Managed SOC · Penetration Testing · Incident Response

Most companies notice an attack only when it is already too late.

Sheriff is your specialised, vendor-independent partner for cybersecurity. We test your systems like a real attacker, monitor them around the clock and step in when it matters. For mid-sized companies and critical infrastructure: pragmatic and measurable.

A radar screen with range rings, a degree scale and a sweeping search sector - a symbol of round-the-clock monitoring of your systems.
SOC / MDR

24/7 monitoring that scales with you

Detect threats around the clock and actively stop them before damage is done.

Penetration Testing

Test before attackers do

We attack your systems like a real attacker and show you exactly what to fix.

Incident Response

Immediate help during attacks

Containment, recovery and forensic investigation, exactly when it counts.

PART OF THE SHERIFF GROUP 600+ specialists across EU countries & Ukraine DE · CH · FR · RO 22+ years of experience Focus: NIS2 & critical infrastructure
Does this sound familiar?

Three situations in which companies call us.

Three situations, three clear answers.

01 - Blind spot
We wouldn't notice an attack in time.

Without continuous monitoring, attackers often move undetected for weeks. In one of our cases, a company first learned of a data leak through our dark-web monitoring.

Detect
02 - Uncertainty
We don't know whether our defences really hold.

Firewalls and tools say nothing about whether they withstand a real attack. The most dangerous gaps often sit at the interfaces between systems.

Test
03 - Limited resources
We lack the capacity internally, or it has already happened.

When vulnerabilities can't be closed or an incident is already underway, experience and speed matter. That is exactly when we step in.

Respond
Our answers

Detect. Test. Respond.

For each of the three situations, the right service, and the specialists to deliver it.

Detect

Managed SOC & MDR

A team of analysts watches over your systems 24/7, detects attacks in real time and stops them before you hear about them in the morning. Including dark-web monitoring that raises the alarm the moment your data shows up somewhere.

All-round protection as a service.
Detect

Managed SOC & MDR

We keep watch over your IT around the clock, like a security service, only digital:

  • Our team watches your systems day and night and spots attacks immediately
  • When a real threat appears, we step in and stop it, not just an alert but action
  • We run the necessary technology for you, so you don't have to build your own team
  • Also for smaller companies: an affordable entry point instead of an expensive enterprise solution
All SOC services →
Test

Penetration Testing

We hack you before anyone else does: web, cloud, network. Instead of a 200-page scanner list, you get the handful of gaps a real attacker would exploit, and a clear path to close them.

Real attacks with an actionable fix plan.
Test

Penetration Testing

We step into an attacker's shoes and test how far someone could really get:

  • We test your websites, apps, networks and Wi-Fi for weaknesses
  • As needed: from the outside like a stranger, or with insider knowledge
  • We also test your people, for example with real but harmless test emails
  • Instead of an incomprehensible list, you get clear priorities: what to do first
All pentest services →
Respond

Incident Response & Forensics

When things catch fire, we're there: stop the attack, restore operations and investigate fully, even without prior monitoring. You're back up and running quickly and know exactly what happened and how to prevent it next time.

Back to safe operations, fast.
Respond

Incident Response & Forensics

If something has happened, we're there immediately and get you running again fast:

  • In an emergency, we stop the attack and restore your operations
  • We investigate fully what happened, court-ready for insurers and authorities
  • Specialised in ransomware: recover data and find the root cause
  • On request, guaranteed standby so no time is lost in an emergency
All IR services →
More services: Vulnerability Management · Cloud Security · NIS2 & Compliance · ISO 27001 · TISAX · Critical Infrastructure (KRITIS) · OT Security · Cyber Audit →
Case Studies

Real cases. Anonymised, but not sugar-coated.

Case ADFIR · Ransomware

Ransomware, no monitoring, full investigation

Several servers encrypted, logs deleted by the attacker, no SIEM, no EDR. From Windows artefacts alone, we reconstructed the complete attack timeline over roughly 48 hours.

