The threat landscape is intensifying, yet many security budgets are not growing at the same pace. Attacks run automatically and around the clock, while smaller and mid-sized organizations in particular face an uncomfortable bill: professional detection and response capability is considered indispensable - and at the same time too expensive. License costs billed per event or per data volume turn thorough analysis of all things into a cost driver: the more you log, the more you pay. Security thus ends up in conflict with the budget.
Diesen Zielkonflikt löst ZephSense von inducio auf. Die Plattform folgt einer einfachen Leitidee: Sicherheit muss nicht teuer sein. Die Plattform ist quelloffen und fair lizenziert: pro Bediener (Seat) und pro Mandant (Tenant), der erste Seat ist gratis. Der Einstieg beginnt bei 8 € im Monat - und Service buchen Sie genau dann hinzu, wenn Sie ihn brauchen. Das Leitmotiv bleibt dabei durchgängig: Erkennen - Reagieren - Steuern - Nachweisen (Detect - Respond - Govern - Prove).
What CTEM is - and why it means more than a SIEM
ZephSense is a Continuous Threat Exposure Management (CTEM) and Security Operations (SOC) Platform. CTEM describes a continuous process that answers not at a single point in time but on an ongoing basis: where are we exposed, what are we doing about it, and can we prove it?
A classic SIEM collects and correlates logs - that is valuable, but only one slice. ZephSense brings together several disciplines in a single interface that in many organizations have historically been operated separately:
- EDR/HIDS - host-basierte Erkennung und Forensik auf Servern und Endpoints.
- NDR und NIDS - netzwerk- und signaturbasierte Angriffserkennung.
- SIEM-Korrelation - zentrale Auswertung sicherheitsrelevanter Ereignisse.
- SOAR und IR - automatisierte Reaktion und strukturierte Incident-Response-Workflows.
- GRC und Risk - Compliance-Mapping, Risikosteuerung und prüffähige Nachweisführung.
Instead of connecting three to five individual tools via manual handoffs, you get one continuous workflow. BSI-SzA and NIS2 are an important compliance aspect here - but just one of several. ISO 27001, NIST, PCI DSS, HIPAA and the GDPR can be mapped just as well.
Fair lizenziert: pro Seat und Tenant statt pro Event
ZephSense wird wie COD by extocode lizenziert: pro Seat (benannter Bediener, 47,50 € im Monat, der erste Seat gratis) und pro Tenant (Mandant, Self Hosted ab 8 € im Monat). Damit bleibt der Preis planbar und folgt Ihrer Organisation, nicht Ihrem Datenvolumen. Es gibt kein per-Event-Licensing: Die Kosten steigen nicht mit jedem zusätzlichen Log-Ereignis, sodass gründliche Auswertung nicht bestraft wird. Der kleinste Einstieg liegt bei 8 € im Monat.
Ehrlich bleibt dabei der Vorbehalt: Einzelne Premium-Erweiterungen und Drittlizenzen sind optional kostenpflichtig - etwa Premium-Regelsätze, sehr hohe Threat-Intelligence-API-Volumina oder kommerzielle Upgrade- und Support-Pfade einzelner Komponenten. Der Kern der Plattform bleibt quelloffen, ohne Vendor-Lock-in.
If you would rather not set it up yourself, you can get a turnkey start. Optionally, inducio delivers the AIMSTRONG appliance including installation, hardening and commissioning - a ready-to-run SOC or CTEM system "out of the box". Performance is scaled via CPU, RAM and network ports, depending on the size of your environment. A note for the sake of accuracy: AIMSTRONG is a brand name - the hardware contains no GPU or AI accelerators, and we promise none. For larger installations, the AIMcompute server platforms are available on request.
For orientation - purely as "from" guide prices, net (excl. VAT), final after technical scoping:
- Einstieg/Standard: AIMSTRONG-Appliance mit 64 GB RAM und 1 TB NVMe ab ca. 3.200 €
- Höhere und HA-Stufen darüber, High-End/KRITIS bis ca. 11.370 €
- Onboarding und Installation: 290 €/Stunde, typisch ab ca. 6.960 € (24 Stunden)
Konkrete Modell-Listpreise nennen wir nicht öffentlich, sondern im individuellen Angebot. Alle aktuellen Richtwerte finden Sie auf der Preisseite.
How ZephSense detects
Detection follows a three-layer methodology of static knowledge, behavioral analysis and correlation.
Signals: priorisierter Alarm-Feed über Perimeter, NDR und EDR (Beispielansicht, vertrauliche Daten verschleiert).
Static Intelligence. In real time, the platform evaluates 3,106 detection rules and 48,764 network-based signatures (inline). Added to this are more than 160,000 threat-intelligence IOCs - around 110,969 domains, around 52,769 IPs, plus file hashes - fed from more than 30 curated threat feeds. These are synchronized hourly and cached locally; lookup takes place in under one millisecond and therefore also in isolated operation, without API calls at runtime.
Behavioral Analysis. Instead of merely matching known patterns, the platform learns per host and per process what is normal, and only alerts on significant deviation. A five-stage process trust model assesses process name and LOLBAS status, signature, signer, hash baseline and execution path, and results in four graded actions: ALLOW, WATCH, KILL or CONTAIN. For the abuse of legitimate system tools, 232 LOLBAS binaries, 8 parent-child rules and 21 command-line attack patterns are monitored.
