Do you want to switch the language?

Cyber Defense Center

BLUE Team Deepdive
Contact our experts nowContact our experts now

Cyber Defence Center: All-round protection against cyber threats

The Active Cyber Defence Center (ACDC) is your reliable partner for protecting your IT infrastructure against cyber attacks and unwanted activities. As a Managed Security Operation Center (SOC), the Cyber Defense Center offers an efficient solution for detecting and analysing security incidents in real time and initiating immediate countermeasures.

The ACDC has a modular structure and adapts flexibly to your IT systems and IT infrastructures. With central modules such as Network Security Monitoring (NSM), Endpoint Detection and Response (EDR) and Log Management, it enables comprehensive security incident management, recognises security events at an early stage and continuously monitors unwanted activities.

In addition, the ACDC supports the implementation of new protection measures, testing, recovery and forensics, including clear runbooks for rapid response to security incidents. The solution protects both internal and external clients and ensures that security-relevant information is available at all times.

With the Active Cyber Defence Center, you can secure your IT systems, defend against cyber attacks and increase your information security efficiently and sustainably.

24/7 monitoring by experienced analysts - man & machine working together

The Cyber Defence Center has over 60 cyber security analysts at four locations in the D-A-CH region. Their expertise is reinforced by state-of-the-art technologies such as SOAR, threat intelligence feeds and automated detection mechanisms.

This interaction enables

  • continuous monitoring of security-relevant information
  • early detection of unwanted activities
  • prioritised and automated initial measures
  • precise analyses for well-founded decisions

Every reported ticket is manually checked by analysts - including specific recommendations for action tailored to your IT environment. Because:
"Where a person attacks, a person should also defend!"

Increased transparency in your IT infrastructure

The Managed Security Operation Centre (SOC) from CANCOM - also known as the Active Cyber Defence Centre (ACDC) - offers full control over your IT infrastructure. The Cyber Defence Centre monitors all security-relevant network elements around the clock, including devices, applications, data and users, and detects cyber attacks and unwanted activities at an early stage.

By analysing in real time, the SOC detects critical incidents before major damage occurs. In the event of a security incident, the ACDC enables rapid incident response: compromised systems are identified, malware is cleaned up and IT systems are restored, while suitable countermeasures are implemented immediately.

The Active Cyber Defence Center offers a holistic security solution that combines security incident management, monitoring and automation to efficiently protect internal and external clients and continuously increase information security.

Presentation of the security functions of the CANCOM Cyber Defense Center, which filters 1,200,000,000 events into 2,6,16 incidents.

Man and machine: an efficient combination at the Cyber Defense Center

The Cyber Defense Center relies on an effective combination of human know-how and advanced technologies. The experience and analytical thinking of CANCOM cyber security analysts are supported by powerful tools such as Security Orchestration, Automation and Response (SOAR) and Threat Intelligence. This combination enables not only the rapid identification of security incidents, but also the automated prioritization and implementation of suitable measures.

Modular protection with the Cyber Defense Center: Customized IT security

The CANCOM Defense Center is designed in such a way that it can be flexibly adapted to the needs of your IT infrastructure. The different modules allow you to choose exactly the functions that are crucial for your organization. While NSM detects anomalies in the network, EDR offers real-time protection for end devices. Log management enables seamless tracking of security incidents, ensuring rapid analysis and recovery.

Rapid response to cyber attacks

The CDC supports you in dealing with cyber attacks by implementing comprehensive incident response plans. As soon as a security incident is detected, precise measures are initiated to minimize damage and quickly restore normal operations. This proactive approach not only protects your IT infrastructure, but also strengthens your company's resilience to future cyberattacks.

see also: PURPLE-, RED- Team

The main areas of a

Cyber Defense Center

Technology

Use of market-leading technologies and partners for continuous service from the Cyber Defense Center as well as regular fine-tuning of the sensors and comparison with various threat feed databases.

Processes

We don't impose a "standardized approach" on our customers, but instead respond to each one individually. Our experience from over 8 years of market presence, including our heterogeneous customer structure, gives us a 360-degree view of the attack world and allows us to establish highly efficient processes, such as senior analysts with customer responsibility, dedicated service managers and monthly report meetings.

