clock. Tuned to regulated-industry threat models, staffed by Tier 3 analysts, and written to pass your next audit in the first walkthrough.

SOC 2 Type II ISO 27001 CMMC L3-ready NIST CSF 2.0 CREST / CISSP staff
SOC · live posture
LAST 30 DAYS
Events analyzed184M
Threats contained1,284
Median triage time11min
Active IR retainers62
Audit pass rate100%
What's inside

Six interlocking capabilities, one retained team.

Every Cybersecurity engagement bundles strategy, engineering and 24/7 operations — because security that's not operated is theater.

S·01

Zero-trust architecture

Identity, device and network posture enforced everywhere — including east-west traffic and third-party access.

  • Identity-aware proxy + mTLS mesh
  • Device attestation & conditional access
  • Segmentation policy as code
S·02

24/7 SOC & MDR

Tier 1–3 analysts on-shift, sub-15-minute triage, and full audit trail delivered monthly to your GRC team.

  • SIEM/XDR co-managed on your tenant
  • Threat hunting & detection engineering
  • Deception & honeytoken programs
S·03

Incident response

Retainers with a one-hour engagement SLA, named incident commanders, and forensic support through regulator & insurer.

  • Tabletop + red team calibration
  • DFIR with chain-of-custody
  • Counsel-ready reporting
S·04

Offensive security

Assumed-breach red teams, purple team exercises, and continuous attack-surface management — with CREST & OSCP staff.

  • Adversary emulation (MITRE ATT&CK)
  • Cloud, app and AD pentesting
  • Continuous external attack surface
S·05

Identity & privilege

IdP modernization, JIT privileged access, and directory hygiene for hybrid Active Directory estates.

  • Okta / Entra ID / Ping deployments
  • Just-in-time PAM (CyberArk / BeyondTrust)
  • AD tier-0 hardening & ESC1–8 remediation
S·06

Compliance & risk

SOX, PCI DSS, HIPAA, SOC 2, ISO 27001, FedRAMP — evidence automated, drift monitored, narratives written.

  • Policy-as-code with OPA / Sentinel
  • Real-time control drift dashboards
  • Audit liaison & narrative authorship
How we engage

Four ways in — matched to the week you're actually having.

Most clients start with one engagement shape and move to a retained SOC over 6–12 months. We can also stand up a SOC in 30 days if you need it next quarter.

Engagement 01 · 2 wk

Posture assessment

A 10-day sprint: architecture review, external attack surface, identity hygiene, and a prioritized remediation register signed by a partner.

Deliverable · Board-grade posture report
Engagement 02 · 30 d

SOC stand-up

From zero to 24/7 monitoring in 30 days — SIEM tuned, playbooks authored, on-call bridges live, and your first monthly scorecard shipped.

Deliverable · Operational SOC + runbook library
Engagement 03 · 1 hr

IR retainer

Pre-paid hours, 1-hour engagement SLA, and a standing bridge with your legal, regulator and insurer contacts already on file.

Deliverable · Always-on IR readiness
Engagement 04 · continuous

Retained SOC + advisory

Steady-state MDR with a named partner on your monthly QBR, detection engineering and board-pack authorship included.

Deliverable · Monthly scorecard + QBR
By the numbers

Outcomes, stacked across 62 retained SOC clients.

Pooled from our 24/7 managed detection & response line, trailing twelve months.

11min
Median triage time
From alert to Tier 2 disposition, across all retained SOC clients. Industry median: ~45 min.
1,284
Threats contained / month
Validated containments, not raw alerts. Credential-theft remains the top vector.
100%
Audit pass rate
Against SOC 2 Type II and ISO 27001 examinations of Corban-managed estates since 2021.
1hr
IR engagement SLA
From retainer call to incident commander on bridge, with forensic support ready to image.
Technology

Stack-agnostic, outcome-anchored.

We operate on your tenant, your license and your data — adding detection content, response runbooks and the on-call bench. We never move your SIEM to ours.

SIEM / XDR
Splunk ES Sentinel Chronicle CrowdStrike SentinelOne Panther
Identity & PAM
Okta Entra ID Ping CyberArk BeyondTrust Teleport
Network & ZT
Zscaler Netskope Palo Alto Cloudflare Tailscale Illumio
Offensive & DFIR
Cobalt Strike Mythic BloodHound Velociraptor Axiom CAPE
Featured engagement

A healthcare insurer — ransomware, contained in 47 minutes.

A HIPAA-regulated insurer engaged our retainer 14 minutes into a suspected ransomware detonation. We took the bridge, isolated 37 hosts, and shipped a full DFIR report in 72 hours.

Fortune 1000 · healthcare insurer
"They were incident commander within 47 minutes of our retainer call. By daybreak, our board had a sequenced timeline and the regulators had a liaison."
CISO National health insurer — 12M members
CASE 07 · IR + DFIR · 72-hour engagement

Contained in 47 minutes, reported in 72 hours, clean by quarter-end.

We isolated 37 endpoints, preserved forensic artifacts, coordinated counsel & regulator notifications, and handed a hardening program back to the client's SOC.

47min
To containment
0
PHI records exfiltrated
3d
DFIR report to board
Frequently asked

Questions CISOs ask before signing.

Do we have to move our SIEM to yours? +

No. We operate on your tenant, your license and your data. Our detection engineering, runbooks and analysts augment what you already own — giving you the option to in-source later without migration pain.

Where are your analysts based? +

Our SOC runs from Washington DC, Dublin and Singapore with follow-the-sun coverage. US-government engagements are US-person-staffed end-to-end; EU engagements have EU-resident analysts during business hours.

Can you stand up a SOC in 30 days? +

Yes. We've done this 14 times in the last three years, typically for companies that just failed a readiness exam or closed an acquisition. Day 1 is posture baseline, day 30 is live 24/7 coverage with a monthly scorecard already shipping.

How does the IR retainer work? +

A small monthly retainer buys a 1-hour engagement SLA, a pre-negotiated MSA/SOW, and pre-filed contact trees with your counsel, insurer and regulators. Unused hours roll over quarterly.

Will you coordinate with our insurer's panel? +

Yes. We are on the approved DFIR panel of most major cyber insurers, and we coordinate directly with breach coaches. Our DFIR work product is written to meet counsel work-product privilege where applicable.

Do you red-team the systems you also defend? +

Not the same quarter, not the same team. Offensive and defensive practices are org-separated with Chinese-wall controls. Clients often run a separate firm's red team quarterly — we'll happily liaise.

Adjacent practices

Pair Cybersecurity with the practices it depends on.

Security rarely lives alone. Most programs involve at least one of the below, staffed by the same senior team.

Start a conversation

Before the next incident — get the bridge on speed dial.

Share an RFP, a readiness-exam finding, or just the quarter you need coverage by. A senior partner responds within one business day.

What you'll get back
  • Posture-snapshot call + remediation hot list
  • Named principal on the follow-up — not a BD rep
  • Three references in your regulatory vertical
  • NDA, MSA and IR retainer sheet on day one