Key takeawayMissing monitoring is not the end of visibility, but a solvable problem.
Case BCTI · Data leak

The attack the dark web gave away

Internal documents surfaced on the dark web before the client noticed anything. We worked backwards: from the confirmed leak (2.72 GB) to the compromised endpoint.

Key takeawayExternal threat intelligence is often the only early-warning signal.
Case CPentest · SaaS

Security at the interfaces

For a multi-app SaaS platform (HR and payroll data), we tested five applications plus the cloud, and specifically what no one finds when testing them in isolation: the trust relationships between the systems.

Key takeawayThe biggest risks often lie between the systems, not within one.

Planning a change: migration, NIS2 or new systems?

Then it pays to look at security before you invest. In a free security workshop, our experts review your specific situation together with your management and IT, pragmatically and without any product sales pitch.

Book a free security workshop
Why Sheriff

German accessibility, international firepower.

Not pure consultants but practitioners who carry out attacks and investigate incidents. Part of the international SHERIFF Group.

Hands-on
Real technical depth

We carry out attacks and investigate incidents ourselves, rather than just advising.

Delivery
Local + international

A dedicated contact in Germany, with scalable delivery across DE/CH/FR/RO behind it.

Neutral
Vendor-independent

We recommend what fits your situation, not what we happen to sell.

22+
years in the SHERIFF Group
600+
specialists across EU countries and Ukraine
DE·CH·FR·RO
delivery locations
70+
projects delivered
Team & Expertise

Roles and expertise instead of names.

The technical depth of our team, proven by verified certifications, without disclosing names.

90
professional certifications
87
currently active
12
certifying bodies
Blue Team Lead

SOC & Incident Response Lead (L3)

Escalation tier, hunting, incident command
  • MSSP
  • SOC
  • MDR
  • DFIR
Certs: CSA, SANS FOR500/508/578 (trained), CTF blue team winner
Offensive

Senior Penetration Tester (Lead)

Web, network & AD, advanced
  • Pentest
  • Attack Simulation
Certs: OSCP, OSWE, PenTest+
AppSec

Web, API & Mobile App Pentester

Web, API, Mobile
  • Web Pentest
  • API Pentest
  • Mobile Pentest
Certs: eWPTX ×2, eWPT ×2, eMAPT ×2, Burp Suite CP ×3
Cloud & Identity

Cloud Security Consultant

Microsoft 365, Azure, AWS
  • Cloud Security
  • Identity
Certs: AZ-500, SC-900, AWS CCP, ICCA
GRC & Audit

Lead Auditor (GRC / Compliance)

Compliance & audit
  • Audits
  • NIS2
  • ISO 27001
Certs: ISO 27001 Lead Auditor (PECB), CISA (ISACA)
Certified by
OffSecPortSwiggerINEEC-CouncilCompTIAMicrosoftAWSTCM SecurityPECBISACAiSQIMobile Hacking Lab
Standards & methodology

Our work is aligned with NIST CSF 2.0, NIST SP 800-61 & SP 800-115, ISO/IEC 27001*, SANS, MITRE ATT&CK, OWASP, CIS Controls, BSI IT-Grundschutz and TIBER-EU.

* aligned with the standard; formal ISO/IEC 27001 certification of the GmbH is in preparation.

Technology stack
SentinelQRadarSplunkFalcon LogScaleWazuhDefender XDRCrowdStrikeSentinelOneESETTheHiveMISPFortiSOARBurp ProNessusBloodHoundPingCastle
Anonymised selection from the certification matrix of our three teams with comparable profiles (90 certifications, 87 active, 12 certifying bodies). The SOC team covers levels L1-L3. Focus: offensive security, web/network, cloud and GRC/audit (ISO 27001 Lead Auditor, CISA).
Partners

Together with strong technology and delivery partners.

Logos and joint presentation are currently being agreed with our partners. Approvals to follow.

Let's talk about your security, before someone else does.

Request via a short form on the contact page, prioritised and answered promptly.