Frequently asked questions
What we usually get asked before a demo about the platform, its integrations and the service model.
About the platform
CiberEm is a SOC platform that centralizes threat detection, investigation and response. It is offered as SOC as a Service and MDR for businesses, and as a multi-tenant console for MSPs and MSSPs.
Integrations
The platform builds on open-source tools established in the industry and unifies them in one console: Wazuh, TheHive and Cortex, DefectDojo and GreyNoise.
Security and compliance
Access is role-based, organization filtering is enforced on every query and every action is audited. The platform does not log personal information in application logs.
All questions
Does CiberEm serve companies in Venezuela?
Yes. Venezuela is our priority market. CiberEm is based in Acarigua, Portuguesa state, and runs a remote SOC with 24/7 monitoring for companies and MSPs across the country and Latin America, with support in Spanish and English and no need to build a SOC on your premises.
What plans does CiberEm offer?
Two monthly plans. The Max Plan includes a 24/7 SOC, vulnerability management and 1 pentest per year. The Max+ Plan adds 3 pentests per year (one every 4 months) and hardening of servers and systems. Annual billing gets you a discount and locks in your rate for as long as you stay with us. Quotes are sent in USD based on your infrastructure.
Which tools does CiberEm integrate with?
Wazuh (SIEM/EDR), TheHive and Cortex (case management and analyzers), DefectDojo (vulnerabilities) and GreyNoise (IOC enrichment).
Does it work for MSSPs or multiple clients?
Yes. Multi-tenancy isolates data, agents, alerts and cases per organization, and the administrator switches clients from a selector without logging in again.
Can I evaluate it without my infrastructure?
Yes. An evaluation mode with sample data for every integration lets you walk through the whole platform before connecting real systems.
Does it support MITRE ATT&CK?
Yes. Every alert is automatically mapped to tactics and techniques, with a coverage heatmap, gap analysis and a ranking of the most frequent techniques.
Does it meet audit requirements?
Every data-changing action is recorded with user, organization, entity, IP and metadata. The log serves audits, compliance and forensic analysis.
What are MTTD and MTTR?
MTTD is the mean time to detect a threat and MTTR the mean time to resolve it. CiberEm computes both automatically from each case lifecycle, together with MTTC (containment).
How do I book a demo?
From the "Request a Demo" button you pick a 30-minute slot in our calendar. In the session we walk through the platform with your use cases and define next steps.
Which languages are available?
The website and sales support are available in Spanish and English. The platform is operated in English, the usual language of the security tools it integrates.