SOC & NIS2 · AEGIS PLATFORM

Threat monitoring.
Evidence of readiness.

Learn about the security operations centre, the capabilities of the Aegis platform and cybersecurity obligations in Croatia.

What is a SOCPlatformNIS2 in CroatiaPackagesFAQ
SECURITY OPERATIONS CENTRE

From event
to timely response.

A SOC brings together experts, procedures and technology to monitor security. Analysts assess alerts, identify incidents and coordinate the response. A managed service adds an expert team for organisations that want to entrust monitoring to an external provider.

Aegis: SOC as a service ↗
  1. 01

    Collection

    An agent sends logs over outbound HTTPS traffic on port 443.

  2. 02

    Correlation

    Different logs are normalised into comparable events and correlated.

  3. 03

    Verification

    Correlated findings are verified before escalation.

  4. 04

    Response

    Rules trigger a block, a notification or a new case.

  5. 05

    Record

    Actions are logged for analysis and reporting.

Processing flow based on Aegis SIEM ↗.

AEGIS SOC PLATFORM

Layers of protection
in a single view.

An overview of capabilities for monitoring infrastructure, detecting threats, responding and preparing security evidence.

EVENTS

SIEM

Centralises security logs, correlates attack patterns and adds MITRE ATT&CK technique context.

SIEM details ↗
WEB APPLICATIONS

WAF

Filters application requests using rules for OWASP risks. Offers traffic monitoring, active blocking and geographic rules.

WAF details ↗
USER ACCOUNTS

UEBA and ATO

Detects unusual sign-ins, behavioural anomalies and possible account takeover.

NETWORK TRAFFIC

NDR

Monitors outbound connections, suspicious DNS, communication with attacker infrastructure and data exfiltration, with process and user context.

NDR details ↗
VULNERABILITIES

CVE and CISA KEV

Finds known weaknesses and prioritises remediation based on risk and data on actively exploited vulnerabilities.

Vulnerability scanning ↗
ENDPOINTS

EDR

AegisEDR monitors endpoint threats and integrates with GravityZone and CrowdStrike.

DATABASES

DAM

Monitors logins and access to MySQL, MariaDB and MSSQL databases.

DATA EXPOSURE

Dark web monitoring

Tracks domain exposure and the appearance of leaked credentials.

AUTOMATION

SOAR

Predefined playbooks link alerts to blocking, notifications, cases and webhook actions.

INVESTIGATION

Forensics

Analyses security logs and reconstructs the sequence of an attack.

EVIDENCE

NIS2, ISO and GDPR

Maps controls to records, activity logs and reports to help prepare for compliance reviews.

EARLY DETECTION

Canaries and honeypots

Dedicated decoys raise alerts about suspicious activity in the infrastructure.

Additional platform capabilities

cPanel protection, code analysis, VPN management, DNS analysis, phishing simulations and attack path analysis.

Module overview: Aegis platform ↗. Availability of individual features depends on the contracted scope.

AE

AegisEDR

Evaluates endpoint events and indicators of compromise.

AV

AegisVerify

Performs additional verification of findings before escalation.

AG

AegisGOD

Combines signals from multiple modules into a risk score for each source.

AM

AegisMind

An AI analyst that summarises incidents and suggests next steps, separately for each client.

COVERAGE SCORE

Track status and priorities.

A score from 0 to 100, with grades A to F, shows security coverage and areas for improvement. Recommendations help guide the next steps.

0–100

Engines: Aegis ↗. Coverage score: SIEM ↗.

SECURITY TESTING

Find weaknesses.
Verify the fixes.

BROAD COVERAGE

Vulnerability scanning

Regular scans look for known weaknesses in services, applications and configurations. The result is a prioritised list of findings with recommendations, and you can track how they are resolved over time.

Aegis: scanning ↗
PROOF OF IMPACT

Penetration testing

Agreed tests check whether weaknesses can be exploited in web applications, LAN/WAN networks, VPN and DNS. The scope, permitted methods and authorisation are defined before testing begins.

  • Evidence and actions are recorded in a WORM log.
  • A retest confirms that the fix has been applied.
  • SARIF and PDF reports are available in Croatian, English and Serbian.
  • SAST code analysis and controlled resilience testing complement the assessment.
Aegis: penetration testing ↗
MANAGED MONITORING

Managed SOC

The Aegis team monitors and assesses alerts, tunes rules, escalates incidents and prepares reports. Coverage of 8×5, 12×5 or 24×7 and response targets are defined in the contract.

Managed service model ↗
FOR SERVICE PROVIDERS

MSSP platform

Separate data, users and rules for each client, with a shared partner console.

  • Nested SOCs and bulk deployment.
  • Role-based permissions and per-client scoring.
  • Your own branding and module management.
Partner platform ↗

Deployment and integrations

Data can stay in your own infrastructure or in a managed environment in Croatia, with primary data stored in Croatia/the EU.

Integrations include Linux, Windows, macOS, Synology, MikroTik, FortiGate, Barracuda and Microsoft 365.

Supported environments at Aegis.hr ↗
NIS2 IN CROATIA

Manage risk.
Document implementation.

