We DefendYour Organization

Blue team specialists with 16+ years of hands-on CERT/SOC experience. We build detections, respond to incidents, and harden infrastructure.

0+Years Experience
0+Years CERT/SOC
0SOC/CERT Environments Built
Who We Are

Operators, not just consultants

16+ years of hands-on experience from Norwegian CERT/SOC operations. We build detections, investigate incidents, and harden infrastructure.

Detection & Threat Hunting

We write detection rules, tune SIEM platforms, and hunt for threats in your environment — using Sigma, YARA, and KQL.

Forensics & Incident Response

When incidents happen, we're there. Disk, memory, and network forensics with evidence handling that holds up in court.

Hardening & Security Testing

Systematic hardening of servers, AD, and cloud. Penetration testing and purple teaming to find and close gaps.

Core Capabilities

Blue Team Security Operations

Three pillars of defense — built by operators who have done this for real.

01

Detection Engineering

Custom detection rules in Sigma, YARA, KQL, and SPL. SIEM tuning, threat hunting, and detection-as-code pipelines that catch real threats — not just noise.

Read more →
02

Incident Response & Forensics

From first alert to post-incident report. Disk and memory forensics, malware analysis, evidence preservation, and response retainers for when minutes matter.

Read more →
03

Hardening & Assessments

Penetration testing, AD security reviews, cloud posture assessments, and systematic hardening. We find the gaps and help you close them.

Read more →
Our Toolbox

Tools and technologies we work with

Microsoft SentinelSplunkSigmaYARAKQLVelociraptorVolatilityCrowdStrikeMicrosoft DefenderMITRE ATT&CKNmapBurp SuiteBloodHoundAzure / M365
Meet Our Expert

Led by operators, not consultants

Kim

Principal Security Lead

Kim spent 12+ years building and running CERT/SOC environments in Norwegian public sector — writing detection rules, leading incident response, and hardening critical infrastructure. That hands-on experience drives everything ForSec delivers.

  • FIRST.org liaison — global incident response network
  • Built 4 CERT/SOC environments from the ground up
  • Detection engineering, forensics, and IR lead across 16+ years
Meet the Team →
Kim
Industries

We defend organizations across sectors

Every industry has unique threat landscapes. We bring operator-level blue team expertise adapted to your sector.

Finance and banking

Financial institutions face sophisticated threat actors targeting transactions and customer data.

  • Detection rules for financial fraud and insider threats
  • Incident response for payment systems and trading platforms
  • Penetration testing against SWIFT, DORA, and PCI DSS scope

Healthcare

Healthcare data is a prime target. We protect the systems clinicians depend on daily.

  • Threat detection across clinical networks and Normen compliance
  • Incident response for patient record systems
  • Hardening of medical device networks and IoT

Government and public sector

We built our expertise inside Norwegian public sector CERT/SOC — we know this domain.

  • Detection engineering aligned with NSM basic principles
  • Incident response and forensics for public infrastructure
  • Hardening against state-sponsored and APT threats

Technology and SaaS

Fast-moving tech companies need security that keeps pace with development.

  • Cloud security assessments (Azure, AWS, GCP)
  • Container and Kubernetes hardening
  • Purple teaming for SaaS platforms and APIs
Client experiences

Trusted by security teams

“ForSec helped us build a detection capability from scratch — custom Sigma rules, SIEM tuning, and a threat hunting process that actually finds things. Our SOC went from reactive to proactive in three months.”
A

Anders M.

SOC Manager, financial sector

“When we got hit with ransomware at 3 AM, ForSec was on the phone within 15 minutes. They handled forensics, contained the threat, and gave us a recovery plan before sunrise. That is what real incident response looks like.”
K

Kristine L.

CISO, technology company

“Their purple team exercise exposed blind spots we did not know we had. ForSec ran realistic attack scenarios and helped our blue team build detections for every gap. Concrete, actionable, technical.”
E

Erik S.

IT Security Architect, healthcare

Trusted Partnerships

Recognized by Industry Leaders

Strategic partnerships that strengthen our security capabilities

Microsoft Partner

Microsoft Partner

Enterprise-grade protection using Microsoft's cloud security ecosystem.

  • Azure security architecture and implementation
  • Microsoft Defender for Cloud expertise
  • Sentinel SIEM/SOAR integration
  • Microsoft 365 security optimization
FIRST.org Liaison

FIRST.org Liaison

Direct connection to the global incident response community through FIRST.org membership.

  • Global threat intelligence sharing
  • Direct connection to international security teams
  • Early warning systems for emerging threats
  • Access to incident response playbooks and methodologies
FAQ

Common Cybersecurity Questions

Answers to what Norwegian businesses ask about cybersecurity and our services.

We start with a no-obligation conversation to understand your situation, challenges, and goals. Then we conduct an initial security assessment that provides a clear picture of your current risk level and actionable recommendations. The entire process typically takes 2–4 weeks from kickoff to final report.

We offer both fixed project pricing and ongoing advisory agreements. An initial security assessment typically starts from NOK 50,000, while ongoing monitoring and advisory services are priced based on scope. We always tailor the engagement to your needs and budget — contact us for a no-obligation estimate.

It's never too late to start with security. Many of our clients come to us precisely because they realize they need professional help. We meet you where you are and build a tailored security program step by step — without disrupting your daily operations.

We build custom detection rules (Sigma, YARA, KQL, SPL) tailored to your environment and threat landscape. This includes tuning your SIEM to reduce false positives, creating detection-as-code pipelines for version-controlled rules, and running threat hunting sessions to find threats your existing rules miss. The goal is detections that catch real attacks — not just noise.

Call us immediately at +47 99 22 06 77. With over 12 years of CERT/SOC operations experience, we can quickly assist with initial assessment, damage scope analysis, evidence collection, and recovery. Clients with ongoing agreements receive prioritized response times.

Our team spent 16+ years inside Norwegian public sector CERT/SOC environments — building detections, responding to incidents, and hardening infrastructure under real threat conditions. We are not consultants who deliver reports and leave. We write the Sigma rules, we analyze the malware, we sit with your team during incidents. That operational experience is what sets us apart.

Latest from our blog

Insights and guidance

View all articles →

Ready for stronger defenses?

Let's discuss how we can help secure your organization.