Correlation Engine. Only connecting multiple evidence sources turns a suspicion into a confirmed threat - for example when a DNS query, a matching network flow and an IOC hit together indicate a command-and-control channel. The DNS intelligence runs in six phases; per endpoint, eight forensic artifact types are available. The result is not a bigger pile of alerts, but a more precise one.
How ZephSense responds
Detection without response leads nowhere. ZephSense automates the time-critical first steps directly at the scene: an on-endpoint kill in under 100 milliseconds, host quarantine in under 5 seconds, a firewall block in under 30 seconds, forensic collection in under 60 seconds and a fleet scan in under 5 minutes.
From four triggers, the platform automatically generates an incident - including affected assets, MITRE ATT&CK mapping and secured evidence. For the most common scenarios, five IR playbooks are available (ransomware, credential theft, malware, lateral movement, data exfiltration), and every incident runs through an eight-phase IR lifecycle. As operational targets, an MTTD under 5 minutes, an MTTC under 15 minutes and an MTTR under 4 hours apply - as target values, not guarantees. For mandatory reporting, BSI 24h and 72h reports can be generated on demand.
How ZephSense proves
This is one of the platform's greatest strengths. ZephSense maps around 274 compliance controls across six frameworks; the counts are to be understood as indicative guide values:
- BSI OH SzA - 45 controls
- ISO 27001:2022 - 93 controls
- NIS2 - 21 Artikel
- NIST 800-53 - 84 controls
- PCI DSS 4.0 - 12 controls
- HIPAA - 19 controls
In addition, the GDPR can be mapped. Every detection rule is tagged with the associated control IDs - from this, a live coverage report and an exportable evidence pack are produced. The integrated GRC module delivers a gap assessment via radar chart; the risk register works with a 5×5 matrix, 15 templates and multi-framework mapping. Above all of this sits a security maturity score on a scale of 0 to 100 - a single metric for the board and auditors. Added to this are 85 automated tests as well as a hardening module with 12 policies and around 18,000 checks.
Service in zwei Bausteinen: Plattform-Support und SOC
Den passenden Betriebsgrad wählen Sie nach Bedarf. Der Plattform-Service deckt Wartung, Updates und Support mit garantierten Reaktionszeiten ab - in vier Paketen von Basic (9×5, ab 190 €/Monat) bis Elite (24/7, ab 2.490 €/Monat), jeweils pro Account. Den SOC-Service wählen Sie über die Reaktionszeit: vom Co-Managed-Einstieg mit Reaktion am nächsten Werktag (8×5, ab 990 €/Monat) bis zum MDR-Betrieb mit 15 Minuten Reaktionszeit (24×7, ab 6.950 €/Monat). Ab 4 Stunden Reaktionszeit ist die Abdeckung immer 24×7. Im Co-Managed-Modell reagiert Ihr Team, im MDR-Modell reagiert inducio - rechtebeschränkt, nach abgestimmten Runbooks und mit SLA.
Die monatliche Grundgebühr deckt bis zu 50 Endpoints, darüber gilt eine Staffelung ab 8 €/Endpoint/Monat. Alle Stufen und Richtwerte stehen auf der Preisseite; die finale Einordnung erfolgt nach technischem Scoping im Angebot.
Operation: sovereign, scalable, DACH-native
ZephSense can be operated on-premises, in a private cloud or fully managed by inducio. The platform is air-gap-capable, EU- and DACH-native, and designed for data sovereignty - the data stays with the customer. It scales from around 50 to over 5,000 endpoints, without per-event licensing. Onboarding is built for speed: on day 1 the agents, on day 3 the first detections live, in week 1 the first report.
From production reference environments, improvements are reported - as empirical values, not as assured properties: a reduction of false-positive alerts by more than 90 percent within 30 days, response times shortened by 60 to 80 percent, a true-positive rate of around 83 percent, as well as audit preparation that shrinks from weeks to hours. The actual values depend on environment, configuration and maturity.
Differentiation: more than SIEM, EDR or a pure CTEM tool
A classic SIEM collects and correlates logs, but knows neither the normal behavior of individual hosts nor responds on its own, and compliance remains a separate world. A pure EDR solution secures endpoints, but sees the network context only to a limited extent. Typical CTEM tools assess exposure, but rarely unite response and audit evidence in the same interface. ZephSense connects all of this - learned baselines, native threat intelligence, on-endpoint protection, automatic incidents with playbooks, integrated compliance mapping and a maturity score - in one platform, without vendor lock-in.
Conclusion
Sicherheit scheitert zu oft am Budget, nicht am Wissen. ZephSense dreht diese Logik um: Die Plattform ist quelloffen und wird fair pro Seat und Tenant lizenziert, der Einstieg beginnt bei 8 € im Monat, und es gibt kein per-Event-Licensing. Optional ergänzen Hardware, Onboarding, Plattform-Service und der SOC-Service nach Reaktionszeit den Betrieb - Sie buchen Service genau dann, wenn Sie ihn brauchen. Erkennen, Reagieren, Steuern und Nachweisen laufen in einer Oberfläche zusammen, und der Sicherheitsreifegrad wird zu einer Zahl, die sich gegenüber Vorstand und Auditoren vertreten lässt.
Jetzt starten: Nehmen Sie die Plattform selbst in Betrieb - oder lassen Sie sich von inducio einen schlüsselfertigen Einstieg einrichten. Schreiben Sie an vertrieb@inducio.de oder nutzen Sie das Kontaktformular.