Directive (EU) 2022/2555 has been transposed into Croatian law by the Cybersecurity Act (Zakon o kibernetičkoj sigurnosti, Official Gazette NN 14/2024). Implementing requirements are set out in the Regulation published in Official Gazette NN 135/2024.

Act ↗ · Regulation ↗

Who is in scope?

Categorisation distinguishes between essential and important entities. It depends on the sector, size and specific criteria; exceptions to the size rule apply to certain providers and public bodies.

Categorisation is carried out by the competent authority. CSIRT responsibilities are divided between NCSC-HR and the National CERT, depending on the sector.

NCSC-HR: entities in scope and competences ↗

Management accountability

Management bodies approve security measures, oversee their implementation and attend appropriate training. Employees must be given the opportunity to receive cybersecurity training.

Act, Article 29 ↗

Areas of security measures

  • Risk analysis and security policies.
  • Incident handling.
  • Business continuity, backup, recovery and crisis management.
  • Supplier and supply chain security.
  • Secure acquisition, development and maintenance; vulnerability handling.
  • Assessing the effectiveness of measures.
  • Cyber hygiene and training.
  • Cryptography and encryption where appropriate.
  • Access control, human resources security and asset management.
  • Multi-factor authentication and secure communications where appropriate.
Act, Article 30 ↗
AEGIS AND COMPLIANCE PREPARATION

Evidence that tracks the measures you implement.

The readiness package links control evidence, security events and activity logs. Reports, ISO/GDPR control mapping and test results make audit preparation easier.

Aegis NIS2 overview

Tools and organisation are chosen to match the prescribed level of measures. A SOC is not a separate legal obligation, and acquiring one does not by itself prove that all requirements are met. NCSC-HR guidance ↗

SIGNIFICANT INCIDENTS

Report without delay,
within clear deadlines.

The first step is to assess whether an incident meets the significance criteria. Notifications are sent to the competent CSIRT through the PiXi system, in line with the applicable guidance.

  1. 24 h

    Early warning

    No later than 24 hours after becoming aware of a significant incident: basic details, suspected malicious activity and possible wider impact.

  2. 72 h

    Initial notification

    No later than 72 hours after becoming aware: an initial assessment of severity and impact and any available indicators of compromise.

  3. 30 days

    Final report

    No later than 30 days after submitting the initial notification: description, root causes, impact and measures taken.

Trust service providers must submit the initial notification within 24 hours. If an incident is still ongoing, a progress report is submitted; longer incidents are subject to additional periodic reports and the final deadline set out in Article 71.

Deadlines and exceptions: Regulation, Articles 64–71 ↗. Forms and procedure: NCSC-HR ↗.

AEGIS PACKAGES

From smaller systems
to a managed SOC.

Pricing is based on the number of monitored systems, or nodes. A node can be a server, a virtual machine, a workstation or a network device. Prices are not published; the offer depends on the scope and service level.

SMALLER ENVIRONMENTS

CORE

up to 5 nodes

Agent-based monitoring, detection rules, automatic blocking and alerts.

COMPLETE MONITORING

SOC

up to 15 nodes

SIEM, web protection, permission management and security case management.

ADVANCED CONTROLS

SOC PRO

up to 30 nodes

Advanced correlation, integrity monitoring, CIS benchmarks and vulnerability assessment.

DOCUMENTED READINESS

SOC + NIS2

up to 50 nodes

SOC PRO capabilities, NIS2 evidence preparation and record reviews.

EXPERT TEAM

MANAGED SOC

50+ nodes

Experts handle monitoring and escalations according to the agreed SLA.

SERVICE PROVIDERS

MSSP

100+ nodes

A partner platform for separate clients under your own brand.

Indicative package scope based on the Aegis pricing model ↗. The final offer and capabilities are confirmed with the provider.

FREQUENTLY ASKED QUESTIONS

What you should know
before choosing.

Do we need to set up our own SOC?

The regulations define the measures and required capabilities, and each organisation chooses suitable tools and ways of working. An in-house SOC is not explicitly required. NCSC-HR ↗

Does a managed SOC always mean 24×7 monitoring?

Coverage depends on the contract: 8×5, 12×5 and 24×7 levels are available. Response and escalation times are agreed separately. Aegis ↗

Is ISO 27001 certification mandatory under this Act?

ISO 27001 certification is not prescribed as an obligation. Appropriate measures must be implemented, and existing ISO documentation can help with control mapping. NCSC-HR ↗

Does the platform guarantee NIS2 compliance?

The platform can help with monitoring and evidence. The organisation remains responsible for meeting its obligations; a security tool is no substitute for a complete compliance assessment. Aegis ↗

How is the implementation of measures verified?

Essential entities carry out an audit at least once every two years, and important entities a self-assessment at the same minimum interval. The competent authority may request an additional review. NCSC-HR ↗

Content reviewed on 3 October 2026. For your categorisation, level of measures and sector-specific requirements, refer to the notice from the competent authority and the current official guidance. Linked legal sources are in Croatian.

SOC & NIS2

Let’s talk about
your infrastructure.

Tell us how many systems you have and what you want to monitor.

Send inquiry