People

"Where a man attacks, a man should defend!" This is the motto by which we design and live our service. Accordingly, our colleagues from the Cyber Defense Center are our top priority. Although we have various supporting systems in place, each of our reported tickets is created manually by an analyst, which also includes recommendations for action tailored to the customer.

Advantages of the Cyber Defense Center

  • Round-the-clock monitoring by experienced analysts
  • Real-time detection of threats and anomalies
  • Modular structure for flexible adaptation to your IT security requirements
  • Use of state-of-the-art technologies such as SOAR and threat intelligence
  • Efficient incident response to deal with security incidents quickly
  • Greater transparency and control over your entire IT infrastructure

With the Cyber Defense Center, you can effectively protect your company against cyber attacks and ensure that your IT security meets the highest standards. Rely on the combination of experience, technology and a tailored approach to stay secure in an ever-changing threat landscape.

Modular Cyber Defense Center design

Categorized according to the logic of the Unified Kill Chain

Red prohibition symbol on a black background.

Network Security Monitoring

  • Recording of network traffic
  • Automated and manual analysis
  • Anomaly detection
  • Network forensics
Graphical representation of a yellow and green circle with text elements on an error page with too many requests.

Log - Analysis

  • SIEM
  • Log aggregation and analysis
  • Statistical analysis
  • Data correlation
Graphic representation of a red and green circle on a black background, possibly symbolizing the server status on an error page.

Threat Intelligence

  • Threat Landscape
  • Threat Actor & Campaign Tracking
  • Brand & Credential Monitoring
Rainbow-colored line with text elements representing security functions of CANCOM's Cyber Defense Center.

Endpoint Detection & Response

  • Endpoint Visibility
  • Live Remote Analysis
  • Remote Data Collection
  • Endpoint Isolation
Graphic representation of a green circle on a black background.

Vulnerability Management

  • Asset Discovery
  • Vulnerability reporting
  • Proactive tracking
  • Enrichment through threat intelligence
Black square against a black background, symbolizes the monitoring and security in CANCOM's Cyber Defense Center.

Operational Technology Monitoring

  • Specialization in OT devices and protocols
  • Continuous monitoring
  • Overview of assets and communication flows
  • Detection of attacks and vulnerabilities

Active Cyber Defence Center (ACDC): All-round protection against cyber threats

The Active Cyber Defense Center (ACDC) is your central partner for modern cyber security, comprehensive defence strategies and efficient protection against cyber attacks. As a Managed Security Operation Centre (SOC), the ACDC continuously monitors your IT infrastructure, detects security incidents in real time and implements immediate countermeasures - 24/7, 365 days a year.

Thanks to its modular service, the Cyber Defence Center offers a flexibly scalable protective shield that secures both internal and external IT systems. The core modules - Network Security Monitoring (NSM), Endpoint Detection & Response (EDR) and Log Management / SIEM - form the basis for holistic security incident management that is efficient, precise and ready for use at any time.

Our IT security services

RED Team

Read more

PURPLE Team

Read more

OT Security

Read more

Security Portfolio

Read more

IT Security

Read more

Blog - 28. August 2025

The best work in the background: how machine learning strengthens cyber security!

Machine learning: between hope and risk Machine learning (ML) is rapidly changing the world of cyber security. Big data analytics, informed machine learning, visual analytics, quantum learning; …

Read the full article

Blog - 19. August 2025

A new frontier. How the IT world opened up and became vulnerable

From the island to the open world In the past, everything was defined: the network was internal, the servers were local, access was regulated. VPN, directory services, clearly separated …

Read the full article

Case Study

CDC Log Module Sentinel

A major Austrian food company has built up an excellent reputation by offering its customers high-quality regional products. This company is committed to sourcing the best food from the region and…

Read more

Case Study

Wienerberger

KBC Cyber Defense Center, the Security Operation Center for optimal IT and network security.

Read more

Contact
CANCOM Austria

Enquire now

Under this link you will find our privacy policy.
How may I help you?
Under this link you will find our privacy policy.